XTREAM3U

Xtream test

Tests Xtream endpoints you provide and returns factual diagnostics. Usernames and passwords are never logged or exposed.

Credentials are sent once for the check, never stored or logged, and the password field is cleared after each run.

What this check examines

  • Host reachability: whether the portal host answers at all, before credentials enter the picture.
  • HTTP status of the player-API response — non-200 means a host or access fault, not a credential fault.
  • Authentication verdict: accepted, rejected, or unrecognized payload, read from the structured response without ever returning your password.
  • Account metadata the panel volunteers: status, expiry date, connection limit, and connections in use, shown when present. Never credentials, never anything the panel did not send.

Reading the verdict

  • Login accepted: host and credentials work. If channels still don't load, the fault is downstream — expiry, connection slots, empty categories, or delivery. See the login-works diagnostic.
  • Login rejected: host reachable, credentials refused. Verify username and password character-by-character (trailing spaces are the classic), then check expiry with the provider.
  • Unrecognized payload: the host answered with something other than player-API data. Confirm the host, port, and http-vs-https values before retrying.

What this check cannot tell you

  • Channel contents, VOD catalogs, or stream health — authentication and delivery are separate stages.
  • Connection-slot availability at a given moment — “too many connections” is transient server state.
  • Anything about other people's credentials. Test only endpoints you hold.

FAQ

What happens to my password? It is sent once with the check request, used for that single authentication call, never logged, never stored, never returned — and the form field clears after every run.

Why is this rate-limited more strictly? Authentication endpoints are abuse-sensitive by nature. Six checks per minute per client prevents brute-forcing while leaving legitimate diagnosis unaffected.

Can I test a provider demo login? Yes, if you hold it legitimately. Demo and trial lines test exactly like paid ones; expiry shows as rejection or empty categories.

What do Expired or Disabled mean? Your password is correct but the account is not usable: a subscription, billing, or provider-side action problem. Renew or contact the provider. Neither status can be fixed from any player or test tool.

Why does it work on one device but not another? Almost always the connection limit: another device holds the single slot. Close the other stream and retry before changing anything else.

What ports and schemes work? Whatever the provider specifies — host, port, and http-vs-https together identify the endpoint. A correct host with the wrong port fails exactly like a dead server, so copy the triplet verbatim instead of reconstructing it.

Login accepted but no channels load. Next step? Check expiry and connection slots first, then whether categories return empty. The ordered tree for exactly this symptom is in the Xtream guide's diagnostic section.

Method and limits

Methodology: single server-side player-API call with a 12-second timeout, http(s) hosts validated against private ranges, rate-limited to 6 checks per minute per client. Credentials exist only in the request lifecycle and are excluded from logs by construction.

Sources

Related: playlist directory · M3U not working guide · all tools