🎧 Your Personal Streaming Service https://www.navidrome.org
  • Go 81.5%
  • JavaScript 15.1%
  • Rust 2.2%
  • Go Template 0.5%
  • Makefile 0.3%
  • Other 0.4%
Find a file
Deluan 8789561b60 fix(api): consolidate grant deletes and harden API v1 auth after review
- GrantRepository keeps three deletes: DeleteForUser, DeleteStaleEpochs
  (replaces DeleteOtherEpochs and DeleteIfEpoch) and DeleteIdle. Delete(id)
  is gone; the idle path in ResolveGrant now calls DeleteIdle, so a grant
  renewed by another node between the read and the delete survives.
  settleEpoch deletes the user's grants below the snapshot's epoch, which
  is safe outside the transaction because epochs only move forward.
- The "dead grants on an older epoch are only deleted when presented"
  policy note moves from the repository to core ListGrants.
- SQL trace logging no longer prints the args of property writes (signing
  keys) or user password writes, both encrypted with a key that may be the
  public default. The SQL statement is still logged.
- The spec gate rejects JSON body keys that differ from a declared property
  only in case. kin-openapi validates exact names while encoding/json
  decodes case-insensitively, so {"scopes":[],"Scopes":null} minted a
  token with every scope and a "Client" key skipped maxLength.
  It also rejects data after the first JSON value, which the handlers'
  decoder ignores and which let a body skip the alias check.
- The liveness cache trims its eviction log on evict, not only on put, so
  evict-only traffic stays bounded; the floor still drops stale fills.
- createAccessToken, login and setupFirstAdmin declare Cache-Control:
  no-store on their success responses.
2026-09-28 20:06:28 -04:00
.devcontainer chore(deps): upgrade to Go 1.27 (#5990) 2026-08-30 12:43:15 -04:00
.github feat(api): add the API v1 foundation behind DevAPIv1 (#6227) 2026-09-26 15:27:23 -04:00
adapters refactor(persistence): stateless repositories with per-call context (#6149) 2026-09-25 18:06:10 -04:00
api fix(api): consolidate grant deletes and harden API v1 auth after review 2026-09-28 20:06:28 -04:00
cmd fix(server): exit with an error code when the server fails to start (#6236) 2026-09-27 14:18:24 -04:00
conf feat(api): add the API v1 foundation behind DevAPIv1 (#6227) 2026-09-26 15:27:23 -04:00
consts refactor(api): reuse existing helpers in API v1 auth 2026-09-28 20:06:28 -04:00
contrib fix(contrib): support libblas in systemd sandbox (#6190) 2026-09-21 09:06:12 -04:00
core fix(api): consolidate grant deletes and harden API v1 auth after review 2026-09-28 20:06:28 -04:00
db feat(api): add api_grant storage for API v1 grants 2026-09-28 20:06:27 -04:00
git feat(plugins): experimental support for plugins (#3998) 2025-06-22 20:45:38 -04:00
log fix(log): redact named string types instead of panicking 2026-09-28 20:06:28 -04:00
model fix(api): consolidate grant deletes and harden API v1 auth after review 2026-09-28 20:06:28 -04:00
persistence fix(api): consolidate grant deletes and harden API v1 auth after review 2026-09-28 20:06:28 -04:00
plugins refactor(persistence): stateless repositories with per-call context (#6149) 2026-09-25 18:06:10 -04:00
release fix(release): repair root-owned artwork and plugins folders on upgrade (#6143) 2026-09-17 17:17:56 -04:00
resources feat(subsonic): OpenSubsonic API key authentication (#6219) 2026-09-27 21:56:58 -04:00
scanner refactor(scanner): remove the unused legacy ffmpeg metadata extractor (#6231) 2026-09-26 12:30:52 -04:00
scheduler fix(log): change debug log level to trace to reduce log noise from cron 2026-08-06 00:40:58 -04:00
scripts build(worktree): add script for setting up git worktrees 2026-03-17 21:34:00 -04:00
server fix(api): consolidate grant deletes and harden API v1 auth after review 2026-09-28 20:06:28 -04:00
tests feat(persistence): add PropertyRepository.PutIfAbsent 2026-09-28 20:06:27 -04:00
ui fix(ui): honor EnableCoverAnimation for theme cover animations (#6234) 2026-09-28 18:06:44 -04:00
utils feat(api): add the API v1 foundation behind DevAPIv1 (#6227) 2026-09-26 15:27:23 -04:00
.dockerignore fix: add music.old to .dockerignore and .gitignore 2026-02-06 07:40:05 -05:00
.git-blame-ignore-revs Move project to Navidrome GitHub organization 2021-02-06 21:47:19 -05:00
.gitignore ci: run the plugins test suite in parallel processes (#6051) 2026-08-30 16:57:40 -04:00
.golangci.yml refactor(persistence): stateless repositories with per-call context (#6149) 2026-09-25 18:06:10 -04:00
.nvmrc chore(deps): update all dependencies (#4618) 2025-10-25 17:05:16 -04:00
.octocov.yml ci: exclude tests/ from the coverage report on pull requests too (#6070) 2026-09-01 23:02:15 -04:00
CODE_OF_CONDUCT.md Use Contributor Covenant v2.0 2020-07-21 14:40:21 -04:00
context7.json Add context7.json with URL and public key 2026-04-14 19:19:42 -04:00
CONTRIBUTING.md docs: update commit message format in CONTRIBUTING.md 2026-02-20 11:00:34 -05:00
Dockerfile build(docker): add curl to container image (#6111) (#6116) 2026-09-09 11:38:59 -04:00
go.mod feat(api): add API v1 login, setup, token, grant and password endpoints 2026-09-28 20:06:27 -04:00
go.sum feat(api): add API v1 login, setup, token, grant and password endpoints 2026-09-28 20:06:27 -04:00
LICENSE Change license to GPLv3 2020-01-22 14:48:38 -05:00
main.go feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00
Makefile feat(api): add the API v1 foundation behind DevAPIv1 (#6227) 2026-09-26 15:27:23 -04:00
Procfile.dev chore(deps): upgrade to Go 1.24.1 (#3851) 2025-03-17 21:08:10 -04:00
README.md feat(subsonic): add structured sidecar lyrics support with OpenSubsonic v2 karaoke cues and agent layers (#5076) 2026-06-19 12:00:58 -04:00
reflex.conf fix(reflex): exclude .worktrees from the reflex configuration regex 2026-09-07 14:43:18 -04:00

