Network & remote access
Fregata’s default listeners:
| Port | Service | Bound to | Notes |
|---|---|---|---|
8971 (default) |
nginx → Frigate web UI + HTTP API | 0.0.0.0 |
HTTPS by default (self-signed cert). Set tls.enabled: false in config.yml for plain HTTP. Customizable — see networking.listen.external below. |
5000 (default) |
nginx → Frigate API (internal) | 127.0.0.1 (default) or 0.0.0.0 |
Loopback-only by default. Set FREGATA_EXPOSE_INTERNAL_PORT=1 to expose to your LAN. Plain HTTP, no authentication. If this port is already taken (e.g. by macOS AirPlay Receiver, if left at the default of 5000), Fregata automatically uses port 5050 instead — see below. Customizable — see networking.listen.internal below. |
1984 |
go2rtc admin UI | 127.0.0.1 (default) or 0.0.0.0 |
Loopback-only by default. Set FREGATA_EXPOSE_GO2RTC_PORT=1 to expose to your LAN. Plain HTTP, no authentication. |
8554 |
go2rtc RTSP re-stream | 0.0.0.0 (default) or 127.0.0.1 |
LAN-exposed by default. Set FREGATA_EXPOSE_RTSP_PORT=0 to lock it to loopback-only. Plain RTSP, no authentication by default — see below to add a username/password. |
8555 |
go2rtc WebRTC | 0.0.0.0 |
Needed for low-latency live view from outside the Mac. |
The HA integration and Fregata Mobile only need 8971. Most users don’t
think about the others.
Changing the ports with networking.listen
Section titled “Changing the ports with networking.listen”Frigate’s networking.listen.internal/.external config keys let you
move the two ports above off their defaults:
- In the web UI, go to Settings → System → Networking.
- Under Listening ports configuration, set Internal port (default
5000) and External port (default8971). - Click Save, then Restart when the page asks. Port changes always need a restart, and the menu-bar app’s Open Frigate Web UI follows the new external port. This browser tab keeps pointing at the old port, so reopen the web UI from the tray after the restart.
networking: listen: internal: 5000 # default external: 8971 # defaultA few things worth knowing about how this behaves on Fregata:
FREGATA_EXPOSE_INTERNAL_PORTand the AirPlay-conflict fallback above both follow whichever port ends up “internal” — not literally5000. Set a custom internal port and those still work the same way, just on the new port number.- Only the port number is honored. An
ip:portstring’s host part is parsed and discarded — Fregata’s own loopback-by-default /FREGATA_EXPOSE_INTERNAL_PORTgating still decides what interface it binds, regardless of what host you write here. - Setting
internalandexternalto the same port is rejected when the config is validated: Save fails in the Settings UI, and a hand-edited file fails validation at startup. A collision would let external, authenticated-path traffic land on the unauthenticated internal-port bypass described below, so Fregata refuses it rather than silently creating that hole. - Picking a port Fregata already uses for something else
(
5001,5002,8082,1984,8554,8555) is logged as a warning and will most likely stop Fregata from starting. Pick a free port.
Reaching it from another device on your LAN
Section titled “Reaching it from another device on your LAN”Fregata is happy to serve 8971 to anything on your LAN. Just open
https://<mac-ip>:8971 from a different device — the first visit shows
a self-signed-certificate warning (the same one you click through on
localhost). To avoid the warning on a trusted LAN, turn off Fregata’s
own TLS and use http://<mac-ip>:8971:
- In the web UI, go to Settings → System → TLS.
- Turn off Enable TLS.
- Click Save, then Restart when the page asks. Fregata now serves
plain HTTP on the external port (
8971by default). This browser tab stops loading, because it still points athttps://; reopen the web UI with Open Frigate Web UI in the tray, or go tohttp://<mac-ip>:8971.
tls: enabled: falseThen choose Restart Frigate from the tray.
