Fast, lightweight HLS and media proxy built as a single dependency-free Node service.
Fzz Proxy is designed for people who want a clean self-hosted proxy that is easy to run, easy to publish, and strong enough for real streaming workloads without dragging in a heavy framework stack.
| Area | Fzz Proxy |
|---|---|
| Runtime | Single dependency-free Node service |
| Playlist support | Master, variant, iframe, alternate audio, subtitles, LL-HLS tags |
| Media support | TS, fMP4, keys, mp4, subtitles, byte ranges |
| Security | CORS allowlist, token auth, rate limiting |
| Performance | Keep-alive pooling, smart in-memory cache |
| Usability | Simple query API, root metadata route, Docker support |
- Rewrites HLS playlists
- Streams segments, keys, mp4, subtitles, and other media
- Forwards custom headers per request
- Handles alternate audio, subtitles, iframe playlists, LL-HLS parts, maps, and keys
- Supports CORS allowlists
- Uses keep-alive upstream connection pooling
- Uses smart in-memory caching for playlists and small cacheable media
- Supports optional token protection for public deployments
- Includes built-in per-IP rate limiting
npm startBase routes:
GET /playlist?url={encoded}&headers={encodedJson}GET /media?url={encoded}&headers={encodedJson}GET /proxy?url={encoded}&headers={encodedJson}&mode=auto|playlist|mediaGET /healthGET /meta
Example:
const proxy = "http://localhost:8080";
const url = encodeURIComponent("https://example.com/master.m3u8");
const headers = encodeURIComponent(JSON.stringify({
Referer: "https://example.com/",
Origin: "https://example.com"
}));
const playlistUrl = `${proxy}/playlist?url=${url}&headers=${headers}`;Recommended minimum settings for a public deployment:
ALLOWED_ORIGINS=https://your-app.com
ACCESS_TOKENS=change-this-token
RATE_LIMIT_WINDOW_MS=60000
RATE_LIMIT_MAX_REQUESTS=240Then call the proxy with &token=change-this-token.
Useful repo files already included:
docker build -t fzz-proxy .
docker run -p 8080:8080 --env-file .env.example fzz-proxyPORT=8080HOST=0.0.0.0REQUEST_TIMEOUT_MS=15000UPSTREAM_REDIRECT_LIMIT=5DEFAULT_USER_AGENT=Mozilla/5.0 Fzz-Proxy/1.0ALLOWED_ORIGINS_FILE=./allowed_origins.txtALLOWED_ORIGINS=*PLAYLIST_CACHE_TTL_MS=4000MEDIA_CACHE_TTL_MS=30000CACHE_MAX_ENTRIES=500CACHE_MAX_BYTES=67108864MEDIA_CACHE_MAX_BYTES=1048576ACCESS_TOKENS=token1,token2RATE_LIMIT_WINDOW_MS=60000RATE_LIMIT_MAX_REQUESTS=240
If ALLOWED_ORIGINS is set, it overrides the file. Use * to allow all origins.
- Keep
ALLOWED_ORIGINS=*only for local testing. - Enable
ACCESS_TOKENSbefore exposing the proxy publicly. - Range requests and authenticated media are intentionally not body-cached.