App Guides

Decypharr on a Seedbox: What a Debrid Gateway Can and Cannot Do Here

Decypharr pretends to be qBittorrent so your arrs can fetch through Real-Debrid or TorBox instead of torrenting. Upstream sells it as a way to keep nothing on disk. On a managed appbox that half doesn't work, and it's better to know before you install it than after. Here's what you actually get, and how to wire it up.

What Decypharr is for

You have a debrid subscription. Real-Debrid, TorBox, AllDebrid, Debrid Link or Premiumize, all five are supported. You also have Sonarr and Radarr doing the searching. The problem is that the arrs only know how to talk to a download client, and a debrid service is not one.

Decypharr sits in that gap. It puts up a fake qBittorrent API and a fake SABnzbd API, so Sonarr and Radarr think they are talking to an ordinary download client. Behind that, it hands the release to your debrid provider and waits. Upstream calls it a media gateway, the licence is MIT, and it is in our app library as a Docker app you install with one click.

That is the good part, and it works. The rest of this page is the part nobody writes down.

The mount does not work on a managed box, and that changes everything

Read Decypharr's own documentation and the headline benefit is this: "No Downloads - Files stream from Debrid/Usenet providers, saving local storage". The way it delivers that is by mounting your whole debrid library as if it were a local folder, so Plex sees a library of files that are not really there.

Look at what that needs. Upstream's recommended Docker compose asks for /dev/fuse, the SYS_ADMIN capability, an unconfined AppArmor profile and a shared mount propagation flag on /mnt. Those are the four things a rootless Docker container on a shared server does not get, and will not get, because between them they are most of the wall that keeps one customer's box out of everybody else's.

So the mount is off. Decypharr supports that: none is a documented mount type and it means exactly what it says. What it does not do is warn you, because upstream assumes you are running this on your own hardware.

The practical consequence: on an appbox, Decypharr downloads. Your debrid provider still does the hard part, grabbing the release from the swarm at its speed rather than yours, and you still skip the torrenting. But the finished file comes down to your disk and sits there, the same as anything else in your library.

The setting that decides whether any of this works

Decypharr has four download actions, and picking the wrong one is the single commonest way this app looks broken.

Action What it does On an appbox
symlink Links your library at the mounted debrid files Broken. There is no mount, so you get a folder of links pointing at nothing
download Fetches the finished file to a real folder This is the one. Use it
strm Writes small text files holding a WebDAV stream URL Works in principle, needs the app URL set correctly by hand
none Marks the job done and forgets it Only useful if something else moves the files

symlink is the default when nothing is set. That is correct upstream and wrong here, so it is the first thing to change in Settings before you connect an arr. If you have already connected one and the queue fills with items Sonarr says it cannot import, this is why: the files it is looking at are links into a folder that was never mounted.

Our install wires the download side for you. The finished-file folder is mounted into the container at the same path it has on your box, under ~/downloads/decypharr, so the path Decypharr reports to Sonarr is the path Sonarr can actually read. That sounds obvious. It is the thing that breaks most often when people build this themselves, and it is worth checking first if an import fails.

What it costs you in disk

This is the honest bit. If you came to Decypharr from a Stremio setup, you are used to debrid meaning "storage is somebody else's problem". Here it isn't.

Every finished release lands in your quota, so plan for the library you want to keep, not for zero. Appbox Lite is 500 GB at 5 euros a month, Appbox +1 is 1000 GB at 11, Appbox +3 is 3000 GB at 14. If you are going to leave a year of television lying around, buy the disk for it.

Bandwidth is the part that goes your way. Pulling whole files from a debrid host burns transfer, and every Appbox tier is unmetered, so a heavy month costs nothing extra. Worth noting if you are looking at the AI Appbox line instead: those tiers carry a bandwidth allowance rather than unmetered transfer, starting at 3 TB on the 500 GB plan, so check the plans page before you point a debrid gateway at one.

Pair it with something that clears up after itself. Cleanuparr handles the stuck-queue half, and it is more useful here than usual, because a debrid fetch that never finishes looks identical to a torrent with no seeders.

Connecting Sonarr and Radarr

In Sonarr or Radarr, go to Settings then Download Clients and add a qBittorrent client. The fields are not what you expect:

Yes, the username field takes a URL. That is upstream's design, not a typo: Decypharr uses those two fields to work out which arr is calling so it can report back to the right one. If the connection test fails, that address is the first thing to check, because Decypharr proves it by asking that URL for a health response.

If you also run Usenet, add a second client of type SABnzbd pointing at the same host with /sabnzbd appended to the URL base, and set priorities to decide which source your arr tries first. Our Usenet guide covers the provider side.

Why your install has a random string in the URL

Worth understanding rather than working around. The fake qBittorrent API cannot sit behind a normal password prompt, because Sonarr's download client has no way to answer one. And Decypharr's own check on the caller is thin: it takes the arr address you supply and accepts it if that address answers a health request at all. Any web server passes.

So on the public internet, an address anyone can guess is the only thing standing between a stranger and the ability to push downloads through your debrid account onto your disk. That is a real hole in a self-hosted setup and it is why our install puts the whole app under a random 32-character prefix, with the web interface behind your appbox login on top of that. Treat the prefix as a password: do not paste your Decypharr URL into a forum thread.

It does not replace your torrent client

Decypharr does not seed. Nothing that goes through a debrid provider does, because you were never in the swarm. So if you care about ratio, this is not the tool, and running it against a tracker that expects you to seed is a good way to lose the account.

Most people who run it keep qBittorrent or Deluge as the first-priority client and put Decypharr second, so the arrs seed what they can and fall back to debrid for the rest. That is a sensible shape and the arrs support it natively through client priorities.

Upgrades, and what you would lose

We pin the image to v2.5 by digest rather than following latest, so a release upstream does not change your box on a Tuesday. An upgrade from the panel keeps ~/.config/decypharr, which is where config.json, the login and your debrid API key live, so your setup survives it. An uninstall removes that folder and you would enter the key again. Files already downloaded stay in ~/downloads, because they are yours.

Should you install it

Install it if you have a debrid subscription already, you want Sonarr and Radarr to use it without you clicking anything, and you have the disk for what it fetches.

Skip it if you came looking for the zero-storage debrid library. That setup needs a mount, the mount needs kernel privileges, and a managed box is not going to hand those out. If that is what you actually want, the honest answer is a machine where you have root, and our seedbox versus debrid guide walks through why the two approaches suit different people.

What's Next?

15+ years of seedbox hosting 4.9/5 Trustpilot (301 reviews) 97+ one-click apps

Ready to Get Started?

Set up your own media server in under two minutes.