lodestar help

By default lodestar talks straight from your iPhone to servers you run, so most problems are about what your phone can reach, and where. Optional remote access routes sealed traffic through our relay.

Updated 2026-10-04

Setting up remote access is further down, with the commands to copy.

Still stuck

Get help with lodestar: report a problem or suggest a feature, and follow it on a private page.

Adding a service

Use the LAN address, not localhost. On a phone, localhost is the phone. A server on your network is something like http://192.168.1.20:7878. Set a server address on the profile and each new connection pre-fills it with that product's usual port.

A trailing slash, a missing http://, a non-default port and a reverse-proxy path such as https://home.example.com/sonarr are all handled. Test connection validates live and tells you what failed rather than just failing.

Where each product keeps its key

ServiceWhat lodestar needs
Radarr, Sonarr, Prowlarr, BazarrSettings, General, API Key
SABnzbdConfig, General, API Key
NZBGetThe control username and password
qBittorrent, TransmissionThe Web UI username and password
DelugeThe Web UI password only, no username
PlexAn X-Plex-Token
Jellyfin, EmbyDashboard, API Keys, then a new key
TautulliSettings, Web Interface, API key
Overseerr, JellyseerrSettings, General, API Key

When something will not connect

"Something answered at that address, but not Radarr"

Something is there, but it is not that product. Usually a hotel or café captive portal, a proxy login page, or a web server on a port you did not mean. Check the port, and check whatever sits in front of it.

It says unreachable

Wrong address or port, the phone on a different network from the server, a VPN routing away from your LAN, or the machine asleep. lodestar waits up to twenty seconds before calling a service unreachable, so a slow first answer from a sleeping disk is not mistaken for a dead server.

It says unauthorized

The key or password is wrong, or the product now insists on authentication even on a LAN. Recent Prowlarr does exactly that.

It is behind Cloudflare Access or an auth proxy

Open the connection and use Headers. There is a preset that inserts the Cloudflare Access pair ready to fill. Header values are stored in the iOS Keychain beside your API keys, and Test connection sends them so a wrong token surfaces there.

It uses a self-signed certificate

Switch on Allow self-signed certificate for that connection. It applies to that connection alone.

Remote access, and the agent that makes it work

lodestar talks straight to your servers, which is why it works so well at home and not at all from a train. Remote access closes that gap without a VPN: you run a small agent on your own network, it dials out to a relay we operate, and the app reaches your servers through it. The relay forwards bytes it cannot read.

What this is not

It is not a requirement. With remote access switched off, lodestar behaves the way it does without an account: service requests go straight to the servers you configured and to nothing else. Nothing here ever becomes load-bearing for using the app at home.

Install the agent

On any Linux machine that can see your services, a NAS included. It needs python3 and nothing else, installs into your home directory, and asks for no password.

curl -fsSL https://lodestar.i8l.tech/agent/install.sh | sh

Piping a script from the internet into a shell is a habit worth resisting, so here is the version that lets you read it first. It is short on purpose.

curl -fsSL https://lodestar.i8l.tech/agent/install.sh -o install.sh less install.sh sh install.sh

Sign in, and the services come across

The installer starts the agent and prints an address on your network, like http://192.168.1.20:9797. Open it in a browser and sign in with the same lodestar account you use in the app. The services you configured in the app are sent to the agent sealed, so there is nothing to type twice, and the app connects on its own from then on.

The agent reaches only the services it has been given: those synchronised from a signed-in device, and any you add at the keyboard. There is no wildcard.

lodestar-agent list lodestar-agent add radarr http://192.168.1.20:7878 <api key>

Start it, and keep it started

The installer writes a user service where systemd is available, so it comes back after a reboot without root. Lingering is the one command that needs sudo, and only if it is not already on.

systemctl --user enable --now lodestar-agent sudo loginctl enable-linger $USER # only if the installer said so systemctl --user status lodestar-agent

The older flow: a pairing code

An agent that has not been updated pairs with a code instead of a sign-in. The app keeps this under Settings, Remote access, Use a pairing code instead, and it gives the same remote access. The code lasts ten minutes and works once, so print it when you are holding the phone.

lodestar-agent enroll <connection code from the app> lodestar-agent pair

You will be asked for a passphrase. It encrypts your library where we store it, it never reaches us, and nobody here can reset it: if you lose it, the stored copy is rebuilt from your own servers.

