Settings
Detailed app behavior for settings.
Request allowances are edited in Request Defaults and each user’s existing request-settings page. Each media allowance can inherit the User default, replace its whole count/window rule, or be unlimited. User pages show effective rules and usage; Reset selected allowances confirms the exact units restored and records an administrator audit. Request allowance is the last entry under Settings > Account (/settings/request-allowance); opening it shows usage, remaining units, and local next/full replenishment times. These controls are hidden when the server does not advertise request_quotas.
Movie, season, book-format, and album controls keep allowance data out of the request flow. Refusals show a short toast naming the blocked category, such as Movie request limit reached., and preserve the user’s choices for an explicit reduction. If both book formats exceed their limits, the toast names both. Availability and playback remain usable at zero remaining. Allowance settings refresh after request changes, request_quota_changed events, resume/reconnect, and rolling-window expiration. Movie delivery now uses the same saved waiting/retry states as the other media.
TV matches (/settings/tv-matches, under Request Settings) and Correct TV match inside the TV detail’s Report a problem sheet are admin-only and hidden on older servers without tv_match_corrections. There is no separate correction button or header menu. The editor shows bundled/custom provenance, searches Sonarr or accepts a TVDB ID, and requires an explicit target season for every source season. Save creates a local override; Pause matching blocks resolution; Restore bundled / default removes the override behavior. Revisions reject stale edits. None changes monitoring. Affected-request previews show recorded/intended targets, the pinned library and exact season/pilot scope, including unverified legacy targets. Confirming creates an idempotent linked corrective request, preserves original history/files/monitoring, and retains normal approval requirements.
On movie and TV details, Report a problem appears after an accepted request (including Pending Approval), for existing Downloading/Partial/Available titles, or when a matching, status-read, or submission error blocks requesting. Initial loading, cancelled options, and denied approval alone do not reveal it. A blocked TV match can therefore be corrected before Request is usable. TV admins retain the correction shortcut when reporting is disabled, but cannot submit reports through it. An existing report remains scoped to the selected library: TV admins find View your report alongside corrections in the same sheet; other users keep the direct report shortcut. Opening a correction submits neither a request nor a report. Settings remains available before any request or error.
The Notifications section appears between Admin and Needs attention menu and groups Push Notifications (everyone) and Discord Notifications (admins). Inside Push Notifications, admins open Server settings (/settings/push-notifications/server) to allow push and individual categories for the server. These controls allow delivery; each person can still opt out. A disabled personal choice explains whether the server or the account has muted it. Self-tests and admin tests respect both master switches. Preferences save immediately, one change at a time, and failed saves preserve the previous choice.
Discord Notifications (/settings/discord-notifications, admin only) configures one text-channel webhook for new media requests needing approval; Include automatically approved requests is off by default. The integration is opt-in and explicitly discloses sharing titles, requester usernames, media types, and approval states with Discord/channel readers. The webhook field is write-only, blank preserves a saved destination, and Remove clears and disables it. Send test message tests the entered or stored webhook without saving or enabling. Turning off auto-approved alerts cancels only those waiting to send. Recent deliveries distinguish waiting, delivered, failed, cancelled, and unconfirmed sends; Refresh preserves unsaved edits. Unconfirmed posts are not automatically resent. Settings search includes this screen, and leaving with edits uses the standard unsaved-changes guard.
- Unsaved settings: Leaving an edited settings page asks whether to Keep editing or Discard changes. This covers Back, browser history, sidebar navigation, and editable connection dialogs. Saving successfully or restoring the saved values clears the warning; failed saves keep the draft. Opening a child page preserves the editor. Browser refresh/close uses the browser’s own warning where supported. Controls that save immediately do not leave an unsaved draft.