Navidrome logo

Navidrome Music Server  Tweet

Last Release Build Downloads Docker Pulls Dev Chat Subreddit Contributor Covenant Gurubase

Navidrome is an open source web-based music collection server and streamer. It gives you freedom to listen to your music collection from any browser or mobile device. It's like your personal Spotify!

Note: The master branch may be in an unstable or even broken state during development. Please use releases instead of the master branch in order to get a stable set of binaries.

Check out our Live Demo!

Any feedback is welcome! If you need/want a new feature, find a bug or think of any way to improve Navidrome, please file a GitHub issue or join the discussion in our Subreddit. If you want to contribute to the project in any other way (ui/backend dev, translations, themes), please join the chat in our Discord server.

Installation

See instructions on the project's website

Cloud Hosting

PikaPods has partnered with us to offer you an officially supported, cloud-hosted solution. A share of the revenue helps fund the development of Navidrome at no additional cost for you.

PikaPods

Features

  • Handles very large music collections
  • Streams virtually any audio format available
  • Reads and uses all your beautifully curated metadata
  • Great support for compilations (Various Artists albums) and box sets (multi-disc albums)
  • Multi-user, each user has their own play counts, playlists, favourites, etc...
  • Very low resource usage
  • Multi-platform, runs on macOS, Linux and Windows. Docker images are also provided
  • Ready to use binaries for all major platforms, including Raspberry Pi
  • Automatically monitors your library for changes, importing new files and reloading new metadata
  • Supports lyrics from sidecar .ttml, .yaml/.yml Lyricsfile, .elrc, .lrc, .srt, .txt files and embedded TTML, Enhanced LRC, LRC, SRT, and plain-text tags (via lyricspriority)
  • Themeable, modern and responsive Web interface based on Material UI
  • Compatible with all Subsonic/Madsonic/Airsonic clients
  • Transcoding on the fly. Can be set per user/player. Opus encoding is supported
  • Translated to various languages

Translations

Navidrome uses POEditor for translations, and we are always looking for more contributors

Documentation

All documentation can be found in the project's website: https://www.navidrome.org/docs. Here are some useful direct links:

Screenshots