{"repo":"ZL154/JellyfinSecurity","free":true,"listed":false,"github":"https://github.com/ZL154/JellyfinSecurity","clone":"git clone https://github.com/ZL154/JellyfinSecurity.git","description":"A Jellyfin plugin that adds native two-factor authentication (TOTP, email OTP) with trusted device tokens, TV device pairing, LAN bypass, and API key bypass. Server-side enforcement — works with all clients including web, mobile, TV, and service integrations like Sonarr/Radarr.","language":"C#","stars":215,"topics":["authentication","csharp","dotnet","jellyfin","jellyfin-plugin","mfa","security","self-hosted","totp","two-factor-authentication"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"🔐 Jellyfin Security Comprehensive authentication and hardening for Jellyfin: TOTP, passkeys, email OTP, OIDC/SSO sign-in , brute-force IP banning, impossible-travel detection, per-user IP allowlist, device pairing, trusted-browser cookies, and a full audit log - all from one plugin. Why this exists: for self-hosters who want a complete auth + hardening layer without standing up a separate identity stack . Full IdPs like Authentik (with OIDC or LDAP outposts) and Authelia work great with Jellyfin and offer features this plugin doesn't - they're often the right call for serious deployments. This plugin is for the case where you'd rather get TOTP, passkeys, OIDC sign-in, brute-force protection, impossible-travel detection, IP allowlist, audit logging, and a proper admin UI as a single Jellyfin plugin — no extra containers, no LDAP outpost, no proxy-auth header juggling, native Jellyfin user model end-to-end. 📖 New: step-by-step guides live in the Wiki — Installation, First-Time Setup, OIDC / SSO, Account Protection, Admin Guide, and Troubleshooting. --- 🛡️ Security posture - what to check before you trust this with your server You don't have to take my word for it. Every signal below is automated and visible to anyone, including you: - CI badge — every push and PR builds and runs the full xUnit test suite (344 tests covering crypto, parsers, authentication flows, translations, and middleware). Green = tests pass. - CodeQL badge — GitHub's static security scanner runs the secu","default_branch":null,"files":null,"tree":[],"storefront":"/r/ZL154","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ZL154/JellyfinSecurity/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}