- Account (every role): the tile under Settings > Account names the signed-in user and their role; a kids account reads
Kids account · movies up to PG · shows up to TV-PG, the one place the app tells a child what their account is limited to. - Video apps (
/settings/video-apps, Settings > Account, every role with a video server): one iPhone/iPad preference per configured Plex, Jellyfin, or Emby service type. Use admin default inherits each instance’s Default video app; explicit choices are the service’s official app, Infuse, and Browser. Choices are saved per Cantinarr user and server, including separate overrides for different video services. Missing preferences keep the official app. Settings search includes Infuse and the service names. Install Infuse and connect the media servers there first. Android retains each service’s official app; web and desktop use the browser. Guide and title actions refresh after preference saves, configuration changes/reconnect, and resume. - Listening apps (
/settings/listening-apps, Settings > Account, every role with Audiobookshelf): separate iPhone/iPad and Android choices saved with the current Cantinarr account. Use admin default follows each Audiobookshelf instance; a personal choice, including Browser, overrides it. iPhone/iPad supports Browser, Audiobookshelf, and ShelfPlayer; Android supports Browser, Audiobookshelf, and TheShelf (rmc.theshelf.player). Install and sign in first. Failed native launches fall back quietly to the original browser link; web and desktop always use the browser. Settings search includes the app names. - Sign out (every role): a Server-section tile that disconnects this device, landing back on the connect screen so the app can be pointed at another server (the way out of the demo). Confirms first, then best-effort unregisters push and revokes the device session server-side, and always clears local credentials: signing out works fully offline. The stable hardware id survives so reconnecting dedupes to the same device row.
- External Address (admin): the origin connect links and passkey links are built from, so an invite works for someone who can’t reach the admin’s LAN. Left unset, a link uses the address the generating admin’s own app connects with, and the invite dialogs say so. The invite dialogs also spell out what a connect link is: it signs one device into the app, once; ongoing web sign-in is what the per-user password/passkey grants on the Users screen are for.
- Outbound Proxy (admin): the proxy the server’s internet-bound traffic leaves through: TMDB, Trakt, the hosted AI providers, plex.tv, the update check, and the push relay. Arr instances, download clients, Plex Media Server, Jellyfin/Emby/Audiobookshelf, Tautulli/Tracearr, and the Local AI provider are never proxied, so there is no bypass list to maintain for the LAN. The dialog takes an
http,https,socks5, orsocks5haddress such ashttp://proxy:8118(no path) plus an optional username and password, and its Test button fetches TMDB through the candidate proxy and shows the server’s reason when that fails (wrong port, wrong password, and so on); saving a blank address clears the setting. The password is write-only: it is never shown again, and leaving it blank on a later save keeps the stored one. With nothing set here, the server’sHTTP_PROXY/HTTPS_PROXY/NO_PROXYenvironment applies to the same traffic instead, which is also the right layout for a self-hosted push relay on the LAN. - Settings search: a search field on the main Settings screen that reaches across every settings screen, not just the visible tiles: results come from a curated index of the app’s static settings (titles, synonyms, screen and section names), each shown with a “Screen › Section” breadcrumb saying where it lives. Results are filtered by what the signed-in account can actually see (role, permissions, server capabilities). Tapping a result opens the owning screen with
?highlight=<anchor>, which scrolls the exact control into view and flashes a fading accent ring (reduced-motion devices jump and show a static ring); results that live on the Settings screen itself dismiss the search and reveal their row in place, and action tiles (About, External Address, Outbound Proxy, Update Portal…) run directly from the results. - Setup Checklist (admin): a live guide at
/setup, derived from actual server configuration. One Features list shows what’s configured and offers Set up and Skip for the rest, with neutral accent colors while items remain. Skips apply server-wide, remove unconfigured items from every progress and reminder count, and stay visible as Skipped; tap that chip to restore an item. Setting up a skipped feature later automatically shows it as configured, and its settings remain accessible. When every item is configured or skipped, the screen and Settings tile show Nothing left to set up with completed progress. The menu reminder starts enabled, can be muted on the checklist, and disappears when no items remain; the Settings tile always stays available. Instance rows preselect Radarr, Sonarr, Chaptarr, or Lidarr; download clients, media servers, and Monitoring (Tautulli or Tracearr) instead prompt for a type. Discovery rows open Settings > Discover and reflect whether an admin has saved a feed/language choice. Completed media downloads opens Settings and checks deployment roots and effective instance mappings. Push notifications opens Settings at the Notifications section (/settings?highlight=root.notifications), below Admin, and explains thathttps://push.cantinarr.comis free to use withCANTINARR_PUSH_GATEWAY_URL. Unknown rows from newer servers still offer Skip without a settings destination. Actions wrap below the description on narrow screens or with larger text. Older servers that refuse a particular skip show a disabled Skip control with a server-update explanation; setup stays available. Skipping changes checklist progress only; feature requirements, Discover visibility, and access grants continue to apply. - Needs-attention navigation (admin): device-local parity switches for Approvals, Issues, Agent fixes, and Profile approvals control whether each queue stays pinned in the menu or appears only while it has active work. The same rows live in Settings, where each row also opens its queue: so a queue whose menu entry is hidden always has a stable doorway, and the switch rides along as the row’s trailing control.
