VoiceRepo Logo
VoiceRepo
Back to Blog
Technical GuideSeptember 19, 20267 min read

How to Enable HTTPS (SSL) on Your Shoutcast or Icecast Stream — Step by Step

HTTPS stream URLs are required by Alexa, Android apps, and modern browsers. Every method to get SSL on Shoutcast and Icecast: control-panel options, reverse proxies with free Let's Encrypt certificates, and what to do if your host refuses.

RA
Raheel AshrafCEO, VoiceRepo — 1500+ Stations Launched

The single most common reason a radio station can't get onto Alexa, an Android app, or even its own HTTPS website: the stream URL starts with http://. It's one letter, and it locks a station out of the entire smart speaker ecosystem and every modern embedding context. The good news is that fixing it is almost always free, and there are exactly three routes — ordered here by how little work they are.

Step Zero: Look at Your URL

Before doing anything: if your stream URL already starts with https://, you're done — close this tab and go work on your station. If it starts with http:// and carries a port like :8000, keep reading. That's the situation, and the rest of this guide is three ways out of it.

Route 1: Ask Your Host (Do This First)

Managed radio hosts have answered the SSL question hundreds of times. Most offer one of: an SSL-enabled port for your stream, a proxy URL on standard 443, or a one-click SSL toggle in the panel (Centova-based hosts and AzuraCast both have one). Open a ticket and ask directly: "Can you enable HTTPS for my stream, or give me a secure stream URL?"

Most hosts do this free, same day. If yours wants a monthly fee for it, that's not a technical limitation — that's a pricing decision, and it's a signal to consider routes 2 and 3, or a different host.

Route 2: A Reverse Proxy with Let's Encrypt (Free, ~20 Minutes)

If you run your own VPS — AzuraCast, standalone Icecast or Shoutcast — the standard solution is a web server in front of your stream that handles SSL. Caddy is the easy version: it obtains and renews Let's Encrypt certificates automatically, which is the entire reason to prefer it over nginx for this job.

  1. 1Point a subdomain at your server — stream.yourstation.com
  2. 2Install Caddy on the server: apt install caddy
  3. 3Add one proxy block: stream.yourstation.com proxies to localhost:8000 (your stream port)
  4. 4Caddy fetches the certificate and renews it forever, automatically
  5. 5Your stream URL becomes https://stream.yourstation.com/live — clean, portless, HTTPS
  6. 6Update every player, embed, and skill that pointed at the old URL

The nginx equivalent works the same way but needs certbot and manual renewal configuration. For a stream proxy, Caddy is simply the better tool in 2026 — the automation is the feature.

💡
The free bonus

A 443-based HTTPS stream URL also fixes the 'works on Wi-Fi, dies on mobile data' problem — some carriers throttle audio on non-standard ports. Behind a proxy on 443, your stream is indistinguishable from web traffic and sails through.

Route 3: Platforms Where It's Already Done

If you want zero configuration, platforms that serve HTTPS by default: Zeno.FM (HLS over HTTPS on every station), Radio.co, and Live365. The trade is control — their player, their limits, their ecosystem. But from an SSL perspective, nothing to do, nothing to maintain, nothing to renew.

Verifying It Worked

  1. 1Open the new URL in VLC — Media → Open Network Stream — it must play
  2. 2Load it in a browser — the certificate must be valid, no warnings
  3. 3If your site is HTTPS: embed the player and check the browser console for mixed-content errors
  4. 4Test on mobile data, not just Wi-Fi
  5. 5Update your Alexa skill or app endpoint to the new URL — the old one doesn't follow you automatically

The Four Mistakes That Follow People Around

  • Pointing a skill at an http URL that redirects to https — Alexa handles redirects badly; always use the direct https URL
  • Self-signed certificates — rejected at certification and warning in browsers; Let's Encrypt is free, there's no reason
  • Assuming the panel's SSL covers the stream port — panel and stream are usually separate services; test the stream URL itself
  • Updating the URL in one place — website player updated, skill still pointing at the old one; make the list before you start

That's the entire landscape. One letter in the URL scheme, three ways to fix it, an afternoon at the outside. Given what it unlocks — Alexa, Android, clean embedding, mobile-carrier compatibility — it's the highest-value afternoon in most stations' technical year.

Want It Checked Before You Do Anything?

Send us your stream URL — we'll test it against Amazon's and Google's requirements and tell you exactly what it needs, free, before you spend time or money on anything.

Free Stream Check

Related Topics

enable https shoutcasticecast ssl certificateshoutcast https streamhttps stream url radiossl for icecast streamlets encrypt radio streammake stream url https