Metube Metube

[SSO] Video downloader

Web GUI for youtube-dl (using the yt-dlp fork) with playlist support. Allows you to download videos from YouTube and dozens of other sites

Links:

Authentik ForwardAuth

Authentik ForwardAuth protects MeTube’s browser UI for the media group. Its cookie file is a host credential and must remain in ignored host configuration.

Setup

scripts/authentik-apps.py --application metube --apply
scripts/labctl.py service recreate media/video/metube

Keep localaccess-authentik@file on the router and do not publish MeTube’s UI port. Browser extensions and shortcuts that cannot follow interactive redirects need a deliberate alternative, not a broadly unauthenticated route.

Verify

Confirm a media member can use the UI, a non-member is denied, downloads work, group removal applies after session refresh, and no direct UI route exists.

name: metube
services:
  metube:
    image: ghcr.io/alexta69/metube:2026.09.26
    container_name: metube
    restart: "unless-stopped"
    environment:
      UID: ${PUID}
      GID: ${PGID}
      # Using browser cookies:
      # https://github.com/alexta69/metube?tab=readme-ov-file#using-browser-cookies
      YTDL_OPTIONS: "{\"cookiefile\":\"/cookies/cookies.txt\"}"
    volumes:
      - ${STORAGE_DOWNLOADS}/youtube:/downloads
      - ${INFRA_CONFIG_PATH:-"./metube"}/metube-cookies.txt:/cookies/cookies.txt
    networks:
      - proxy
    labels:
      traefik.enable: true
      traefik.http.routers.metube.middlewares: localaccess-authentik@file
      traefik.http.services.metube.loadbalancer.server.port: 8081
      homepage.group: Media
      homepage.name: Metube
      homepage.icon: metube.png
      homepage.href: https://metube.${MYDOMAIN}/
      homepage.description: "[SSO] Video downloader"

networks:
  proxy:
    external: true