- Agent Auto-Approvals (admin, Settings): manages the standing rules armed from the approve dialog: each card shows the rule’s fixed label, Active/Paused state with the server’s pause reason, and its approved/resolved track record, with Pause / Resume / Delete actions (delete confirms first; decided fixes keep their audit history).
- Instances (admin): add/edit all sixteen service types; test connections; set the global default (single-default invariant with takeover confirmation). A non-default Radarr/Sonarr instance (and every Chaptarr and Lidarr instance) carries a User Access checkbox list: checking a user grants them that library ALONGSIDE their default: additive, never a move: which is what puts the per-request library choice on their request sheet; unchecking removes their access to exactly that library (a legacy pin counts as access here and unchecking clears it too). A Jellyfin, Emby, Plex, or Audiobookshelf instance has no default at all: its User Access list is the whole story (checked users can create their own account there from the menu, or on Plex get their invite; unchecking turns that account off without deleting it, or removes the Plex share, and re-checking turns it back on or sends a new invite), and the form adds two sections of its own: an Address users open field (the browser/app address for sign-in and Open/Watch/Listen links; leaving it blank hides those links; Use same URL explicitly copies the connection URL when users can reach it, while Plex prefills app.plex.tv) and Shared libraries (Default libraries on Audiobookshelf), a checklist read live from the server after a passing connection test (or through the stored key when editing) where nothing chosen means every library, including ones added later, and a stored id the server no longer reports stays checked as “Unknown library” until dropped. Audiobookshelf also has Default listening apps for iPhone/iPad and Android, initially Browser, applying to all libraries in that instance; each user can override them in Account settings. A Plex form has no URL or API key: Link Plex account runs plex.tv’s PIN flow in the browser (the token stays on the server; the form saves with the pin id), a Server to share list offers the account’s owned servers, and an Auto-approve access requests switch grants the server to anyone who shares a Plex email and invites them at once. Radarr, Sonarr, Chaptarr, and Lidarr forms also accept repeatable media path mappings from the path that instance reports to a read-only, server-approved Cantinarr path; no mappings means downloads are off for a new instance. When editing a saved instance the form lists the library folders the arr reports live (tap one to start a mapping) and warns on any mapping whose source path matches none of them. Instant updates (the server-managed Connect webhook) are installed automatically when a Radarr/Sonarr/Chaptarr/Lidarr instance is created, with the outcome reported in the create confirmation; the edit screen shows the live webhook state read from the arr itself and a Configure instant updates button that re-runs the install: credentials rotate server-side and the secret never reaches the device. Video servers also offer a Default video app for iPhone/iPad, overridden by each user’s Video apps preferences; saving it retains library selections and user grants.
- Audiobookshelf libraries (admin): an ABS instance has default libraries and per-user choices under User Access. Each person can follow the default, access all libraries, or receive a specific set before creating an account. Individual choices survive revoke/regrant and default changes. Pending remote updates are shown and retried; linked-only and administrator accounts cannot be changed through these controls.
