FFLIPBOX

Setup guide · Xtream

Xtream Codes login on iPhone, done right

Three fields — server, username, password — and thirty seconds, when the details go in exactly as your provider sent them. This guide shows what belongs in each field, what the login errors actually mean, and how to tell an expired line from a typo.

ALSO IN: DEUTSCH · PORTUGUÊS (BR)

What “Xtream Codes” means, in one paragraph

Xtream Codes is the login protocol most IPTV provider panels speak. Instead of one long M3U link, you get three separate pieces: a server URL, a username, and a password. A player that speaks the protocol — Flipbox does — uses them to fetch your live channels, your movies-and-series catalogue, and the programme guide in one go, with cleaner category structure than the equivalent M3U export. If your provider offers both connection types, Xtream is the one to use; the trade-offs are laid out in Xtream vs M3U. Flipbox includes no channels and no providers — these credentials come from a service you already pay.

The three fields, and what goes in each

Your provider's welcome message contains something like:

Server:   http://line.example.net:8080
User:     a1b2c3d4
Password: x9y8z7w6
  • Server — the full address including the port (the :8080). Include the http:// or https:// prefix exactly as given. Nothing after the port: no /get.php, no trailing path.
  • Username — copied exactly. Xtream usernames are case-sensitive and frequently machine-generated, which makes l/1 and O/0 mix-ups the classic failure.
  • Password — same rules. Copy it on its own, not as part of a sentence, so no stray space rides along.
Worth knowing

If all you have is a long M3U link, your Xtream details are usually inside it: the server is everything up to and including the port, and the username= and password= values are visible in the link itself.

Signing in, step by step

  1. Add a playlist, choose Xtream login

    Open Flipbox, choose Add playlist, then Xtream login as the source type.

  2. Fill the three fields

    Paste each value separately — server with port, username, password. Name the connection after your provider so it stays recognisable in backups and diagnostics later.

  3. Connect

    Flipbox authenticates and pulls your channel list, on-demand catalogue, and guide data. The guide needs no separate URL — Xtream servers publish it at a standard endpoint, and Flipbox collects it automatically.

  4. Clean up, then play

    Run the one-tap cleanup preview to collapse duplicate HD/FHD/4K channel variants — big provider lists shrink by roughly half — then tap a channel. If it plays, setup is finished.

Login errors, decoded

“Invalid credentials” or “authentication failed”

  • Re-copy each field on its own. Trailing spaces and autocorrected capitals are invisible and fatal. Turn off any keyboard auto-capitalisation before retyping.
  • Check the port. A server address that works in a browser without the port can still refuse a player connection missing it. Use the exact address, port included.
  • Swap http and https once. Providers migrate between them and forget to tell anyone.
  • Ask whether the line is active. Renewals, password rotations, and panel migrations all present as “invalid credentials.” Your provider's portal or support can confirm in a minute — no player setting fixes an expired subscription.

“Too many connections” or streams that cut off when another device plays

Most subscriptions permit a fixed number of simultaneous streams — often one. If the line works until a second device starts playing, you've found the limit. Stop playback on the other device, or ask your provider about a multi-connection plan. This is a property of the line, not of the player.

Login succeeds, but categories are empty or wrong

Category structure comes from the provider's panel. If a group is empty in Flipbox, it is empty at the source — refresh once, then check the provider portal. Reorganised lists are routine in this category.

Login succeeds, playback stutters

Different plumbing, different page: the buffering guide walks the diagnosis in the order that isolates network, device, and server causes.

Everything plays, guide is blank or shifted

See the EPG repair guide — and if you want to know whether your provider's guide feed is actually any good, the EPG checker reads any XMLTV file and reports its coverage, depth, and faults in seconds.

Questions that come up

Is Xtream Codes a service I subscribe to?

No — it's a protocol, the way “email” is a protocol. Your subscription is with your provider; Xtream is just the shape of the login they hand you. Flipbox speaks the protocol and supplies nothing else.

Why does my Xtream login say invalid credentials?

Nine times out of ten: a copy-paste error (trailing space, capital letter, letter-number mix-up), the wrong port in the server address, or an expired line. Re-copy each field separately from your provider's message and confirm the subscription is active.

Do I need an EPG URL as well?

Usually not. The guide arrives automatically with an Xtream connection. If it's empty anyway, the provider's feed is likely thin or stale — test it before assuming the app is at fault.

Where are my credentials stored?

On your phone, in the app — and nowhere else. Backups never include your passwords, so credentials never leave your phone. Flipbox has no accounts and no analytics; the App Privacy label is Data Not Collected.

Can I add a second line for reliability?

Yes — with Pro's unlimited playlists, a second line from your provider enables automatic failover: when the active line drops, Flipbox switches to the healthy one and keeps the evening intact.

Keep going