Repository navigation
Your-Spotify #2119
Description
Activity
Caveat found during testing: the Spotify login cannot be completed on a plain LAN IP.
Spotify rejects the redirect URI with
redirect_uri: Insecure. Per their docs:Use HTTPS for your redirect URI, unless you are using a loopback address, when HTTP is permitted. If you are using a loopback address, use the explicit IPv4 or IPv6, like
http://127.0.0.1:PORTorhttp://[::1]:PORTas your redirect URI. localhost is not allowed as redirect URI.So
http://192.168.x.y:8080/oauth/spotify/callbackis not accepted, and neither is anything usinglocalhost. The app itself installs and runs fine on the LAN — only the OAuth step is blocked, which is the step that makes it useful.Two workable setups, both now documented in
json/your-spotify.jsonand echoed in the CT footer:- TLS reverse proxy (recommended) —
API_ENDPOINT=https://your.domain, registerhttps://your.domain/oauth/spotify/callback, then re-run the update so the frontend is rebuilt (the API endpoint is baked into the built client). Spotify validates the URI string only, so an internal CA is sufficient. - Loopback exception — register
http://127.0.0.1:8080/oauth/spotify/callback, setAPI_ENDPOINT=http://127.0.0.1:8080/CLIENT_ENDPOINT=http://127.0.0.1:3000, reach the container viassh -L 8080:<IP>:8080 -L 3000:<IP>:3000.
Also fixed in this script during testing:
pnpm install --dangerously-allow-all-buildswas removed — the repo'spnpm-workspace.yamlalready declaresonlyBuiltDependencies, and pnpm aborts withERR_PNPM_CONFIG_CONFLICT_BUILT_DEPENDENCIESwhen both are configured. The flag came from the upstream Dockerfile, which is stale on that point.- TLS reverse proxy (recommended) —
The Your-Spotify script is ready for testing:
bash -c "$(curl -fsSL https://github.com/community-scripts/ProxmoxVED/raw/main/ct/your-spotify.sh)"Spotify only accepts https redirect URIs (loopback excepted), so the Spotify login cannot be completed on the container's plain IP - it fails with 'redirect_uri: Insecure'. A TLS reverse proxy with a real domain is required for normal use.
Create an app at https://developer.spotify.com/dashboard, put its client ID and secret into SPOTIFY_PUBLIC and SPOTIFY_SECRET in /opt/your-spotify.env, set API_ENDPOINT and CLIENT_ENDPOINT to your https URLs, and register <API_ENDPOINT>/oauth/spotify/callback in the dashboard. The API endpoint is baked into the built frontend, so run the update after changing it.
Two services run here: your-spotify (API on 8080) and your-spotify-web (UI on 3000). Point the reverse proxy at both.
Listening history is stored in the local MongoDB database 'your_spotify'. Back that up rather than /opt.Note: This is not in the official repo yet—it's just a dev version! After merging into ProxmoxVE, it will need to be recreated.
Discord testing thread: https://discord.com/channels/1302816934508630047/1533833819092943041
Sorry, but what is meant with
so run the update after changing it
systemctl restart / reload or when its not enough;
cd /opt/your-spotify pnpm install --frozen-lockfile pnpm --filter @your_spotify/server build pnpm --filter @your_spotify/client build API_ENDPOINT=$(grep '^API_ENDPOINT=' /opt/your-spotify.env | cut -d= -f2-) cp /opt/your-spotify/apps/client/build/variables-template.js /opt/your-spotify/apps/client/build/variables.js sed -i "s;__API_ENDPOINT__;${API_ENDPOINT};g" /opt/your-spotify/apps/client/build/variables.js sed -i "s#connect-src \(.*\);#connect-src 'self' ${API_ENDPOINT}/;#g" /opt/your-spotify/apps/client/build/index.html
i dont have a public URL for this, so i cant test it directly
After running
cd /opt/your-spotify
pnpm install --frozen-lockfile
pnpm --filter @your_spotify/server build
pnpm --filter @your_spotify/client buildAPI_ENDPOINT=$(grep '^API_ENDPOINT=' /opt/your-spotify.env | cut -d= -f2-)
cp /opt/your-spotify/apps/client/build/variables-template.js /opt/your-spotify/apps/client/build/variables.js
sed -i "s;API_ENDPOINT;${API_ENDPOINT};g" /opt/your-spotify/apps/client/build/variables.js
sed -i "s#connect-src (.*);#connect-src 'self' ${API_ENDPOINT}/;#g" /opt/your-spotify/apps/client/build/index.htmland putting it behind a domain in this style
*.*.yourdomain.deworks.My Setup:
Pihole local DNS record pointing to my reverse proxy.
In my reverse Proxy I got two seperate entrys,yourspotify.*.mydomain.deandyourspotifyapi.*.mydomain.depointing at the same IP with their respective ports (8080, 3000).
In Spotify Developer Dashboard my Redirect URI ishttps://yourspotifyapi.*.mydomain.de/oauth/spotify/callback.In my .env the two URIs are set to the ones behind the reverse proxy,
yourspotify.*.mydomain.deandyourspotifyapi.*.mydomain.deUnfortunately, I find this rather fiddly even for ordinary home lab enthusiasts, which is why I’m thinking of not adding it to the main repository in the first place. What do you think? Maybe some tools just shouldn’t exist in our Repo Space ^^
the main part that a bit tricky was to find this code. I believe that if you've setup a few lxcs, you'll know how to use a reverse proxy. I run Pihole so i have to run the local DNS through it but that's setup specific. One thing that may be good having is this code for editing the hardcoded URI next to the .env file and then having a short notice on the PVE Script page to run this file as a list of commands to update the url.
This script works for me, I was able to transfer my Docker setup to this LXC setup.
github-actions commented
on Sep 19, 2026 on Sep 19, 2026 – with GitHub ActionsContributorMore actionsA PR has been created for your-spotify: community-scripts/ProxmoxVE#17376
Merged with #17376 in ProxmoxVE
github-actions commented
on Sep 20, 2026 on Sep 20, 2026 – with GitHub ActionsContributorMore actionsFiles deleted with PR #2304
Name of the Script
Your-Spotify
Script Type
CT (LXC Container)
Does this script support arm64?
arm64 supported
📋 Script Details
Your Spotify records your Spotify listening history and turns it into statistics — top tracks/artists/albums per period, habits by time of day, long-term trends, plus import from a Spotify privacy data export.
LOCAL_INSTALL.mdupstream is stale (says yarn,server/,lib/bin/www.js). Current v1.20.x is a pnpm workspace with rsbuild:apps/server→build/index.js,apps/client→build/(output.distPathinrsbuild.config.ts). The script follows the actual Dockerfiles, not that doc.setup_mongodb,NODE_VERSION="22" NODE_MODULE="pnpm@^10,serve" setup_nodejs,pnpm --filter @your_spotify/server buildand--filter @your_spotify/client build.your-spotify(API :8080, withExecStartPre=node build/index.js --migratematchingapps/server/scripts/run/run.sh) andyour-spotify-web(serve -son :3000).apps/client/scripts/run/variables.sh: copyvariables-template.js→variables.js, substitute__API_ENDPOINT__, and patch theconnect-srcCSP inindex.html. The update path redoes this fromAPI_ENDPOINTin the env file.SPOTIFY_PUBLIC/SPOTIFY_SECRETin/opt/your-spotify.envplus the redirect URIhttp://<IP>:8080/oauth/spotify/callbackin the Spotify dashboard — both flagged as warnings.Source: https://github.com/Yooooomi/your_spotify