- Users (admin): invite new users (an app-bar action asks for a name, creates the account, and shows its connect link), roles, re-invites / device links, per-user password & passkey enablement (disabling is a real revoke), included-AI grants, per-user request settings (tri-state inherit/on/off + default instances, plus per-type “also grant” library checkboxes wherever siblings exist: grants widen the user’s per-request choice and never move their default), test push. Enabling an OAuth-backed grant requires an explicit sharing/quota warning. The screen also shows each user’s shared Plex email and whether they are still waiting to be granted (“Asked for Plex access”). Each linked Plex server shows Awaiting Plex acceptance, Active on server, or Server access unconfirmed from current evidence; historical creation no longer produces an invite badge. The account-link picker marks pending invitations and offers Refresh accounts. Library linking and Plex sign-in review are explained separately; the Plex instance’s grant toggle in the same menu is what sends the invite. With a Jellyfin, Emby, Plex, or Audiobookshelf instance configured, each row shows the Cantinarr grant, Managed by Cantinarr / Linked only / Protected administrator, and remote access or pending/unconfirmed status separately. Link … account… links an existing identity and grants it in Cantinarr; its management checkbox is unchecked by default. Turn … access off/on edits the actual instance grant and changes remote access only for managed accounts. Manage … access… confirms applying the current grant, Stop managing … access… retains the link and remote state while canceling pending changes, and Unlink … account forgets the link while retaining the grant and remote account. Delete confirmation names managed servers affected. Old servers without the config capability keep legacy descriptions and omit unsupported controls. A failed read of the account rows is named as such rather than shown as nobody having one. The screen’s Import from a media server action (a chooser first when there are several) lists the server’s accounts with what importing each would do (“New Cantinarr user …”, “Existing Cantinarr user …”, “Already linked to …” for rows that cannot be picked, plus administrator, turned-off, and invite-pending marks); Select all skips administrators; the picked accounts become Cantinarr users of the same name, granted and linked (linked only by default; an unchecked management option explicitly enables access management and re-enables ordinary disabled accounts), and the sheet then shows each outcome with a Copy link per user that was created (and Copy all links), with the same “address your app connects with” hint as a single invite when no External Address is set. A Kids account section leads the same per-user screen: the switch, the ratings region, the highest movie and TV rating for that region (from the server’s rating schemes; the suggested starting caps are US PG and TV-PG), Hide unrated titles, and hidden genres per media type as chips. Turning it on pre-sets Require approval to On (still editable), the policy is written first and only when it changed, the row carries a Child tag once it pops, and the server does every bit of the filtering: the app never filters on the device. An admin target has no such section, and neither does a server too old to have kids accounts (the certifications route is the probe).
- Request policy (admin): global require-approval, season choice + default scope, quality choice + default profiles.
- Devices (admin): every connected device with hardware model, last-seen, “This device” badge, and revoke.
- Credentials (admin, write-only): the included server AI profile: Anthropic/OpenAI/Gemini/xAI API keys or a shared OpenAI (OAuth) or xAI Grok (OAuth) connection and provider/model selection. When the server offers it, the OpenAI provider also shows an optional base URL field so included access can run against a self-hosted OpenAI-compatible server (llama.cpp, vLLM, Ollama); leaving it empty uses api.openai.com, and personal OpenAI keys are never redirected. AI saves show a testing state and succeed only after one small tool-free, low-reasoning response turn. Validation distinguishes invalid credentials, unsupported model access, exhausted quota, and temporary provider outages without exposing upstream secrets. A default-on daily shared-model test can be disabled to eliminate background usage; failures open one admin issue.
- AI Access (self-service): choose included access when the admin grants it, or configure a personal Anthropic/OpenAI/Gemini/xAI key or an OpenAI (OAuth) / xAI Grok (OAuth) link at any time, with or without a grant. The included panel is listed first; while included access is the active source the personal panel rolls up into a tappable one-line summary so it reads as the optional override it is. A personal provider need not match the server provider. Personal and included sources are labeled separately, keys are write-only, and a broken personal override is never replaced by surprise shared usage. Key and model are tested and saved together so a failure keeps the prior profile intact and shows the same safe actionable error category.
- OpenAI OAuth: personal and admin-shared device-code flows open ChatGPT sign-in in the browser, poll until approval, perform a small response test, show the owning account’s current Codex usage windows, and support disconnecting it. The model picker includes OpenAI recommended and GPT-5.6 Sol, Terra, and Luna. Passwords and OAuth tokens never pass through the app; authorization is encrypted on the server. Only admins can see shared-account identity and usage metadata.
- xAI Grok OAuth: the same personal and admin-shared device-code pattern against xAI’s sign-in page for SuperGrok / X Premium+ accounts: show a one-time code, poll until approval, run the response test, display the linked account email and plan, and support disconnecting. Grok models are shared with the API-key path.
- AI tools (admin): per-tool toggles for chat + MCP, and a one-hour debug-logging switch.
