Installation
Scryer runs on Docker, macOS via Homebrew, release binaries on Linux and macOS, and Windows through Winget or an MSI installer. Pick the method that fits your environment, follow its sub-page, then come back here for the first configuration pass.
Before installing, decide on three persistent paths and keep them on storage that survives restarts and upgrades:
- A config directory
- One or more final media roots
- A completed-work staging path that Scryer can see at a stable location
First-Time Boot Password Configurations
Section titled “First-Time Boot Password Configurations”To require sign-in from the first boot, configure a bootstrap administrator before starting Scryer. SCRYER_AUTH_ENABLED=true alone does not create a usable password on a fresh database.
Use The Default Administrator
Section titled “Use The Default Administrator”Add this environment block to your existing Compose service. Supply SCRYER_ADMIN_PASSWORD through your deployment environment or .env file; the required-value expression prevents Compose from starting with a missing or empty password.
services: scryer: environment: SCRYER_AUTH_ENABLED: "true" SCRYER_ADMIN_PASSWORD: "${SCRYER_ADMIN_PASSWORD:?Set a strong temporary password}"Sign in as admin with exactly the password you supplied. Scryer requires you to choose a different, policy-valid password before normal access, then saves that password in its database.
Use A Custom Administrator And Disable Admin
Section titled “Use A Custom Administrator And Disable Admin”For a public-facing seedbox, you can create a differently named administrator and disable the built-in admin before the server accepts requests:
services: scryer: environment: SCRYER_AUTH_ENABLED: "true" SCRYER_ADMIN_USERNAME: "box-owner" SCRYER_ADMIN_PASSWORD: "${SCRYER_ADMIN_PASSWORD:?Set a strong temporary password}" SCRYER_DISABLE_DEFAULT_ADMIN: "true"Sign in as box-owner and replace the supplied temporary password. Scryer provisions this account before disabling admin and invalidating its sessions. Startup fails if no other enabled local full administrator has a usable password. An administrator awaiting password replacement qualifies; restricted, disabled, passwordless, external-only, and recovery accounts do not.
You can also set only SCRYER_DISABLE_DEFAULT_ADMIN=true when a qualifying alternate administrator already exists. The requirement is checked every startup, even when admin is absent or already disabled. While the flag is active, normal administration cannot reenable admin; removing it does not automatically reenable the account. Do not combine disabling admin with provisioning or resetting that same account.
Read The Password From A Secret File
Section titled “Read The Password From A Secret File”Instead of the direct password variable, mount a secret readable by the Scryer process and set SCRYER_ADMIN_PASSWORD_FILE to its container path:
services: scryer: environment: SCRYER_AUTH_ENABLED: "true" SCRYER_ADMIN_USERNAME: "box-owner" SCRYER_ADMIN_PASSWORD_FILE: "/run/secrets/scryer_admin_password" SCRYER_DISABLE_DEFAULT_ADMIN: "true" secrets: - scryer_admin_password
secrets: scryer_admin_password: file: ./secrets/scryer-admin-password.txtCreate the host secret file with your chosen temporary password before starting Compose. The file takes precedence over SCRYER_ADMIN_PASSWORD. Scryer strips trailing line endings from file contents but preserves other whitespace. An unreadable or empty secret stops startup. For native and Homebrew installations, use the same variables through the installation’s environment configuration, with a file path readable by that service.
Restarts And Explicit Password Resets
Section titled “Restarts And Explicit Password Resets”Leaving SCRYER_ADMIN_PASSWORD or _FILE configured does not overwrite an existing password. Ordinary restarts preserve the database password and any pending password-replacement requirement. Changing the supplied secret alone also does not reset an existing password.
To intentionally reset the selected account, set SCRYER_ADMIN_PASSWORD_RESET=true together with its SCRYER_ADMIN_USERNAME and a password or secret file. The username defaults to admin when omitted. Every startup with reset enabled reinstalls that supplied temporary password, invalidates existing sessions and pending authentication challenges, and requires a different replacement password again. Remove the reset flag after use so later restarts keep the replacement password.
Password reset preserves TOTP enrollment, passkeys, recovery codes, permissions, and MFA policies. Existing MFA is still required to sign in. If MFA is lost, use the separate recovery-admin workflow.
Configuration Checks
Section titled “Configuration Checks”- Bootstrap settings require authenticated operation and disable local-IP login bypass while active. Remove conflicting
SCRYER_AUTH_ENABLED=false,SCRYER_DEV_AUTO_LOGIN=true, orSCRYER_ALLOW_UNAUTHENTICATED_PUBLIC_ACCESS=truesettings. Do not combine bootstrap configuration withSCRYER_RECOVERY_ADMIN_PASSWORD. - Account names are trimmed and validated. Blank names and reserved
anonymousorrecovery-adminidentities are rejected; use an existing account’s exact stored spelling. - A username without a password must identify an existing usable local full administrator. Bootstrap does not promote restricted accounts, reenable disabled accounts, or convert external identities.
- Omit unused variables rather than supplying empty strings. Invalid booleans, empty secrets, and reset without a supplied password stop startup with an error.
- Credential installation and default-admin disabling persist authenticated settings before changing accounts. Later no-op startups preserve saved sign-in preferences, though active bootstrap configuration still enforces authentication without local-IP bypass for that process.
See Configuration for the complete environment reference.
First Configuration Pass
Section titled “First Configuration Pass”- Complete setup and create your first admin user, or sign in with your bootstrap administrator and replace its temporary password.
- Confirm library roots and media paths are configured correctly in Scryer’s Settings. For Docker, verify that mounted paths match what Scryer expects — see path layout and hard linking.
- Choose how Scryer will be reached, including its bind address, reverse proxy, TLS, and any URL prefix. See Networking.
- Set any remaining startup environment overrides your deployment needs. For the full reference, see Configuration.
- Add or scan titles in the relevant facet: Movies, Series, or Anime.
- Configure only the provider instances Scryer needs in Settings.
- Review permissions and navigation before adding additional users.
Keep the first pass conservative: confirm library roots, add a small number of titles, and verify scans, imports, and Wanted state before broadening defaults or user access.
A new instance runs hot for its first day or two while it scans, analyzes files, searches indexers, and encodes artwork. See High CPU After Install.
Related Concepts
Section titled “Related Concepts”- Facet — the behavior category (Movies, Series, Anime) to configure libraries inside before adding titles
- Library — owns roots, permissions, scans, and import destinations inside a facet
- Library Scan — run this after confirming media roots are mounted correctly
- Import — how Scryer moves completed local items into a managed library location
- Monitoring — controls whether Scryer keeps evaluating a title for new or better files
- Wanted Item — what Scryer creates when a monitored title is missing or below cutoff
- Networking — bind addresses, reverse proxies, URL prefixes, TLS, and container connectivity
- Configuration — environment variables and runtime startup knobs
- Permissions — understand access grants before adding additional users
- Upgrading — full upgrade reference for all install methods