Ant Media · Authentication Profile

Ant Media Authentication

Authentication

Ant Media Server is self-hosted, so authentication is configured per instance rather than issued by a vendor-run identity service. There is no API key or OAuth client to register: the operator turns filters on in the web panel or in red5.properties, and callers present a JWT signed with the instance's own shared secret — or, for the management panel API, a session cookie obtained with an operator's e-mail and MD5-hashed password.

Ant Media declares 4 security scheme(s) across its OpenAPI definitions.

BroadcastingLive StreamingMediaStreamingVideoWebRTC
Methods: Schemes: 4 OAuth flows: API key in:

Security Schemes

http
scheme: bearer
openIdConnect
apiKey
· in: header ()
session-cookie

Source

Authentication Profile

Raw ↑
specification: API Commons Authentication
specificationVersion: '0.1'
provider: Ant Media
providerId: ant-media
generated: '2026-09-02'
method: searched
docs: https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/jwt-rest-api-filter/
source: >-
  https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/jwt-rest-api-filter/,
  https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/securing-rest-apis/ and
  https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/management-rest-apis/
  (fetched 2026-09-02, HTTP 200 each). The published OpenAPI documents declare no
  securitySchemes at all, so the whole auth model comes from the documentation.
description: >-
  Ant Media Server is self-hosted, so authentication is configured per instance rather than
  issued by a vendor-run identity service. There is no API key or OAuth client to register:
  the operator turns filters on in the web panel or in red5.properties, and callers present a
  JWT signed with the instance's own shared secret — or, for the management panel API, a
  session cookie obtained with an operator's e-mail and MD5-hashed password.
default_posture:
  description: >-
    Out of the box the REST API is protected by an IP filter, not by a token. The JWT REST API
    filter is DISABLED by default and the IP filter is ENABLED, restricted to 127.0.0.1 plus
    whatever the operator adds. An instance exposed to the internet with the IP filter widened
    and JWT still off has an unauthenticated REST API.
  source: https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/jwt-rest-api-filter/
schemes:
  - id: jwt-rest-api-filter
    type: http
    scheme: bearer
    bearerFormat: JWT
    applies_to:
      - Ant Media Broadcasts API
      - Ant Media Vods API
      - Ant Media Filters API
      - Ant Media Push Notification API
      - Ant Media Version API
    header: Authorization
    value_form: 'Bearer {JWTToken}'
    algorithm: HS256 (HMAC-SHA256)
    secret: >-
      A shared secret configured by the operator in the web panel under the JWT REST API
      Filter setting. There is no per-caller credential; every caller signs with the same key.
    enabled_by: Web panel — JWT REST API Filter setting (disabled by default)
    example: >-
      curl -X POST -H "accept: application/json" -H "Content-Type: application/json"
      -H "Authorization: Bearer {JWTToken}"
      "https://{domain:5443}/{application}/rest/v2/broadcasts/create" -d '{"name":"streamName"}'
    expiry: >-
      Optional. The docs describe using the standard JWT `exp` claim (a Unix timestamp); the
      token is rejected once it passes. No default lifetime is imposed by the server.
    source: https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/jwt-rest-api-filter/
  - id: jwks
    type: openIdConnect
    applies_to:
      - Ant Media Broadcasts API
      - Ant Media Vods API
      - Ant Media Filters API
      - Ant Media Push Notification API
    description: >-
      Instead of a local shared secret the instance can validate REST JWTs against an external
      OAuth server's JSON Web Key Set. Configured per application in
      /usr/local/antmedia/webapps/{App-Name}/WEB-INF/red5-web.properties with
      settings.jwtControlEnabled=true and settings.jwksURL=<issuer>. The documented example
      issuer is an Auth0 tenant, whose keys are read from <issuer>/.well-known/jwks.json.
    source: https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/jwt-rest-api-filter/
  - id: management-jwt
    type: apiKey
    in: header
    header: ProxyAuthorization
    applies_to:
      - Ant Media Management API
      - Ant Media Cluster API
    description: >-
      The management panel REST API takes its JWT in a ProxyAuthorization header — NOT
      Authorization, and with no "Bearer " prefix. Enabled by setting
      server.jwtServerControlEnabled=true and server.jwtServerSecretKey=<32+ char secret> in
      conf/red5.properties and restarting the server.
    example: >-
      curl -X GET -H "Content-Type: application/json" -H "ProxyAuthorization:{JWTToken}"
      "https://example.com:5443/rest/v2/system-resources"
    source: https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/management-rest-apis/
  - id: management-session
    type: session-cookie
    cookie: JSESSIONID
    applies_to:
      - Ant Media Management API
      - Ant Media Cluster API
    description: >-
      Alternative to the management JWT. POST /v2/users/authenticate with a JSON body of
      {"email": "...", "password": "<MD5 hash of the password>"}; the server returns a
      JSESSIONID cookie that authorises subsequent management calls. The password is sent as
      an MD5 hex digest, which is a weak digest by modern standards and is transport-security
      dependent — always call this over HTTPS on port 5443.
    operations:
      - authenticateUser
      - deleteSession
      - isAuthenticatedRest
      - isAdmin
    source: https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/management-rest-apis/
network_controls:
  - id: rest-ip-filter
    description: >-
      Per-application allow-list of IPs and CIDR ranges configured at
      Dashboard > {Application} > Settings > IP Filter Settings. Enabled by default with
      127.0.0.1 allowed. Removing 127.0.0.1 blocks requests originating on the server itself.
    source: https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/securing-rest-apis/
  - id: web-panel-cidr
    description: >-
      server.allowed_dashboard_CIDR in /usr/local/antmedia/conf/red5.properties restricts which
      CIDR blocks may reach the web panel. Defaults to 0.0.0.0/0 — everything.
    source: https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/securing-rest-apis/
stream_authorization:
  note: >-
    Distinct from REST authentication — these secure publish/play of the media streams, not the
    management API, and are documented under Stream Security.
  mechanisms:
    - id: hash-based-token
      docs: https://docs.antmedia.io/guides/stream-security/hash-based-token/
    - id: jwt-stream-security-filter
      docs: https://docs.antmedia.io/guides/stream-security/jwt-stream-security-filter/
    - id: one-time-token
      docs: https://docs.antmedia.io/guides/developer-sdk-and-api/rest-api-guide/
      operations:
        - getTokenV2
        - validateTokenV2
        - listTokensV2
        - revokeTokensV2
        - getJwtTokenV2
    - id: totp-subscriber
      description: Time-based one-time passwords per subscriber, with a base32 b32Secret.
      operations:
        - addSubscriber
        - getTOTP
        - blockSubscriber
        - revokeSubscribers
    - id: keycloak-integration
      docs: https://docs.antmedia.io/guides/stream-security/keycloak-integration/
    - id: cors-filter
      docs: https://docs.antmedia.io/guides/stream-security/cors-filter/
maintainers:
  - FN: Kin Lane
    email: info@apievangelist.com
    url: https://apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ant-media-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.