Help and user guide
Mestrio Stream Server turns an Android device into a local media server and operations console. It can accept live inputs, pull remote streams, relay existing encoded media, publish local files, record sources, and expose playback endpoints to clients on the same device or network.
1. Quick start
- Open Overview and tap Start server.
- Allow notifications if Android asks. The persistent notification keeps the server visible and provides a Stop action.
- Open Addresses, choose the host reachable by your client, and set an example app and stream name.
- Publish from a camera, encoder, OBS-like client, another server, or a Workbench task to one of the generated publish addresses.
- Open Sources to confirm that the media source is online, inspect its tracks, copy a playback URL, or run an in-app playback test.
- Use Library to record a live source or import and distribute a media file. Use Monitor for sessions, traffic, server events, and WebRTC room administration.
The interactive guide under My → Interactive guide highlights the same workflow in the live interface without starting the server or creating media tasks for you.
Choosing the correct host address
- Use
127.0.0.1only for a client running on the same Android device. - Use the device's Wi-Fi or Ethernet address for another client on the same network.
- Mobile networks, guest Wi-Fi, VPNs, firewalls, and router client isolation can prevent inbound connections.
- A public Internet connection normally requires router port forwarding, a VPN, or another secure tunnel. The app does not configure NAT traversal automatically.
2. Core concepts
Publish, pull, playback, and RTP
| Action | Meaning | Typical use |
|---|---|---|
| Publish / push into the server | An external producer sends an encoded live stream to this device. | A camera or encoder publishes RTMP, RTSP, SRT, or WebRTC WHIP. |
| Pull / ingest | This device actively connects to a remote playback URL and registers the received stream locally. | Bring an IP camera or remote server stream into the local source list. |
| Playback | A viewer connects to a local source through RTSP, RTMP, HLS, HTTP-FLV, WebRTC, or direct MP4. | Watch, validate, or distribute a source. |
| Republish / push out | This device sends an existing local source to another server. | Forward a camera to a remote RTMP/RTSP/SRT endpoint. |
| RTP send or receive | Raw RTP packets carry encoded tracks without a higher-level publish session. | GB28181, broadcast equipment, or an integration that already negotiates port, SSRC, and transport. |
Live publication versus file VOD
- Shared live publication: a local MP4 is published as one server-side timeline. All viewers join the current position. Loop and idle-close behavior can be selected. It produces the enabled live protocol outputs.
- Private RTSP VOD session: one seekable RTSP session starts from a selected position for a particular validation workflow. It is independent of a shared publication and ends at EOF or when stopped.
- Direct HTTP(S) MP4: the original compatible file is served over HTTP. Each player has an independent seekable timeline and no live source is created.
- Generated HLS VOD: the file is packaged into an HLS playlist and segments. Each viewer can seek independently after generation completes.
Port value 0
For a fixed server listener, port 0 means that listener is disabled. In the RTP receive task wizard, port 0 has a different task-level meaning: allocate an available even RTP port automatically. The app labels both cases where they appear.
3. Overview
Overview is the operating dashboard for the embedded server.
Server lifecycle
- Start server launches the media engine in its own Android process and starts an Android foreground service.
- The six-state status model distinguishes disconnected, stopped, starting, running, stopping, and failed states.
- Stop server closes listeners and active network sessions. Recording, pull, relay, or VOD tasks that depend on the engine are interrupted.
- The foreground-service notification shows that the server may continue while the UI is in the background and offers an explicit Stop action.
Dashboard metrics
The dashboard summarizes registered media sources, active client sessions, recording tasks, and Workbench jobs. These are operational counts, not a guarantee that every client can decode every stream.
Connection addresses
The address page generates copy-ready publish and playback URLs from the selected host, active listener ports, TLS state, access-control scope, and example app/stream name. It can show RTSP/RTSPS, RTMP/RTMPS, HLS/HTTPS HLS, HTTP(S)-FLV, WebRTC signaling, SRT, and direct web endpoints when applicable.