A couple of practical notes:
- Use a hostname, not an IP. Bonjour gives you
<mac-name>.localfor free; bookmarking that survives DHCP shuffles. Set the hostname in System Settings → General → Sharing → Local hostname. - macOS firewall. If you’ve enabled it (System Settings → Network → Firewall), the first inbound connection to Fregata triggers the standard “allow incoming connections” prompt. Allow it once and the rule sticks.
Fregata Mobile: away from home
Section titled “Fregata Mobile: away from home”Fregata Mobile, the free iPhone, iPad and Apple Watch app (public beta), talks to Fregata directly. There is no Fregata cloud in between, so away from home your phone needs a way to reach your Mac.
The app needs one port: 8971, the one that asks for a sign-in. Don’t
point it at 5000: it has no sign-in, so it should stay off the internet,
and alerts registered through it are lost while sign-in is on (see the
caution under Option A).
Live video and the app’s live updates use WebSocket connections on that
same port, so the app doesn’t need 8555.
You give the app two addresses, At home and Away:
| Address | |
|---|---|
| At home | https://<mac-ip>:8971 |
| Away | https://<tailscale-ip>:8971, or the domain of a reverse proxy |
It tries both, uses whichever answers, and switches by itself as you move between networks. Either one on its own is enough: if a single address works everywhere, put it under Away and leave At home empty.
Ways to make the Mac reachable, simplest first:
- Tailscale or another VPN. Install it on the Mac and on the phone, sign both in to the same account, and use the Mac’s Tailscale address under Away. Nothing is exposed to the internet. See the Tailscale paragraph under Exposing it to the public internet.
- Cloudflare Tunnel or another reverse proxy. Point it at port
8971as in Putting Fregata behind a reverse proxy, and let WebSocket connections through. If Cloudflare Access sits in front, give the app a service token as custom headers. - Port forwarding. It works, but read Exposing it to the public internet first.
Fregata’s default certificate is self-signed. On a home-network address the app trusts it the first time and remembers it. On any other address it shows the certificate’s fingerprint and asks before trusting it. A real certificate from a reverse proxy needs no question.
Without an Away address, alerts still reach the phone away from home, but without their picture, and live view and recordings only work at home.
Only Fregata can do the next part: when the NVR is Fregata, the app steps recordings down on a slow connection and opens live view on a lighter stream away from home. Recordings need adaptive transcoding turned on for the camera, and live view also needs Enable live-view transcoding.
The app’s own pages cover the rest: Away from home and Connect your server.
Putting Fregata behind a reverse proxy
Section titled “Putting Fregata behind a reverse proxy”A common setup: Caddy or Traefik on a NAS or small Linux box, terminating TLS, and proxying to the Mac. The minimum Caddyfile:
cameras.your-house.example { reverse_proxy http://10.0.1.42:8971}Caddy gets you a Let’s Encrypt cert, HTTP/2, websocket upgrade (needed for live MSE/WebRTC), and a clean URL.
Exposing it to the public internet
Section titled “Exposing it to the public internet”Short answer: don’t, unless you absolutely mean to.
Long answer: if you do, the bare minimum:
- Put it behind a real reverse proxy with TLS (Caddy, Traefik, Cloudflare Tunnel).
- Keep Frigate’s authentication on. It’s enabled by default, and the admin password was set in the welcome wizard (see Your dashboard sign-in). The box below shows how to confirm it.
- Restrict by source IP at the proxy if you can.
- Don’t expose
8554(RTSP) or1984(go2rtc admin) to the internet under any circumstance. Neither has authentication by default.
In the web UI, go to Settings → System → Authentication and check that Enable authentication is on.
auth: enabled: trueThe reasonable middle path for “I want to check my cameras from my
phone” is Tailscale or a similar mesh VPN: install on the Mac
and on your phone, hit https://<tailscale-ip>:8971 from anywhere
(click through the self-signed warning once). The Tailscale tunnel is
already encrypted end-to-end, so if you’d rather skip the warning, turn
off TLS (Settings → System → TLS, or tls.enabled: false; see
above) and use
http://<tailscale-ip>:8971. No public exposure, near-zero attack
surface. On an iPhone or iPad, Fregata
Mobile works the same way: put the
Tailscale address under its Away setting.
