Heddohon

ヘッドホン · headphones

Heddohon

A web music player you host yourself,
for Navidrome, Subsonic and Jellyfin.

Listen together over a live link, share a song with anyone, and keep your music server off the internet.

FLAC 24/192 amd64 · arm64 MIT

Install Releases Source

Heddohon on an album page of Bach played by Kimiko Ishizaka, 24-bit FLAC, with the now-playing panel on the right, both tinted gold by the cover

01What it does differently

aListen together

Play for people who are not in the room

Start a session and send its link. Everyone who opens it hears what you play, as you play it, in their own browser and without an account, and can answer with reactions.

Listeners
up to 50
Reactions
5 emoji, 1 a second
Ends
when you end it, or after 12 h

bShared links

A song, an album or a playlist, for anyone with the link

The link plays that one item in the browser, with its cover and the original file, and nothing else in your library. Withdraw it from Settings and streams already playing through it stop.

Lasts
1, 7 or 30 days
Token
256 random bits
Stored as
an HMAC digest

cSecurity

Your music server stays off the internet

browser ─► Heddohon ─► music server

The browser only talks to Heddohon, which fetches every byte from the music server itself. The upstream address appears in no page, script or error. The threat model, the known gaps and each audit are in SECURITY.md.

Credentials
AES-256-GCM, scrypt keys
Sign-in
10 attempts a user in 15 min
Writes
origin checked on every one
Media
sandboxed by its CSP

02And the player itself

  1. Original files

    Up to FLAC 24/192, with the decoded format shown in the player. Optional transcoding to MP3, Opus or AAC from the quality badge. Casts to Chromecast and AirPlay.

    24/192
  2. Coloured by the artwork

    The interface takes its colour from the cover that is playing, in Liquid (dark glass) or Paper (parchment and ink). This page does the same with its screenshots; the switch is in the top bar.

    2 themes
  3. Synced lyrics

    From your music server, or from LRCLIB when you turn it on. A living-room screen shows what plays full screen with the lyrics, for a TV across the room.

    LRCLIB
  4. One app across your devices

    Installs on phones and desktops. The queue and settings follow you, and one browser can pause, skip or take over the queue of another.

    PWA
  5. Your listening, on your server

    Every play kept in Heddohon's own database: top artists, albums and hours, and the albums you played on this date in earlier years. Instant mixes of up to 100 similar tracks.

    history
  6. Navidrome, Subsonic or Jellyfin

    Signs in with the music server's own accounts. SQLite by default, or PostgreSQL.

    3 servers

03Screens

Synced lyrics from LRCLIB in the now-playing panel, the current line highlighted, above the track details
aSynced lyrics, in place of the artwork
An album page scrolled to more albums from the same artist
bMore from the artist, under the track list
A shared song, playing in the browser without an account
cA shared song, for anyone with the link
An album page on a phone, with what is playing and four tabs in one panel at the foot of the screen
dThe player and the tabs, one panel
The full player on a phone, with the cover filling the top of the screen
ePulled up from it, and down to close

On a phone

What is playing and the four tabs sit in one panel at the foot of the screen, within reach of a thumb. A swipe on it skips, a tap opens the full player, and a pull closes it again. The tabs fold away while you scroll down a page.

Music in these screenshots: songs and cover art by Josh Woodward (joshwoodward.com), including "The Nest", "Insomnia", "Only Whispering" and "California Lullabye", under CC BY 4.0; J.S. Bach, The Art of the Fugue, played by Kimiko Ishizaka, dedicated to the public domain (CC0). They are captured by one script against a fresh Navidrome.

04Install

docker compose
git clone https://github.com/zorcerer/heddohon.git && cd heddohon
cp .env.example .env
echo "HEDDOHON_SECRET=$(openssl rand -base64 48)" >> .env
echo "HEDDOHON_SUBSONIC_URL=http://10.0.0.10:4533" >> .env
docker compose up -d
Open
http://localhost:3000, and sign in with your music server account. To expose it publicly, set ORIGIN and read SECURITY.md.
Images
ghcr.io/zorcerer/heddohon and zorcererd/heddohon
Platforms
linux/amd64 and linux/arm64: a Raspberry Pi 4 or 5 on a 64-bit OS, an ARM NAS, an Ampere server. 32-bit ARM is not built.
Tags
latest is the newest release. dev is built from the dev branch once a day when it has changed and passed the test suites.
Unraid
A template is in templates/heddohon.xml.
No Docker
On Node 22 or later: npm ci && npm run build && node build/index.js

05Documentation