Runtime status and diagnostics
The runtime component view presents product-facing protocol and packaging availability. Diagnostics can check configured TCP listeners on the local interface. It does not test every remote route, UDP path, client decoder, or certificate trust store.
4. Server settings
Stop the server before editing listener ports. Saved settings take effect on the next start.
Listeners and protocols
| Group | What it enables | Notes |
|---|---|---|
| HTTP / HTTPS | Web APIs, HLS, HTTP-FLV, direct MP4, and WebRTC HTTP signaling. | HTTPS requires a valid imported or local certificate identity. |
| RTSP / RTSPS | RTSP publish and playback, including file VOD sessions. | RTSPS clients must trust the certificate and support RTSP over TLS. |
| RTMP / RTMPS | Common live publish and playback workflows. | RTMPS requires compatible TLS support at the client. |
| WebRTC | WHIP/WHEP signaling and low-latency media. | Codec negotiation and network reachability still apply. |
| SRT | Encrypted or unencrypted MPEG-TS-compatible SRT ingest and output. | A matching passphrase is required when encryption is used. |
| RTPProxy | A fixed RTP reception service. | Separate from task-specific RTP receive ports. |
| Admin Shell | Advanced administrative command access. | Off by default. It requires access control and uses user admin with the saved access token as password. |
TLS certificate management
The app can use its local self-signed identity or import multiple PKCS#12 (.p12/.pfx) and combined PEM identities. Enter the password before selecting a protected identity. Review issuer, validity, and expiry status after import, then explicitly activate the identity to use on the next server start. The active identity cannot be deleted. Certificate material remains in app-managed storage.
Configuration profiles
A configuration profile captures listener ports, access-control policy, role credentials, network scope, and the selected TLS identity. Applying a profile temporarily stops a running server, validates the target, restarts it, and restores the previous configuration if startup fails.
Access control
Access control can protect publishing, playback, or both. The app generates a token of at least 16 characters and can place it into generated client addresses. HTTP clients may also use Bearer authorization where supported. Regenerating the token invalidates previously generated protected URLs.
- Use different app/stream names to separate workflows, but do not treat names as authentication.
- Keep the token private. Avoid screenshots or logs that expose protected URLs.
- Enable TLS when credentials or private media cross an untrusted network.
Local control API
The optional /api/v1 interface is disabled by default. It requires the admin Bearer token and accepts only loopback clients unless LAN access is explicitly enabled. Read endpoints expose status, sources, sessions, workflows, recording plans, recordings, and storage. Mutating endpoints can start a saved workflow or recording plan, stop a recording, close a source, kick a session, or run safe storage cleanup. Supply a unique Idempotency-Key header for retryable mutating requests.
5. Sources
Sources is the live registry of media currently known to the server. Pull relays, external publishers, RTP/GB28181 inputs, WebRTC inputs, shared file publications, and private VOD sessions are labeled separately.
Finding and inspecting a source
- Pull down to refresh, type an app/stream value in Search, or use the type filter.
- Open a source to view ingress type, online state, reader counts, total and live traffic, and available tracks.
- Inspect video codec, resolution, and frame rate or audio codec, sample rate, and channel count.
- Copy a generated output URL or select Preview for an in-app end-to-end check.
Source actions
The action shown depends on source ownership. You may stop a pull relay, RTP receiver, WHEP pull, GB28181 preview, shared file publication, or private VOD session; disconnect an external publisher; stop MP4 recording; or close a temporary source. Closing a source interrupts its readers and any dependent output.
A source can disappear because its publisher disconnected, a file reached EOF, an idle-close policy fired, the server stopped, or its owning task was explicitly stopped. Owned file sessions are reconciled by lifecycle events rather than a single transient registry miss.
6. Workbench
Workbench creates active ingest and output jobs. Start the server first. Running, reconnecting, failed, and stopped jobs appear under Active jobs, where an explicit stop also cancels automatic reconnect.
