# OBS remote control (/docs/obs-remote-control)





The VISP plugin for OBS Studio 31 connects your VISP account directly to OBS.
It lists publishing devices, adds relay feeds to scenes, can configure this OBS
installation as a publishing device, and lets the web or phone app control the
stream remotely. OBS never opens an inbound port and no port forwarding is
needed.

Pairing is step 4 of [Get started](/docs/get-started). This page covers
install details, security, and recovery.

## Install [#install]

Download the package for your platform from the project's GitHub Release —
Windows, macOS (signed and notarized), and Ubuntu packages are attached to
every stable release with a `SHA256SUMS.txt`. Install it like any OBS plugin
and restart OBS. Building from source is only needed for development; see the
`apps/obs-plugin` README.

## Pair [#pair]

1. In OBS, open **Tools → VISP Remote Control**.
2. Click **Sign in with browser**.
3. Sign in to VISP and approve the OBS code, then return to OBS.

The dialog lists every active publishing device. **Add to scene** creates or
refreshes its Media Source in the selected scene. **Create and use as OBS
output** creates a new VISP publishing device and, after confirmation, replaces
the current OBS profile's stream destination with its SRT URL. Stop streaming
before changing that destination.

<img alt="OBS Tools → VISP Remote Control" src="__img0" />

The dashboard shows **Connected** within a few seconds, without restarting OBS.
Existing manual pairing still works: generate a token in the dashboard, or
place these values in the generated `config.ini` while OBS is closed:

```ini
[visp]
control_url=https://APP_DOMAIN/api/obs/control
token=the-token-shown-by-visp
```

Remote start/stop uses the active OBS profile. Configuring this OBS installation
as a VISP publishing device replaces that profile's current service and key;
VISP never receives the replaced provider key.

## Security model [#security-model]

* Browser approval uses a short-lived device authorization. The temporary VISP
  session is revoked as soon as OBS exchanges it for a limited machine token.
* The machine token is random and 256-bit. VISP stores only its SHA-256 hash
  and compares in constant time.
* Rotating the token in the dashboard disconnects every previously paired OBS
  configuration at its next poll.
* Treat `config.ini` as a machine credential: anyone holding it can start and
  stop your stream. Rotate immediately if it is exposed.
* Transport is ordinary HTTPS with normal TLS certificate verification through
  OBS's bundled Qt network stack.
* The token can list and create publishing devices and obtain read URLs, but it
  cannot manage unrelated account or provider settings. Treat `config.ini` and
  OBS scene collections as machine credentials.

## How commands flow [#how-commands-flow]

Every two seconds the plugin reports its state — streaming or not, the scene
list, and the current scene — and receives at most one pending command in
return. The dashboard marks the pairing **Connected** while polls are under
ten seconds old, and shows a live snapshot tile for each publishing path so
you can see what OBS would broadcast before pressing start.

Because commands ride on the next poll, a start or stop takes at most about
two seconds to reach OBS.

## Troubleshooting [#troubleshooting]

* **Never connects:** verify `control_url` points at the public app origin and
  that the machine can reach it over HTTPS; the endpoint is authenticated by
  the token, not by network location.
* **Was connected, stopped after a rotation:** expected — re-pair with the new
  token.
* **Start does nothing in OBS:** configure a streaming service and key in OBS
  first; the plugin does not supply them.
