Setup Guide

Xtream Codes Setup — Every Field Explained

Xtream Codes setup asks for three things: a server URL, a username and a password. Almost every failed login is one of four mistakes — the port left off the server URL, a trailing slash, the server URL pasted into the M3U box instead, or credentials typed on a TV remote with the wrong case. This page explains what each field is, what it looks like when it is right, and which error message maps to which mistake.
·Updated 24 August 2026·6 min read

The three fields

Xtream Codes is an API, not a file. Rather than downloading a playlist and re-importing it whenever the lineup changes, your player asks the server for the current channel list, the EPG and the on-demand catalogue every time it opens. That is why it is worth using where your player supports it — and why the login is stricter than an M3U URL.

  • Server URL — the address of the portal, almost always including a port number. It looks like http://example-server.com:8080. The scheme (http:// or https://) and the port are both part of it.
  • Username — issued with the subscription. Not an email address, not a display name you chose.
  • Password — issued with it. Case-sensitive, and usually contains characters that are painful on a TV remote.

The port is not optional

This is the single most common failure. A browser assumes port 80 for http:// and 443 for https://, so a portal address looks like a normal website address and people drop the :8080 when typing it in. Xtream Codes portals rarely run on 80 or 443. Without the port, the player connects to a port nothing is listening on and reports a generic connection failure.

If your credentials arrived as a single M3U link, the port is already in it — look for the colon and digits immediately after the hostname and before the first /. That is the port your server URL needs.

The silent failure: server URL in the M3U box

Every major player offers both login methods on the same screen, and they are easy to transpose. Paste an Xtream server URL into the M3U or "playlist URL" field and the player will often succeed at connecting, receive something that is not a playlist, and show you an empty channel list with no error at all.

An empty list after a successful-looking login almost always means the wrong box. Pick the option explicitly labelled Xtream Codes API — or "Login with Xtream Codes", depending on the player — and you will get three separate fields instead of one.

Trailing slashes and copied whitespace

Two smaller ones that produce the same generic failure:

  • A trailing slash. http://server.com:8080/ is rejected by some players and accepted by others. Leave it off.
  • A copied space. Selecting the URL out of a message frequently picks up a leading or trailing space, which is invisible in the input box. Retyping the first and last characters by hand fixes more logins than it has any right to.

Which error means what

The messages are not standardised across players, but the categories are consistent.

  • "Failed to authorize" / "Invalid credentials" — the server was reached and rejected the username or password. That is good news: your server URL and port are right. Check case, and check the subscription has not expired. We have a longer breakdown in the Failed to Authorize guide.
  • "Connection failed" / a spinner that never resolves — the server was never reached. Port, scheme, typo in the hostname, or your ISP blocking the address.
  • Login succeeds, list is empty — wrong field, as above. Or, less often, a subscription active but with no bouquet assigned to it, which support has to fix at their end.
  • Channels load, EPG does not — not a login problem at all. See EPG not working.

Entering it without losing your mind

Typing a case-sensitive password on a TV remote is where most of the frustration actually lives. Three things that help:

  • Use the phone app remote. Both the Fire TV and Google TV apps give you a phone keyboard for on-screen text fields.
  • Set it up on a phone first. Some players sync a playlist across devices once it is added on one, which turns the TV step into a login rather than a transcription exercise.
  • Check the credentials on a computer browser first. If the portal has a web interface, confirming the login works there separates "wrong credentials" from "wrong player configuration" before you fight the remote.

Where to go next

Device-specific walkthroughs pick up from here: Firestick, Google TV and Chromecast, Samsung Smart TV, and TiviMate, which is the player most people settle on once the credentials are working.

If you do not have credentials yet, a free trial issues a working set so you can test the setup on your own hardware before committing to a plan.

New to the service? Start with the full Vivimate IPTV guide — what it includes, what it costs and how to set it up.

Stream Everything with Vivimate

55,000+ live channels · NFL · NBA · MLB · 4K UHD · No contract · From $19.99/month