What we keep, and how to keep nothing

Two settings, in the same screen. Sealed copy, the default, stores your library encrypted with that passphrase, so the app and the web version paint instantly and you have a backup. We can count what we hold and we cannot read it. Nothing kept stores nothing at all, and every screen is fetched from your machine when you open it, which is slower. Either way we can see that your agent connected, roughly from where, for how long and how many bytes moved, because no relay can run without that.

Delete everything now is in that screen too. It removes the stored copy from live systems immediately and returns a receipt saying what went.

The web version

Once an agent is paired, lodestar.i8l.tech/app reads the same library in a browser. It asks for a device token and that same passphrase; everything is decrypted in the page, and the relay only ever held ciphertext.

When it will not connect

What you seeWhat it usually means
Pairing says the code was refusedCodes last ten minutes and work once. Print another.
The app says no agent is connectedsystemctl --user status lodestar-agent, then its log: journalctl --user -u lodestar-agent -n 50
It worked, then stopped after a rebootLingering is off. sudo loginctl enable-linger $USER
A service is missing from the appWith the sign-in flow the app sends its services to the agent on its own: open lodestar once, then check with the command. An agent on the older pairing flow may need the service added at its keyboard. lodestar-agent list

Artwork, notifications and widgets

Artwork comes from your own servers. Two honest limits. A film or show you have not added yet has no art on your server, so its poster comes from the metadata provider instead, and that has its own switch in Settings. And Sonarr holds no per-season artwork at all, so a season row shows the show's poster unless you also run a media server that has season art, in which case lodestar uses that.

Notifications are raised on the phone itself. They are posted locally, not through a push service; the phone checks your servers during its background refresh, through our relay if remote access is on and a server is not reachable directly, which means iOS decides when to look. Expect minutes, not seconds. They need Background App Refresh switched on for lodestar, and iOS runs nothing in Low Power Mode. Settings reports when the last pass finished, which is the only honest thing to say about the timing.

Widgets read a file the app writes, so open lodestar once after adding it to a home or lock screen.

Subscription, billing and refunds

What is offered

The agent and its web app on your own network are free.

lodestar lifetime, a single payment of $19.99: the iOS app with unlimited profiles and services, and thirty days of remote access from the purchase, once.

lodestar monthly, $2.99 per month, with a free week for eligible new subscribers: remote access through our relay and the hosted web app. It does not change the app's limits.

The free tier stays genuinely usable: one profile with up to two services, direct connections. Both purchases can be shared with Family Sharing. Prices are United States pricing and differ elsewhere. Nothing outside the iOS app sells or unlocks anything.

Payment is charged to your Apple Account. A subscription renews automatically unless it is cancelled at least 24 hours before the end of the current period. A lifetime owner who subscribes simply has remote access continue past the thirty days.

Managing or cancelling: the iPhone's Settings app, tap your name, then Subscriptions. Neither lodestar nor we can cancel on your behalf.

Restoring a purchase: Restore Purchases sits next to the purchase button. Use the Apple Account that bought it.

Refunds are Apple's to give, not ours. Request one at reportaproblem.apple.com.

Privacy

On your own network lodestar talks straight from the phone to your servers: no account, nothing sent to us. If you sign in under Remote access, we hold your account and our relay carries sealed traffic it cannot read, while seeing that your agent connected, when, roughly where from and how much passed. Addresses and preferences stay on the device and API keys live in the iOS Keychain. Artwork for a title you have not added yet comes from a metadata provider, and that has a switch. Full detail in the Privacy Policy.

Compatibility

iOS 17 or later, on iPhone and iPad, as one universal app. Seventeen services: Radarr, Sonarr, Prowlarr, Bazarr, Overseerr and Jellyseerr, Plex, Jellyfin, Emby, Tautulli, NZBGet, SABnzbd, qBittorrent, Transmission, Deluge, LazyLibrarian and Audiobookshelf.

lodestar is a remote control for software you already run. It downloads nothing itself and needs those servers to be yours.

We are not affiliated with any of those projects. The names appear only to describe which software the app can control.