How to access Jellyfin remotely, outside your home network
Updated ยท 6 min read
Jellyfin works at home the moment it's installed, but your phone on cellular or a laptop at a hotel can't see it. There are two safe ways to access Jellyfin remotely, outside your home network, and one popular shortcut you should skip. This page walks through both by hand.
Why it doesn't work away from home
Your router gives every device at home a private address, such as 192.168.1.20, and shows the internet one shared address. When a visit arrives from outside, the router doesn't know which device it's for, so it drops it. That's good: it's why your computers aren't open to the world by default.
Jellyfin is entirely self-hosted, so nothing outside your home knows it exists. To reach it, you either join your devices to your home network privately, or you give Jellyfin a public address and let your router send visits for that address to it.
Private or public: pick one
| Private (Tailscale or another VPN) | Public (reverse proxy with HTTPS) | |
|---|---|---|
| Who can connect | Only devices you sign in to your private network | Anyone with the address and a Jellyfin password |
| On each device | Install the VPN app and sign in | Nothing; any browser or Jellyfin app |
| Router changes | None | Forward TCP port 443 |
| Works when your provider shares one address | Yes | Only over IPv6, if you have it |
| Good for | You and your household | Family and friends in other homes, smart TVs |
If you only watch on your own phone and laptop, start private. If you want to hand a relative an address that works in the Jellyfin app on their TV, go public.
Private: Tailscale
Tailscale builds a private network between your own devices. Nothing is opened to the internet, and it works even when your internet provider doesn't allow incoming connections. A traditional VPN server on your router does the same job if you already run one.
- Install Tailscale on the computer that runs Jellyfin and sign in.
- Install Tailscale on your phone, tablet or laptop and sign in with the same account.
- In the Tailscale app, note the server's Tailscale address. It starts with 100.
- In the Jellyfin app on your phone, add the server as
http://100.x.y.z:8096, using that address. - On Windows, make sure the firewall lets Jellyfin's port in on the Tailscale network too (see when the firewall blocks Jellyfin), or the connection times out.
Tip: Jellyfin treats addresses outside its LAN networks list as remote. Tailscale addresses usually are, so the person's account needs remote connections allowed (see below), and Jellyfin's limit for streams away from home applies. That limit is usually what you want on cellular.
The catch: every device needs the Tailscale app, and some smart TVs can't run it. For those, the public route is easier. If your home has no public address of its own, read Jellyfin behind CGNAT first.
Public: a domain, HTTPS and port 443
This is how most people share Jellyfin. A small program called a reverse proxy sits in front of Jellyfin, holds a free HTTPS certificate for your domain, and passes visits through. Jellyfin's own documentation recommends this over exposing Jellyfin directly.
- Give every Jellyfin account a strong password. Anyone on the internet can reach the sign-in page once this is done.
- Reserve the server's address in your router. Use the router's DHCP reservation, so the server keeps the same private address after a restart.
- Get a name that points at your home. Use a domain or subdomain you own with a DNS A record set to your home's public address. If that address changes, use a dynamic DNS service (many routers have one built in) to keep the name current.
- Install a reverse proxy on the server. Caddy is the simplest, because it gets and renews a Let's Encrypt certificate by itself. The full setup is in Jellyfin HTTPS with a free certificate.
- Forward TCP port 443 on your router to the server. Find Port forwarding (sometimes Virtual servers or NAT) and send TCP 443 to the server's reserved address. Forward port 80 too if your proxy uses it to prove you own the domain or to redirect plain visits.
- Tell Jellyfin about the proxy. In Dashboard > Networking, add the proxy's address to Known proxies (127.0.0.1 if it runs on the same computer) and make sure remote access is allowed. Save, then restart Jellyfin.
- Choose who may watch from outside. In Dashboard > Users, open each person and tick or untick Allow remote connections to this server.
- Test from outside. Turn off Wi-Fi on your phone and open
https://your.domainon cellular. Testing from home can pass even when the outside route is broken.
Most setups don't need Published server URIs on the Networking page. It tells apps which address to use, and is worth looking at only if an app keeps being sent to a wrong address.
Careful: once port 443 is forwarded, your sign-in page is public. Remove old test accounts, and don't give the administrator account a password you use anywhere else.
Why not just forward port 8096
Many old forum answers say to forward 8096, Jellyfin's web port, and connect to your public address. It works, and it's a bad idea. Port 8096 is plain HTTP: your password and everything you watch cross the internet unencrypted, readable on any public Wi-Fi along the way. Jellyfin's documentation calls opening a port directly to the internet insecure and not recommended.
Browsers and some apps also warn about, or refuse, sign-in pages that aren't HTTPS. A reverse proxy on 443 fixes both problems with one forwarded port.
Questions
Is it safe to access Jellyfin remotely?
It's as safe as the route you choose. Tailscale opens nothing to the internet. A public address is reasonable when it uses HTTPS, every account has a strong password, and only port 443 is forwarded. Forwarding plain HTTP on 8096 isn't safe.
Do I need to buy a domain for Jellyfin remote access?
No. Tailscale needs no domain. For a public address you need a name that points at your home, which can be a domain you own or a free dynamic DNS name.
Why does Jellyfin work at home but not on cellular?
At home your phone reaches Jellyfin's private address directly. On cellular it needs a route in: a VPN like Tailscale, or a public name, a forwarded port and a reverse proxy. A missing router rule or a provider that shares one address among many homes are the usual causes.
Does remote streaming use my home internet upload?
Yes. Every stream away from home is sent from your home connection, so your upload speed sets the quality. Lower Jellyfin's limit for remote streams if videos buffer outside the house.
The one-click way: Reelhost
Reelhost's Watch away from home screen offers both routes. Pick a web address you can share, such as yourname.watchhome.app, and it turns on remote watching in Jellyfin, opens port 443 on your router with UPnP, gets the HTTPS certificate with Caddy and Let's Encrypt, then checks the address from outside. Or pick private access with Tailscale, with nothing opened. Video streams straight from your home either way. It needs Complete or Yearly; the free check-up shows whether remote watching is set up.
The check-up is free and changes nothing. Every fix is previewed, backed up and reversible.