Mac sleep and Wake-On-Demand
Section titled “Mac sleep and Wake-On-Demand”Fregata keeps the system awake while it’s running. As soon as
the menu-bar status reads Running, the supervisor takes a
ProcessInfo activity assertion with .idleSystemSleepDisabled
and holds it until Frigate stops, errors out, or you quit the app.
You don’t need to touch System Settings; the display is still free
to sleep, only the system itself stays awake.
This means the boring 24/7 install case — Mac mini in a closet, Fregata launched at login, never restarted — just works.
Caveats worth knowing about:
- A laptop that closes its lid still sleeps. Lid closure is a hardware-level signal that overrides every software assertion. If you need 24/7 detection, run on a desktop or use clamshell mode with an external display attached.
- The activity is released on
.errorand.stopping. A Fregata that crashed or was stopped by you doesn’t strand the Mac awake. - Belt-and-braces: if you want the same behavior even when Fregata isn’t running, System Settings → Energy Saver / Battery → “Prevent automatic sleeping when display is off” (desktop) or “Prevent automatic sleeping on power adapter” (laptop).
caffeinatecommand or theAmphetamineapp are still useful to prevent your Mac from sleeping when Fregata isn’t yet running.
Using the API from local automation tools
Section titled “Using the API from local automation tools”Tools like Node-RED or custom scripts that run on your LAN can talk to Fregata’s HTTP API. There are two ways to do it:
Option A — Port 8971 with a Bearer token (recommended)
Section titled “Option A — Port 8971 with a Bearer token (recommended)”This is the standard path and keeps authentication in place.
- POST to
http://<mac-ip>:8971/api/loginwith your credentials:{ "user": "admin", "password": "your-password" } - The response body contains a JWT. Store it in a Node-RED flow variable or script environment.
- Add
Authorization: Bearer <token>to every subsequent request.
Tokens are valid for 24 hours by default. To keep a script running
indefinitely, re-POST to /api/login on a timer (every 23 hours is safe).
Alternatively, turn authentication off. Port 8971 then requires no credentials at all, which may be simpler if the network is fully trusted:
- In the web UI, go to Settings → System → Authentication.
- Turn off Enable authentication.
- Click Save, then Restart when the page asks.
auth: enabled: falseOption B — Port 5000 with FREGATA_EXPOSE_INTERNAL_PORT=1
Section titled “Option B — Port 5000 with FREGATA_EXPOSE_INTERNAL_PORT=1”Port 5000 is nginx’s internal proxy. It has no authentication middleware — requests arrive at the API already labelled as admin. By default it only accepts connections from the same Mac. Setting the environment variable opens it to your whole LAN.
To enable, add FREGATA_EXPOSE_INTERNAL_PORT=1 in the tray’s
Settings → Environment Variables… and restart Fregata. A warning
appears in the Fregata log every time Fregata starts while the flag is set,
so you always have a visible reminder that the port is open.
Point your automation tool at http://<mac-ip>:5000/api/… — no
Authorization header needed.
Option C — Port 1984 with FREGATA_EXPOSE_GO2RTC_PORT=1
Section titled “Option C — Port 1984 with FREGATA_EXPOSE_GO2RTC_PORT=1”This one’s for tools that need to talk to go2rtc directly — reading or changing restream config, or pulling an RTSP/WebRTC feed — rather than going through Frigate’s API. Most automation should use Option A or B instead; reach for this only if go2rtc itself is what you need.
To enable, add FREGATA_EXPOSE_GO2RTC_PORT=1 in the tray’s
Settings → Environment Variables… and restart Fregata, then point your
tool at http://<mac-ip>:1984/api/…. Unlike port 5000, there’s no
conflict fallback to worry about — go2rtc runs as its own process, so a
failed bind only affects go2rtc, and port 1984 isn’t known to collide with
anything on macOS.