- Configuration history (admin): a durable record of AI/MCP quality-profile and custom-format writes, with the initiating admin/source, exact instance and resource, and bounded before/recorded/current differences fetched from the live service. The recorded value is labeled as applied, attempted, or intended according to the outcome. Each successfully applied quality-profile update can be restored once, only while its live state still matches; success appears immediately as a linked append-only restore record that cannot itself be restored. Custom-format history supports live comparison but not restore; generic admin-proxy or managed-webhook writes are not represented.
- Profile Change Approvals (admin): the consent surface for quality-profile changes proposed by external MCP agents at
/settings/profile-approvals. Each pending proposal shows the server-rendered diff, the proposing admin and MCP client, and Approve/Reject: approval executes server-side against re-validated live settings (a drifted profile refuses and the agent must re-propose), rejection changes nothing on the arr. Aprofile_change_pendingpush (sharing the agent-fixes preference) deep-links here; decided proposals stay visible in a Recent section. The drawer’s needs-attention menu carries a Profile approvals entry with a live pending-count badge (seeded from the list endpoint, kept fresh byprofile_change_pending/profile_change_decidedevents, counted in the hamburger dot) and the same only-show-while-pending switch as the other admin queues. - AI remediation (admin): master switch, auto-dispatch, reporting affordance, mark-resolved-issues-as-read,
supervised/investigate_onlymode, an optional remediation-only model override, step/turn/time and daily-run budgets, reporter-reply timeout, and minimum-watch / arr-quiet / recovery-settle timers that delay investigation and alerts while Radarr or Sonarr can still recover on its own. This server-owned agent always follows the currently selected admin shared provider and credential, including the shared OpenAI OAuth connection; it never uses personal credentials or per-user included-access grants. The override must pass a small response test with that shared provider, and a later provider change safely falls back to the shared model until a new override is tested. - Discover (admin, under Modules): includes the four conditional visibility switches under Discover tabs, picks which feed backs the headline discovery row, hosts the write-only TMDB and Trakt credentials those feeds run on, and offers an English-only switch (on by default) that hides movie and TV titles whose original language is not English from their discovery and recommendation rows. Book search uses Chaptarr and music uses ListenBrainz/MusicBrainz independently of these controls. Search is never filtered, and a title the metadata source did not classify is kept rather than hidden. The Trakt source carries a Recommended tag and: because Cantinarr ships a built-in Trakt application: backs the headline rows out of the box; an admin client ID (entered just below) replaces the built-in app, and on a build without one the row is shown but unselectable, tag included, until an ID is added.
- Update Portal (admin): optional link to your own container-management portal (e.g. an Unraid or Portainer page). The app-wide banner slot carries the warn-only version-skew notices: “update this app” for everyone when the app is older than the server’s floor (never on web: the served web app is always in step), and “update the server” for admins when the server is older than the app’s floor; each dismisses per exact version pair, and the server one’s primary action is this portal (or the update guide when unset). The slot deliberately carries no “a newer Cantinarr is available” bar: the server still computes that comparison for
/api/admin/update-status, but nothing nags about release news. The About sheet shows the running server version alongside the app’s own version and build number; per distribution channel, so a TestFlight build, a Play build, and the web bundle a self-hosted image serves each report their own number. - Project links: the About section links to the GitHub repository, the Discord (questions, help, and release news; it ships in every build, because a community link is not an external-payment link), and the public roadmap (a “Request a feature” tile: anonymous voting, no account), plus a GitHub Sponsors donate tile on the web bundle and desktop builds only; store payment policies keep external donation links out of the iOS/Android binaries.
- Get the phone app: an About tile (web bundle and desktop builds only; the store binaries are the apps it advertises, so they never show it) opens a sheet linking the iPhone beta on TestFlight and the Android beta at cantinarr.com. The same sheet also offers itself exactly once per device, right after a first successful request: the moment the phone app has something concrete to add (a push notification when that request is ready). Dismissing it any way counts; the tile remains the permanent home for the links.
- Push Notifications, Passkeys, Password: self-service (passkey/password screens appear when admin-enabled).
