About this project
slskr is a self-hosted Rust daemon, HTTP API, and browser UI for the Soulseek peer-to-peer file-sharing network. It is designed for operators who want a private, scriptable Soulseek client that can run locally, on a server, or behind their own service boundary. A single `slskr serve` process manages the Soulseek session, peer listeners, share index, transfer engine, HTTP API, event stream, and a bundled Web UI.
Key features include:
- **Web Access**: A React-based Web UI served on the same HTTP listener, with search, downloads, uploads, rooms, private messages, users, contacts, browse state, shares, collections, integrations, player controls, configuration status, telemetry, and runtime health.
- **Search and Results**: Supports global, user, room, and wishlist-style targets. Results include peer metadata such as locked state, slot availability, queue length, speed, file size, and path. The UI adds filters, duplicate folding, hidden/blocked users, search history, review notes, acquisition profiles, discovery graph panels, and metadata-assisted follow-up searches.
- **Transfers**: Downloads and uploads are represented as daemon-owned transfer records with queue, start, progress, completion, cancellation, retry, and failure state. Supports local file-backed projections for tests, outbound downloads, inbound shared-file serving, direct peer transfer sockets, type-1 obfuscated transfer sockets, indirect transfer fallback, offset/resume fields, and bounded transfer event history. Accelerated downloads can use `POST /api/v0/multisource/swarm` with multiple HTTP range-capable sources and an expected SHA-256 digest. Short-lived peer and mesh preview tickets stream audio to the browser without creating a normal download.
- **Shares and Browse**: Share roots are indexed at startup or by rescan. The catalog uses virtual share paths rather than exposing raw host paths. Operators can configure hidden-file handling, symlink following, scan limits, and allowed transfer directions.
- **Messaging, Rooms, and Users**: Tracks private-message conversations, message acknowledgement, room lists, room join/leave state, recent room messages, watched users, user stats, contacts, notes, and related peer context.
- **API and Automation**: Versioned `/api/v0/*` routes plus selected unversioned compatibility aliases. API clients can use bearer auth or the `X-API-Key` header. Event consumers can poll bounded event records or subscribe to the WebSocket event stream. OpenAPI and detailed endpoint docs are provided.
- **Integrations**: Includes Spotify OAuth callback handling, Lidarr status/wanted/manual-import flows, external visualizer launch reporting, and UI-side panels for library, source, and recommendation workflows.
Security defaults are conservative: HTTP binds to `127.0.0.1:5030` by default, non-loopback binds require at least one API token unless auth is explicitly disabled, browser-origin mutating requests are checked with `Origin`/`Referer`, sanitized config responses do not return credentials, and share APIs return virtual paths rather than raw host paths.
Deployment assets include systemd examples, Kubernetes manifests, Prometheus rules, and public posture checks. The project includes a certification runner with per-account VPN isolation to bypass Soulseek's per-IP rate limiting, covering 7 phases across 39 test cases. Client libraries are available for TypeScript, Python, Go, and Rust. The project is licensed under AGPL-3.0-only.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.