The web player can decrypt stream segments that are encrypted with AES-128 in HLS or MPEG-DASH streaming packages.

When encryption is used, the manifest playlist file needs to reference the corresponding key file so that the player can retrieve the keys for decryption.

JWP supports three modes for decoding encrypted segments:

  • The key can rotate per fragment or be the same.

  • The key can be hosted externally or be embedded within the index file.

  • Custom initialization vectors (IVs) can be used.

<br />

Below is an example of a playlist file with a custom IV.





JWP does not support SAMPLE-AES in non-Safari browsers.

<br /> <hr />

## aestoken Property



Please be aware that `aestoken` is not supported in Safari on desktop or mobile.

<br />

Using the `aestoken` property, the player can also pass a token to the key request URI, enhancing the security of AES.



<br />

When the web player requests the key, the token is appended as a URL parameter called `token`. This appended parameter allows the key server that is providing the AES decryption key to authenticate whether or not the request is valid. JWP will check to make sure the `?` is present on the key URI and add one if necessary.

<br />

(Script tags will be stripped)