Service — Jellyfin
What it is
Jellyfin is a self-hosted media server. It organizes and streams movies, TV shows, and other media to devices on the local network and externally.
Location
- External URL:
https://watch.juncyard.com - Internal:
http://192.168.10.10:8096 - Container:
jellyfin - Compose stack:
~/projects/junc1/compose/admin/ - Config / data:
~/data/admin/jellyfin/ - Media paths:
~/data/media/tv/,~/data/media/movies/ - Hardware acceleration: enabled via
/dev/dri(VAAPI)
Authentication
Jellyfin authenticates via Authentik using the SSO-Auth plugin (9p4/jellyfin-plugin-sso, v4.x).
- SSO login URL:
https://watch.juncyard.com/sso/OID/p/authentik - Authentik provider: slug
jellyfin,per_providerissuer mode - Register both
https://andhttp://variants of the/sso/OID/r/authentikredirect URI (the plugin sends HTTP internally; nginx redirects to HTTPS) - Plugin config:
~/data/admin/jellyfin/config/plugins/configurations/SSO-Auth.xmlEnableAuthorization=false— do NOT enable; with empty AdminRoles it strips admin from all SSO users
A “Sign in with Authentik” button is injected into the login page via an nginx
sub_filter — required because Jellyfin 10.11.x is a React SPA, so the classic
CustomCss injection trick does not work.
External apps (Infuse, Emby Theater, etc.) cannot use OIDC SSO. Users set a local Jellyfin password under User Settings → Security and use that in the app.
API
Jellyfin has a REST API at http://192.168.10.10:8096 (Swagger docs at
/api-docs/swagger). Auth is via an API key generated in the admin dashboard.
Key endpoints: GET /Items, GET /Users/{userId}/Items, GET /Sessions,
POST /Sessions/{sessionId}/Playing.
Quorra integration
Planned. Jellyfin runs with SSO fully configured. The Quorra integration — library search, watch history, and watchlist management — is designed but not yet built; playback control is deferred. See Quorra’s service integrations reference.
Radarr and Sonarr manage what gets added to the library; Jellyfin serves what’s already there.