Saved workflows can restore when the server starts or after a device restart according to their recovery setting. The task page keeps recent run records including start, reconnect, stop, and failure outcomes.
Pull relay
Purpose: make a remote playback URL available as a local source.
- Enter a reachable RTSP, RTMP, HTTP, or other supported remote URL.
- Choose a unique local app and stream name.
- Optionally request HLS generation or MP4 recording.
- Create the job, then verify it in Sources and Active jobs.
The remote encoded tracks are relayed; incompatible codecs are not automatically converted.
Republish stream
Purpose: continuously send an online local source to another media server.
- Select a registered source.
- Enter the remote RTMP or RTSP publish URL.
- Create the republish job and monitor reconnect or failure state.
RTP receive
Purpose: accept an RTP sender that already knows the destination and payload agreement.
- Choose UDP, TCP passive, or TCP active mode.
- Enter a local port, or use
0for automatic even-port allocation. - Set an optional SSRC and multiplex behavior. TCP active mode also needs the remote host and port.
- Create the receiver and give the allocated address, transport, port, and SSRC to the sender.
RTP send
Purpose: send one local source as RTP to equipment or a platform that has provided a host, port, SSRC, and transport mode. Select the source, enter the agreed endpoint, and create the send job. RTP is not a discovery protocol; both ends must agree on session parameters.
SRT pull and push
Purpose: carry resilient low-latency MPEG-TS media across unreliable networks.
- Pull to local connects to a remote SRT endpoint and registers a local source.
- Push source sends a selected local source to a remote SRT endpoint.
- Configure URL, latency, and an optional 10–79 character passphrase.
- H264/H265 video and compatible audio are relayed without transcoding. Failed tasks can reconnect with exponential backoff.
WebRTC WHIP and WHEP
Purpose: publish or pull low-latency media through standards-based HTTP(S) SDP signaling.
- WHEP pull connects to a remote WHEP endpoint and creates a local source.
- WHIP push publishes a selected local source to a remote WHIP endpoint.
- The client performs POST signaling, tracks the returned session location, and sends DELETE when stopped.
- WHIP output requires a compatible H264 rendition in the current product. WebRTC codec negotiation, ICE reachability, and client decoder support can still prevent playback.
GB28181 surveillance access
Purpose: let compatible cameras, NVRs, or lower-level platforms register with the phone through SIP, expose their catalog, send live RTP, and accept PTZ commands.
- In Platform, configure the SIP port, bind address, 20-digit platform ID, 10-digit domain, digest realm, and registration password.
- Start the platform and configure the device with this phone's reachable address and matching credentials.
- In Devices, verify registration and refresh the catalog to load channels.
- In Live & PTZ, choose a device channel, start live RTP, then use directional or zoom controls. Send Stop after a movement command when required.
7. Library
Library has three tabs: Recording, Media files, and Delivery tasks.
Recording
- Select an online source.
- Choose MP4, FLV, HLS-TS, or fMP4 HLS when offered.
- Set the maximum segment duration and start recording.
- Use Stop recording from the active task. If the source disconnects, the app finalizes or marks the task interrupted and keeps recoverable output in the media library.
Recording plans
Recording plans run once, daily, or on selected weekdays in the device timezone. Choose the source, output format, start time, total duration, segment duration, and how long to wait for an offline source. The scheduler wakes the foreground media service only when a plan is due and releases a scheduler-owned server after the recording finishes. Use Run now to test a saved plan while the server is running. Recent execution records distinguish waiting, recording, completed, skipped, and failed outcomes.
Importing media files
Use the system file or folder picker. You can copy files into managed app storage for predictable availability, or retain a persistable system document grant when linking is supported. Import progress is stable while the list updates, and failed imports can be cleared. A linked file can become unavailable if the provider revokes access, the source is moved, or removable storage is detached.
Media information
Each file card can show origin, size, duration, video codec (for example H264 or H265), audio codec, resolution, and distribution status. Open Details when the summary is not sufficient.
