The API took a session cookie, a proxy's word or the shared admin token, so a script or an agent working for one person had to sign in with their password and carry the cookie, or be given the admin token. Settings now makes named tokens, ipx_ and 256 random bits, sent as Authorization: Bearer. A token is its owner and no more. Only its SHA-256 is kept, in the new api_tokens table, with when it was made and last used; it is shown once and revoked from the same list. An unknown or revoked one gets a 401 rather than falling through to a cookie. Cloudflare Access still stands in front of the tunnel, so from outside a token needs an Access service token beside it; docs/sso.md says how. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ipx
A self-hosted podcatcher for a household. It checks your feeds, downloads the episodes, and serves
a web UI modelled on the 2004 Mac app iPodderX, for any number of people sharing one copy of
the files. One Rust binary, ipx, is both the daemon and the command line.
It is a rewrite of ipodderx-core, the Python engine behind iPodderX (2004-2008, Ray Slakinski & August Trometer).
What it does
- The web UI. It has a toolbar, and a feed list that opens with Directory, Popular and All Subscriptions. Items sit in a sortable table with a Files pane, and there is a player bar. It comes in Dark, Light and Classic themes, and works on a phone.
- Several people, one copy. Each person has their own subscriptions and their own read, pinned and playback state. There is one file on disk per episode, however many people want it. People sign in with a password or through a proxy (Cloudflare Zero Trust or Authentik), and admins manage accounts and settings.
- Scanning. Feeds are checked on a schedule, globally or per feed, and a feed's own TTL is honoured. Keyword, explicit-content and media-type filters decide what is downloaded, with a limit on how many of a feed's newest episodes are downloaded.
- Downloads. Files come over HTTP or BitTorrent and are filed into a folder per feed. Retention deletes the oldest files to stay under a disk quota or an age limit, and never touches an item someone has pinned.
- OPML. You can import and export your own subscriptions. You can also subscribe to an OPML URL, which keeps a whole list in step as a folder.
Run it
With Docker:
docker build -t ipx .
docker compose up -d
docker-compose.yml is set up for the author's own server. Point its image and its three volumes
(/config, /data and /downloads) at yours first. The UI is on port 8099. BitTorrent uses 6881
over TCP and UDP. Files are written as PUID/PGID, 99:100 by default.
From source:
cargo build --release
./target/release/ipx daemon
The first start creates admin / ipodderx. Sign in at /login, then change it:
echo -n 'a good password' | ipx user passwd admin
The UI is plain HTTP, so put TLS in front of it if it is reachable from outside your network.
Documentation
| docs/configuration.md | Every config key, path and environment variable |
| docs/cli.md | Every command, including ipx user |
| docs/users.md | Accounts, and what several people share |
| docs/sso.md | Signing in through Cloudflare Zero Trust or Authentik |
| docs/architecture.md | How it works: modules, schema, control socket, HTTP API |
| CHANGELOG.md | What changed, by release |
| CLAUDE.md | Notes for working on the code, including how production is deployed |
Tests
cargo test # the engine: parsing, filters, retention, schedules, SQL, per-user state
node tests/page-smoke.js # the page script loads without throwing
node tests/native-bridge.js # the page hands playback to a native shell
npx playwright test # a real browser against a real daemon on fixture feeds
npm install gets the test runner, and npx playwright install --with-deps chromium gets the
browser.
License
MIT, see LICENSE. The icons are Font Awesome Free 7.3.1 by @fontawesome, under CC BY 4.0, embedded as SVG.