Access your Jellyfin server remotely by setting up a reverse proxy, enabling remote access in Jellyfin settings, or using a VPN connection to your home network

Jellyfin is a self-hosted media server that lives on a computer or device in your home. By default, you can only reach it from devices connected to your home Wi-Fi or network cable. To watch your media from outside — at work, on vacation, or from a friend's house — you need to create a secure path from the internet back to your server.

The three main routes are a reverse proxy (most reliable for streaming), remote access through Jellyfin's built-in settings (simplest to set up), or a VPN connection (most private, but slower). Each has trade-offs in complexity, speed, and security. This guide walks you through each method so you can pick the one that fits your setup.

Key Takeaways

  • Remote access in Jellyfin settings is the fastest way to start, but requires you to open a port on your router and exposes that port to the internet.
  • A reverse proxy like Nginx or Caddy sits between the internet and your Jellyfin server, encrypts traffic, and hides your home IP address from the world.
  • A VPN connection routes all your traffic through your home network, keeping everything private but using more bandwidth and potentially slowing down playback.
  • You will need to know your home network's public IP address or use a dynamic DNS service if your internet provider changes it regularly.
  • Port forwarding on your router is required for remote access and reverse proxy methods, and must be done carefully to avoid security risks.

Enable remote access through Jellyfin settings

This is the quickest way to get your free guide. Jellyfin has a built-in remote access feature that creates a secure tunnel to Jellyfin's servers, which then routes your connection back to your home server. You do not need to touch your router or set up any extra software.

Open Jellyfin on the device where your server runs. Go to Dashboard (the gear icon), then Remote Access. You will see your public IP address listed. If it shows a green checkmark next to "Remote Access", your server is already reachable from outside. If it shows red, click the button to enable it. Jellyfin will test the connection and confirm when it works.

On any device outside your home, visit the Jellyfin web address using your public IP address and the port number shown in the Remote Access settings — usually something like 192.0.2.100:8096 (replace with your actual IP). You can also use the Jellyfin mobile app and enter this address in the server settings. The connection is encrypted, so your password and media are protected in transit.

The downside: this method exposes a port on your router to the internet, which increases risk if Jellyfin has an unpatched security flaw. It also reveals your home's public IP address to anyone who watches your network traffic. For most home users this is acceptable, but if you want more privacy or security, use a reverse proxy instead.

Set up a reverse proxy for encrypted remote access

A reverse proxy is a piece of software that sits between the internet and your Jellyfin server. It handles all incoming requests, encrypts them, and forwards them to Jellyfin. This keeps your home IP address hidden and adds a security layer. The most common choices are Nginx, Caddy, or Traefik.

Caddy is the easiest to configure. Install Caddy on the same device as your Jellyfin server (or on another device on your home network). Create a text file called Caddyfile with these lines:

jellyfin.example.com {   reverse_proxy localhost:8096 }

Replace jellyfin.example.com with a domain name you own or rent. Caddy will automatically fetch an SSL certificate (which encrypts the connection) and start forwarding traffic to your Jellyfin server on port 8096. You then point your domain's DNS records to your home's public IP address, and Caddy handles the rest.

The advantage: your actual IP address is hidden behind the domain name, and all traffic is encrypted. If Jellyfin has a security issue, the reverse proxy can filter or block malicious requests before they reach it. The disadvantage: you need a domain name (usually $10–15 per year), and setup is more involved than the built-in remote access. You also still need to forward a port on your router — usually port 80 and 443 — to the device running Caddy.

Use a VPN to route traffic through your home network

A VPN (virtual private network) creates an encrypted tunnel from your remote device back to your home network. Once connected, your device acts as if it is sitting on your home Wi-Fi, and you can reach Jellyfin using its local address — usually something like 192.168.1.50:8096.

Set up a VPN server on a device in your home using software like WireGuard, OpenVPN, or Tailscale. Tailscale is the simplest: install it on the device running Jellyfin, create a free account, and install the Tailscale app on your phone or laptop. Once both devices are logged in, they can reach each other over an encrypted connection, even across the internet. You access Jellyfin using its local IP address as if you were home.

The advantage: everything is encrypted and private, and you do not need a domain name or reverse proxy software. The disadvantage: all your media traffic flows through the VPN tunnel, which uses more bandwidth and can slow down playback if your home internet upload speed is limited. A VPN is best if privacy is your main concern and your home internet can handle the extra load.

Forward a port on your router

Both remote access and reverse proxy methods require port forwarding. This tells your router to send incoming traffic on a specific port to a specific device on your home network.