Direct MP4 delivery
HTTP MP4 and HTTPS MP4 are direct file playback URLs. They do not create a live media source. Each client can seek independently. HTTPS playback fails when the client does not trust the configured certificate.
HLS VOD generation
Generate HLS when you need a playlist and segments suitable for HTTP-based playback. Wait until generation completes before testing the playlist. The generated HLS cache can later be deleted without deleting the source media file.
Publish as a shared stream
- Choose Publish MP4 and enter a unique stream ID.
- Select the publication mode. Looping live publication restarts at EOF; one-shot publication ends naturally.
- Choose whether no-reader timeout may automatically stop the publication.
- Use the Delivery tasks tab to copy all enabled protocol addresses, preview the source, or stop publication.
All viewers of a shared publication observe the same server timeline. Opening a new RTSP preview does not create a new file timeline.
Private RTSP VOD session
Create a private seekable RTSP session only when a client specifically needs RTSP VOD behavior with an independent start offset. It is separate from Publish MP4, appears as its own delivery task, and can be explicitly ended. Starting both creates two different server tasks; it does not change the shared publication.
Deleting and cleaning
Removing an imported managed file deletes the app's copy after confirmation. Removing a linked item removes the library reference, not the original external document. Storage cleanup never silently includes recordings or imported media in the safe temporary cleanup action.
8. Built-in playback verification
The player is a diagnostic client, not proof that every third-party device supports the same protocol and codec. It uses protocol-specific clients and can route supported streams through a reusable MPEG-TS bridge before handing them to Android Media3.
| Input | Verification approach | Common limitation |
|---|---|---|
| HTTP(S) MP4 and HLS | Media3 HTTP playback. | TLS trust, incomplete HLS generation, or unsupported codec. |
| RTSP | RTSP playback with resume behavior where the source supports it. | A shared live file publication joins its current timeline; a private VOD session has independent seeking. |
| RTMP and HTTP(S)-FLV | Native protocol input; H265 can use the common TS bridge instead of relying on FLV codec support in the player library. | The Android decoder must still support the elementary video/audio codec. |
| RTMPS and RTSPS | Secure protocol input can be normalized through the TS playback bridge. | Certificate trust and client-side TLS compatibility. |
| WebRTC / WebRTCS | Native WebRTC rendering and audio track playback. | ICE path, codec negotiation, device decoder, or source timestamp quality. |
If the app reports an unsupported decoder after protocol/container normalization, changing the container cannot fix the missing hardware codec. Try another source rendition or a compatible client. The current product does not bundle FFmpeg software decoding.
9. Monitor
Monitor refreshes at the interval selected in App settings while the page remains visible. Pull down for an immediate refresh.
Sessions
View protocol, remote endpoint, connection duration, live download/upload rates, total traffic, and WebRTC status where available. Disconnect ends the selected client session immediately; it does not necessarily stop the source publisher task that can reconnect.
Events
The event timeline records server lifecycle, media registration/unregistration, access, recording, and related runtime events. It is useful for correlating a client failure with what the server observed.
Rooms and DataChannel
- Signaling room keeper registers this engine with a compatible WebSocket or secure WebSocket signaling service.
- Enter the host, signaling port, local room ID, and whether to use WSS, then register the room.
- Inspect connected peers and explicitly unregister the room to release its signaling and peer state.
- SCTP DataChannel can send a UTF-8 message to one selected peer or broadcast it. Stream ID and PPID are advanced protocol values; keep the defaults unless the peer expects different values.
10. My, settings, storage, and permissions
Mestrio Pro
The Mestrio Pro card shows the current entitlement, localized lifetime price, purchase state, and restore action. Core server and protocol features remain free. The optional one-time Pro purchase unlocks higher task capacity, saved workflows, recording schedules, extended history and export, profiles, storage automation, and advanced security controls. It does not renew automatically.
App settings
- Theme: follow the system, always light, or always dark.
