DRM — Widevine, PlayReady and FairPlay
Updated 06 Oct 2026Castreon can encrypt a channel with the three DRM systems that devices use for paid content: Widevine (Android, Chrome, Firefox, Android TV, most Smart TVs), PlayReady (Windows, Edge, Xbox, Smart TVs) and FairPlay (Safari, iPhone, iPad, Apple TV). The picture and the sound can only be decrypted inside the protected part of the device, with a license that your DRM provider gives each viewer.
Available from Castreon 1.0.5, on the Enterprise plan. For simple encryption on every plan, see HLS encryption with AES-128.
Who does what
| Does | |
|---|---|
| Castreon | at every start of the channel asks your DRM provider for a new key (CPIX), encrypts the channel and publishes DASH and HLS with the DRM information players need |
| Your DRM provider (for example DoveRunner) | keeps the keys and gives licenses to players |
| Your platform (app, website, middleware) | decides who may watch and creates a license token for every viewer |
Castreon never issues licenses and never sees your subscribers. The packaging is done by Shaka Packager, which is included in Castreon (BSD license) — there is nothing extra to install.
What you need
- An Enterprise license on the server.
- An account with a DRM provider that delivers keys over CPIX — for example DoveRunner (formerly PallyCon). The provider's plan must include the DRM systems you want (FairPlay also needs an Apple FairPlay Streaming certificate, which the provider explains).
- Channels in H.264 or HEVC.
- HTTPS for web players: browsers only allow DRM on HTTPS pages.
1. Connect your DRM provider
Settings → DRM:
- At DRM provider, choose:
- DoveRunner (PallyCon) — paste only the KMS Token from DoveRunner Console → Multi-DRM → DRM Settings; Castreon builds the address itself;
- Other provider (CPIX) — paste the complete CPIX address of your provider, with the token included (HTTPS only).
- Save. The KMS server shows the provider and the name of its server; the token itself is never shown again — not in the panel, not in the API, not in the audit log and not in the diagnostic report.
- Test connection asks for a test key for each delivery. You should see DASH (CENC) with PlayReady and Widevine, and HLS (CBCS) with FairPlay, Widevine and PlayReady.
The status at the top right shows Ready when the license, the provider and Shaka Packager are all in place.
2. Add the DRM output to a channel
- Open the channel → Edit → Add output and choose DRM as the Type.
- Content ID — the name under which the provider stores the key. Empty means the short name of the channel. Letters, digits, dot, dash and underscore.
- Choose the deliveries:
- DASH · Widevine + PlayReady (CENC)
- HLS · FairPlay + Widevine + PlayReady (CBCS)
- Optionally change Segment duration (s) (default 4) and Segments in playlist (default 6).
- Save. The channel restarts with the DRM output.
The other outputs of the channel keep working as before and are not encrypted. For a paid channel, keep only the DRM output (and, if you need them, push outputs to your own systems).
The addresses and the content IDs
For a channel with the short name channel1, Delivery shows:
| Row in Delivery | Value |
|---|---|
| DRM · DASH (Widevine, PlayReady) | http://<domain>/live/channel1/drm/dash/manifest.mpd |
| DRM · DASH · content ID | channel1 |
| DRM · HLS (FairPlay, Widevine, PlayReady) | http://<domain>/live/channel1/drm/hls/master.m3u8 |
| DRM · HLS · content ID | channel1-hls |
DASH and HLS use different keys (CENC and CBCS must not share a key), so they have different content IDs: the HLS one ends in -hls. The license token your platform creates must use the content ID of the delivery the player opens.
The same Token for players and Allowed addresses apply as for the other outputs.
Which delivery for which device
| Device | Delivery | DRM |
|---|---|---|
| Android phones and tablets, Android TV, Fire TV | DASH | Widevine (ExoPlayer / Media3) |
| Chrome, Firefox, Edge, Opera on a computer | DASH | Widevine (Edge also PlayReady) — with Shaka Player, dash.js, Video.js, Bitmovin, THEOplayer… |
| Samsung (Tizen), LG (webOS) and other Smart TVs | DASH | PlayReady or Widevine |
| Windows apps, Xbox | DASH | PlayReady |
| Safari on Mac, iPhone, iPad, Apple TV | HLS | FairPlay (AVPlayer, Safari) |
Your player needs: the address of the delivery, the license server address of your provider and the license token of the viewer (DoveRunner: in the pallycon-customdata-v2 header). For FairPlay it also needs the FairPlay certificate address from your provider.
The license token
Your platform creates the token on its server, for every viewer, with the content ID, the DRM type and the rules (for example how long the license is valid), and signs it with the keys of your provider account (DoveRunner: Site ID, Site Key and Access Key). Keep these keys on your server — never in the app or in the web page. Your provider documents the exact format.
How it behaves
- A new key at every start. When the channel restarts, the players load the new manifest and ask for a new license by themselves.
- The provider does not answer: the channel does not deliver anything on the DRM addresses and tries again. The content never reaches the DRM addresses unencrypted.
- No Enterprise license, no provider set, or a codec Shaka cannot take (AV1, VP9, copied MPEG-2): the channel starts without the DRM output and its log says why; the other outputs keep running.
- Live clock: the DASH manifest tells players the time of the server (from
/live/time, with a public time server as backup), so devices with a wrong clock still find the current segments. With the Public domain set tohttps://…, players use the full address of your server. - The keys received from the provider are kept only while the channel runs, readable only by Castreon, and deleted when it stops.
If it does not work
- Test connection: "… refused the key request: HTTP 401 (or 403) — check the token in the KMS address" — the KMS Token (or the CPIX address) is wrong or was regenerated at the provider.
- "the DRM provider sends the keys encrypted for a recipient" — turn off key encryption (CPIX with certificate) in the provider account; the connection is HTTPS anyway.
- "the DRM provider did not send the data for FairPlay" (or another system) — the system is not active in your provider plan.
- The channel log says "warning: the DRM output is off — …" — the reason follows: the plan, the provider settings, the codec of the profile or the source.
- The player loads the manifest but gets no license — the problem is in the license token or the provider account: the content ID (with
-hlsfor HLS), the DRM type, the validity time, the provider keys. Your provider's test tools (for DoveRunner: DevConsole) show the exact error code. - No picture in the browser, no error — the page or the stream is on HTTP; browsers only allow DRM over HTTPS.