- Media server access guide (
/media-servers): for users an admin granted a Plex, Jellyfin, Emby, or Audiobookshelf instance, and for anyone on a server that has Plex: a Watch on Plex / Watch on Jellyfin / Watch on Plex or Jellyfin menu entry (titled from the granted set), a Media server access row under Settings > Guides, and the instance’s own tile in Settings all open it. A Plex card is the invite flow: Sign in with Plex runs the plex.tv PIN flow with the user’s own account from a sheet (plex.tv opens, the sheet polls, with “I’ve approved, check now”, “Reopen plex.tv”, and Cancel) and the server links the share that account already holds or sends the invite to its verified email, saying which in a snackbar; Share my Plex email opens a sheet for the email instead and the invite goes out (an address someone already shared by hand is adopted instead); the card then reads the live share from plex.tv: invite pending (accept it from the email or under the bell at app.plex.tv, with a “Wrong email?” link), accepted (where to sign in; the server’s owner reads “You own {server}”), or “couldn’t confirm” when plex.tv was unreachable: and a user who holds no Plex grant sees one ask-for-access card instead, with the same two actions: signing in or sharing their email notifies the admins (or, with auto-approve on the instance, grants and invites them within seconds). The old/plex-guideaddress redirects here. It re-readsGET /api/media-serverson every open, resume, and pull-to-refresh and shows one card per server: Create my account opens a sheet where the user picks a password (min 8, confirmed, never kept by Cantinarr) and the account is created under their Cantinarr username; I already have an account opens a sheet for that account’s username (prefilled with the Cantinarr one) and password, which the server checks with the media server once and never keeps, administrator accounts included; when the server reports an unlinked account already named like the user (existing_account), the card says so and leads with Sign in to link it instead, with “Not yours? Ask your admin.” and no create button, since creating could only collide; an active account shows the username with copy, an “Administrator account. Cantinarr never changes it.” line when it is one, the admin-typed sign-in address with Copy address / Open (Open prefers the installed official app on iOS/Android and falls back to that address; “ask your admin” appears when none is set), and a “couldn’t confirm this account just now” line when the server was unreachable rather than a silent claim; a turned-off account says so with nothing to tap. Refusals are said in requester words (name already taken -> go back and sign in with it via I already have an account, or ask your admin; a wrong password, an account the server refuses, or one already linked to another user -> said so, with what to do next; already have one -> the card refreshes). All account cards appear first, labeled with both the service and server name; each server has its own account or invitation and credentials. Separate instructions follow once per relevant service; Plex, Jellyfin, Emby, then Audiobookshelf; with provider app-download links, sign-in steps, and links explaining Plex remote playback requirements and Emby app unlocks and Premiere. Video installation instructions remain visible in mixed audio/video setups. Available means the files have arrived; the media server still needs to scan them. Watch on and Listen in … require a verified match for the account; a general Open shortcut does not confirm that a title is present. Mobile video apps may open their home screen even after a verified Watch link, so the guide explains how to find the title there. With nothing shared (and no Plex to ask for), it explains the absence differently for requesters and admins. Audiobookshelf uses the same create/link account cards, with Audiobookshelf access as the menu title when it is the only service and Media server access for a mixed audio/video set. Its instructions cover browser or compatible-app sign-in, the separate Chaptarr grant needed to see and request books in Cantinarr, and listening after a library scan, and choosing an app in Settings > Account > Listening apps. The guide’s Open action uses that choice; browser links always use the configured address users can reach. All account cards distinguish managed from linked-only access and show pending access changes separately from Plex invitation acceptance. A deliberately unlinked Plex server offers Link my Plex account; general Plex sign-in does not reconnect it automatically. - Media guide navigation preference; the Hide from main navigation switch sits directly below the guide title, outside the scrolling content, including during loading, failed connections, incomplete accounts, and pending invitations. It immediately hides or restores the shortcut in both the mobile drawer and desktop sidebar while leaving the current page open. The choice is saved on this device/browser separately for each Cantinarr server address and user ID. Settings → Guides → Media server access, its Settings search result, and
/media-serversremain accessible. Hiding records the granted media-server instance IDs: a new grant, including another instance of the same service, clears the preference and restores the shortcut until it is hidden again. Renames, account-state changes, removed access, and failed connections do not reset it. Requesters use the grants in configuration; admins use their own user-grants endpoint because their configuration includes ungranted servers too. Configuration changes, reconnects, and app resume refresh that information; failures retain the last successful set. When an admin hides before any grant read has succeeded, the first successful read establishes the baseline. With no eligible media server or requestable Plex access, the existing eligibility rules still omit the shortcut.