eyeball

What Eyeball can see

You're trusting a stranger across the street to watch your server. Fair to ask what the stranger holds. Here is the whole arrangement in plain terms, including the part that isn't perfect.

Your password never comes here

Sign-in uses Plex's own consent flow, the same one your TV apps use. You approve a code on plex.tv and Plex hands Eyeball a token. Think of it as a visitor badge with Eyeball's name on it. Your password stays between you and Plex.

What the token is for

Eyeball asks plex.tv two questions with it: which servers you own, and what addresses they answer at. That is all we use it for.

The watching itself needs no token

Every check knocks on your server's public identity endpoint, the same doorbell any Plex app can ring. It learns whether your server answered and how fast. It can't see into your library, and it has no idea who watched what.

Why the token is kept, by default

Home internet moves. When your address changes, Eyeball quietly asks plex.tv where your server went and keeps watching at the new address. That is the default, because most people never want to think about it again. The token is allowed to do more than look up an address. Keeping it means you trust us to use it the way we said.

You can tell us not to keep it

Tick Forget the Plex token after setup on the sign-in button, or open Settings and tap Forget this token. Some people would rather not leave that token with us, because it is allowed to do more than look up an address. We never see your password. We use the token long enough to find the servers, then delete our copy and ask Plex to remove the Eyeball device. Watching still works. Save the Plex token in Settings if you change your mind. If your home address later changes, you may get a down alert. Tap Re-check Plex and sign in again to update the address.

Check our work: open Authorized Devices in Plex. Eyeball should be gone. If it is still listed, Plex did not take our delete. Remove it there. We will say so in Settings when that happens.

The honest part

Plex doesn't make a smaller token. The one we get is allowed to do more than look up an address. There is no read-only version to ask for. That is why some people tell us not to keep it. There's an open feature request for scoped tokens. The day Plex ships them, Eyeball switches. Until then the promise is how we use it: two questions, nothing else.

How it's stored

Tokens are encrypted before they reach the database and never written to logs. The encryption key lives outside the database, so backups and database copies carry only ciphertext.

Your kill switch

Forget this token in Settings deletes our copy and tries to remove the device at Plex. Or open Authorized Devices and remove Eyeball yourself. Watching keeps going on the last address we have. Sign in again only if you want the list refreshed.

Questions

Write to support@eyeball.watch. A human answers.

Fix it once. I'll watch it from here.

I watch your Plex from the internet and send word the moment it breaks. The pay is nothing. The setup is one sign-in.

What does this mean?

Plex gives us a token so we can see where your servers are. That token is allowed to do more than look up an address. Keeping it means you trust us with it. We never see your password. Some people would rather we not keep it. This is for them.

That's fine. I still watch your servers. We never see your password. If your home internet moves, you may get an alert. Sign in once more and I pick up the new address.

🤓 Nerd details

The token is allowed to do more than look up an address. We use it to find your servers, then we delete our copy and ask Plex to deactivate the Eyeball device. Open Authorized Devices in Plex. Eyeball should be gone. If it is still listed, remove it there.

How Eyeball works