Option D — Port 8554, locking it down with FREGATA_EXPOSE_RTSP_PORT=0
Section titled “Option D — Port 8554, locking it down with FREGATA_EXPOSE_RTSP_PORT=0”Port 8554 is go2rtc’s RTSP restream, and unlike the other ports on this
page it’s open to your LAN by default — tools that want to pull the
RTSP restream directly (VLC, Home Assistant’s RTSP camera platform,
another NVR) can connect to rtsp://<mac-ip>:8554/<camera_name> with no
extra configuration.
To restrict it to loopback-only, add FREGATA_EXPOSE_RTSP_PORT=0 in the
tray’s Settings → Environment Variables… and restart Fregata. A warning
appears in the Fregata log every time Fregata starts while the port is
locked down, so you always have a visible reminder. Same posture as port
1984 — no conflict fallback to worry about, since go2rtc runs as its own
process and port 8554 isn’t known to collide with anything on macOS.
To add a username/password instead of locking the port down entirely, set
go2rtc.rtsp.username/password in config.yml:
config.yml only. The Settings UI only manages go2rtc streams, not the other go2rtc options.
go2rtc: rtsp: username: "admin" password: "pass"Clients then connect with rtsp://admin:pass@<mac-ip>:8554/<camera_name>.
This is go2rtc’s own credential check, independent of Frigate’s
auth.enabled and separate from the username/password your cameras use
upstream.
Custom go2rtc stream sources
Section titled “Custom go2rtc stream sources”go2rtc can build a stream by running a command on your Mac — an exec:
source (usually a custom ffmpeg pipeline), or an echo:/expr: source
that shells out to compute the stream URL. These enable genuinely useful
setups: splitting a dual-fisheye camera, burning in a drawtext timestamp,
or GPU-accelerated rotation (go2rtc’s built-in #rotate is CPU-only, so
rotation is done with a VideoToolbox exec: pipeline). By design, though,
they run arbitrary local commands.
Allowing custom sources
Section titled “Allowing custom sources”If you genuinely need one, set
GO2RTC_ALLOW_ARBITRARY_EXEC=true
in the menu-bar tray’s Settings → Environment Variables…, then restart Fregata
— environment-variable changes take effect only when Frigate starts. This is
the Fregata equivalent of the environment: block you’d use with Frigate on
Docker.
The exec: streams Fregata generates for itself — the birdseye restream
and the adaptive-live rungs — are always allowed; this switch gates only the
sources you write into go2rtc.streams.
The {{output}} token and brace-doubling
Section titled “The {{output}} token and brace-doubling”Stream values are expanded with Python’s str.format() before go2rtc sees
them, so you can reference {FRIGATE_*} environment variables directly (this
is upstream Frigate’s behavior). The catch: every literal { or } in the
value must be doubled. That is why go2rtc’s RTSP output placeholder is
written {{output}} — it collapses to the {output} token go2rtc fills in —
and why an ffmpeg expansion like drawtext’s %{localtime} has to be written
%{{localtime}}.
config.yml only. The go2rtc streams page in Settings refuses exec:, echo:, and expr: sources, so add them in config.yml.
go2rtc: streams: front_custom: # {{output}} -> {output}; {FRIGATE_CAM_PW} is filled from the environment - "exec:ffmpeg -hwaccel videotoolbox -i rtsp://user:{FRIGATE_CAM_PW}@10.0.0.5/main -c:v h264_videotoolbox -f rtsp {{output}}"A value that isn’t a valid format string — an un-doubled {output}, a bare
%{localtime}, an empty {} — is dropped with an explanatory log line rather
than passed through raw (an un-collapsed brace would reach ffmpeg literally and
the camera would silently 404-loop). Brace-doubling is required whether or not
GO2RTC_ALLOW_ARBITRARY_EXEC is set — the env var only decides whether a
successfully-expanded restricted source is kept.
Ports for Home Assistant
Section titled “Ports for Home Assistant”If you’re running HA on a different host, see the
Home Assistant guide — the integration
needs to reach 8971 and (if you’ve enabled it) MQTT on whatever
broker you’re using.