Log into your router's admin panel — usually at 192.168.1.1 or 192.168.0.1 in a web browser. Look for a section called Port Forwarding, Virtual Server, or UPnP. You will need to enter:

  • The external port (the port the internet sees — usually 8096 for Jellyfin, or 80 and 443 for a reverse proxy)
  • The internal IP address of the device running Jellyfin or the reverse proxy (like 192.168.1.50)
  • The internal port (usually 8096 for Jellyfin)

Save the rule and test it by visiting your public IP address and port from outside your network. If it does not work, check that the internal IP address is correct and that Jellyfin is running. If your internet provider changes your public IP address regularly (which is common), use a dynamic DNS service to keep your domain or address up to date automatically.

Find your public IP address and set up dynamic DNS

Your public IP address is the address the internet sees when you connect from home. You can find it by visiting whatismyipaddress.com or ifconfig.me in a web browser. Write it down, but know that many internet providers change this address every few days or weeks.

If your IP address changes, any bookmarks or addresses you shared will stop working. To prevent this, use a dynamic DNS service like No-IP, DuckDNS, or Cloudflare. These services let you create a domain name that automatically updates whenever your IP address changes. You install a small client program on your Jellyfin device, and it tells the service your new IP whenever it changes. Then you always use the same domain name, and it always points to your current address.

DuckDNS is free and simple: create an account, pick a subdomain like myjellyfish.duckdns.org, and install their updater on your Jellyfin device. From then on, that domain always reaches your server, even if your IP changes. This is especially useful if you are using a reverse proxy or sharing your server address with friends.

Secure your remote access

Opening your server to the internet increases risk. Take these steps to reduce it:

  • Use a strong password for your Jellyfin account — at least 12 characters with uppercase, lowercase, numbers, and symbols.
  • Enable two-factor authentication in Jellyfin if available, so a stolen password alone cannot access your account.
  • Keep Jellyfin updated by checking for new versions regularly. Security fixes are released often.
  • Disable remote access when you do not need it — turn it off in Jellyfin settings if you will not be accessing it remotely for a while.
  • Use a reverse proxy or VPN instead of direct port forwarding if possible, as they add a security layer between the internet and your server.
  • Monitor your Jellyfin logs for failed login attempts or unusual activity. Go to Dashboard and check the logs regularly.

Troubleshoot common remote access problems

If you cannot reach your Jellyfin server from outside your network, start with these checks:

The connection times out or shows "server not found": Your public IP address or domain name may be wrong. Visit whatismyipaddress.com from your home network to confirm your public IP. If you are using a domain name, test it by visiting it in a browser. If it does not resolve, check that your DNS records are pointing to the correct IP address.

You can connect but playback is very slow or keeps buffering: Your home internet upload speed may be too low. Jellyfin streams video from your server to you, so upload speed matters. Test your upload speed at speedtest.net. If it is below 5 Mbps, try lowering the video quality in the Jellyfin app settings. If you are using a VPN, the VPN itself may be the bottleneck — try the reverse proxy method instead.

Port forwarding is not working: Make sure you forwarded the correct port to the correct internal IP address. Log back into your router and double-check the rule. Also confirm that the device running Jellyfin has not changed its internal IP address — if it does, the port forward will point to the wrong device. You can fix this by assigning a static IP address to that device in your router settings.

Frequently Asked Questions

Can I use Jellyfin's remote access and a reverse proxy at the same time?

Yes, but there is no benefit. They both do the same job — let you reach your server from outside your network. Pick one and use it. If you switch methods later, disable the old one first to avoid confusion.

Do I need a domain name to access Jellyfin remotely?

No. You can use your public IP address directly, like 203.0.113.45:8096. A domain name is more convenient because it does not change if your IP address does, and it is easier to remember and share. But it is not required.

Is it safe to open a port on my router?

Opening a port increases risk, but the risk is manageable if you keep Jellyfin updated, use a strong password, and monitor for suspicious activity. A reverse proxy or VPN reduces the risk further. If you are very concerned about security, use a VPN instead of direct port forwarding.

What if my internet provider blocks port 8096?

Some providers block common ports to prevent abuse. Try forwarding a different port, like 8097 or 9000, to your Jellyfin server. Then access it using that port number, like 203.0.113.45:9000. If many ports are blocked, a VPN is your best option.

Can I access Jellyfin remotely on a mobile phone?

Yes. Install the official Jellyfin app on iOS or Android, then go to Settings and add your server. Enter the address you use to reach it from outside your network — your public IP, domain name, or VPN address. The app will connect and let you stream just like on a computer.