- Language: choose Chinese or English for the app interface. This online documentation is currently English.
- Preferred playback verification protocol: let the app choose automatically or prioritize an available protocol.
- Monitor refresh interval: controls periodic session and throughput refresh while Monitor is visible.
Storage
Review managed recordings, imported media, HLS VOD cache, server web cache, temporary app files, logs, TLS identities, linked files, and other data. Clean only the selected safe category and read the confirmation carefully.
Permissions
- Notifications: allows the required foreground-service status notification on supported Android versions.
- System file grants: are granted through Android's picker for files you select; the app does not request broad storage access.
- Background operation: the foreground service, wake lock, network state, and multicast capabilities support server operation while the UI is not foregrounded.
Interactive guide
Start, continue, or restart the guided overlay. Progress is saved by stable step ID. Skipping and completing are different states, and the guide never starts the server or performs media operations automatically.
Contact and About
Contact us opens an email draft and can include basic diagnostics only when you choose to send them. About shows the app version. Advanced native version details appear only after five consecutive taps on the version presentation.
11. Security checklist
- Bind and expose only listeners you use. Keep Admin Shell disabled unless actively required.
- Enable access control before placing the server on a shared or untrusted network.
- Use TLS with a certificate trusted by your clients; a self-signed identity encrypts traffic but does not establish public trust by itself.
- Use a VPN or authenticated tunnel instead of exposing device ports directly to the Internet where possible.
- Do not share protected URLs, access tokens, certificate private keys, or surveillance credentials.
- Confirm you have permission to ingest, record, relay, publish, or monitor every media source and device.
- Stop the server when it is not needed and review active sessions for unexpected clients.
12. Troubleshooting
A client cannot connect
- Confirm the server status is Running and the protocol listener has a non-zero port.
- Copy the address again using a host reachable from the client.
- Check Wi-Fi client isolation, VPN routing, Android power restrictions, router rules, and desktop firewall settings.
- For TLS, verify the secure port and client certificate trust.
- For protected endpoints, verify the current token and publish/playback scope.
The source exists but playback keeps loading
- Open Source details and confirm that both media tracks are present and timestamps continue to advance.
- Try another output protocol. A valid server stream may still be incompatible with one player library or container.
- Check whether H265, AAC, or another codec is supported by the Android device decoder.
- For HLS, wait for the first complete segment or VOD generation to finish.
- Review Monitor events and active sessions for rejection, disconnect, or no-reader timeout.
WebRTC is frozen, silent, or unstable
Verify H264 compatibility, audio-track negotiation, source timestamp continuity, signaling URL, ICE reachability, and device hardware decoding. Test the same source over RTSP or HLS to distinguish a source problem from a WebRTC transport problem. Repeated rendering crashes should be reported with app version, device model, Android version, source codec, and reproduction steps.
An imported file cannot be opened
A recent-provider URI can disappear when a document provider returns a temporary path or does not grant persistable access. Re-select the original file and choose copying into managed storage for reliable long-term use. Remove or clear failed import entries from the import queue.
A file publication stops by itself
Check whether the publication is one-shot, reached natural EOF, has no-reader automatic close enabled, lost its source file, or was stopped with the server. The Delivery tasks tab identifies the owning task and its final state.
Recording cannot be stopped after disconnect
The task should transition to interrupted or finalizing and keep recoverable output. Refresh the Recording tab and inspect the recent result. If a task remains stuck, stop the server once, preserve the file, and report the task state and event timeline.
Battery optimization stops background service
Keep the foreground notification enabled and allow background operation in the device vendor's battery settings. Some Android variants impose additional restrictions that the app cannot override.
13. Support
Email robinxdroid@gmail.com. Include the app version, Android version, device model, protocol, source codecs, whether TLS/access control is enabled, exact steps, and the visible error. Do not send media files, credentials, access tokens, certificate private keys, or protected URLs unless explicitly necessary and safe.
Author and provider: Robin Wang, publishing under the Mestrio brand.