Diagram: the example address rtmps://stream.example:443/live/YOUR_SECRET_KEY is split into five colored parts: protocol, server, port, path, and stream key. Below it, the difference: RTMP normally unencrypted, RTMPS TLS-encrypted.

The short answer

RTMP normally sends the live stream unencrypted. RTMPS carries the same RTMP data stream inside a TLS-encrypted connection. That protects video, audio, and stream key better on the way to the server.

Recommendation: If the target platform or your own server supports RTMPS reliably, use RTMPS. RTMP still makes sense for isolated internal networks, older devices, or a self-run server that has no TLS endpoint yet.

In this guide

1. What are RTMP and RTMPS?

RTMP is a persistent, TCP-based transport for audio, video, and metadata. In live streaming, it is mostly used today as an ingest protocol: OBS, a hardware encoder, or a streaming app sends the finished signal to a platform or your own server.

RTMPS does not change the video content itself. It adds a TLS layer, much like the difference between HTTP and HTTPS. The server identifies itself with a certificate and the connection is encrypted.

Don't confuse it with the viewer format: RTMP or RTMPS is usually the path to the server. Viewers then typically get the stream in a different delivery format from the platform.

2. RTMP and RTMPS side by side

The most important differences
FeatureRTMPRTMPS
TransportRTMP over TCPRTMP inside a TLS connection
EncryptionNormally no transport encryptionVideo, audio, metadata, and stream key are encrypted in transit
Typical URLrtmp://server.example/livertmps://server.example/live
Common portTCP 1935Often TCP 443; the provider may specify a different port
CertificateNot requiredValid TLS certificate and matching hostname required
CompatibilityVery broad, including older encodersEncoder and server must support RTMPS
Recommended useInternal network, lab, compatibility exceptionPublic internet and platform ingest

The URLs are only patterns, not clickable server addresses. The port numbers are typical values too, not a fixed rule. What counts is always the full address your server or platform gives you.

3. Which one should I use?

TLS protects the connection from simple eavesdropping and from tampering in transit. It does not turn a compromised or published stream key into a safe one. So keep your stream key secret and replace it if you suspect a leak.

4. Keeping server URL, port, and stream key apart

Many errors come from mixing up the server address, the application path, and the stream key. The addresses and keys below are examples only, not targets to click or copy.

Example for your own server
FieldRTMP exampleRTMPS example
Serverrtmp://stream.example:1935/livertmps://stream.example:443/live
Stream keyYOUR_SECRET_KEYYOUR_SECRET_KEY
Full target pathrtmp://stream.example:1935/live/YOUR_SECRET_KEYrtmps://stream.example:443/live/YOUR_SECRET_KEY
Important: In OBS, the server and stream key normally go into separate fields. Never copy your real key into screenshots, status pages, or public guides.

5. Setting up RTMP or RTMPS in OBS

  1. In OBS, open Settings → Stream.
  2. If the platform is available as a ready-made service, pick it. A current platform preset is usually better than a server address you typed in by hand.
  3. For your own target, choose Custom and enter the full RTMP or RTMPS server address.
  4. Paste the stream key into its own field.
  5. With RTMPS, check that the server name matches the certificate. A raw IP address only works if the certificate is valid for exactly that.
  6. Test with a private or unlisted broadcast, and under View → Stats in OBS watch for dropped connections and dropped frames.

YouTube provides the RTMPS address in the Live Control Room and names port 443 as a possible explicit setting if you run into TLS problems. Official help: Encrypt your stream with RTMPS.

6. RTMPS on your own server

A classic Nginx RTMP server often listens unencrypted on TCP port 1935. Changing only the prefix of the encoder address from rtmp:// to rtmps:// is not enough. The server side has to actually accept TLS.

This is usually done with a TLS endpoint or a suitable proxy in front, which accepts RTMPS and forwards it internally to the RTMP service. You also need a domain, a valid certificate, the right firewall port, and automatic certificate renewal.

Don't lock yourself out by accident: Before you switch, check that every app and encoder you use supports RTMPS. During a controlled migration, RTMP and RTMPS can run side by side on separate ports.

For a server that runs permanently, there is the detailed Linux guide with Nginx RTMP. If you want to run the receiving server and OBS on one Windows PC, use the separate Windows guide with NOALBS. A later RTMPS extension with a certificate and TLS proxy can build on the Linux setup.

7. A sensible setup for an IRL stream

RTMPS encrypts reliably, but it does not smooth out an unstable cellular connection. For a mobile stream, a combination often makes sense:

  1. Moblin, IRL Pro, or a mobile encoder sends over SRT or SRTLA to the relay or bonding server.
  2. OBS receives the mobile picture and adds scenes, alerts, audio, and outage protection.
  3. OBS sends the finished program stream over RTMPS to the target platform.
Rule of thumb: SRT/SRTLA stabilizes the difficult mobile leg. RTMPS protects the final platform uplink.

If you want to set up your own SRTLA receiver for mobile ingest, the automatic SRTLA installation guide walks you through it. It does not install an RTMP server; for that there is the separate RTMP server guide.

8. Common RTMP and RTMPS errors

Narrowing down errors quickly
SymptomLikely causeCheck
Connection refused right awayWrong port, service not running, or firewall blockingCheck the server address and the specified TCP port
TLS or certificate errorHostname doesn't match, certificate expired, or the server only speaks RTMPCheck the RTMPS address and certificate chain; don't just change the URL prefix
Authentication failedStream key wrong, expired, or entered in the wrong placeCopy the key again and watch for spaces
RTMP works, RTMPS doesn'tEncoder or server doesn't support RTMPSCheck current software, platform preset, and server configuration
Stream drops regularly on mobileRTMP/RTMPS reacts badly to network switches and longer dropoutsTest SRT/SRTLA with a suitable latency for the mobile leg
Doubled or wrong URLThe stream key was appended to the URL and entered separately tooFollow the encoder's convention and keep the fields cleanly separate

Technical background: RTMP carries audio, video, and metadata over a persistent connection; modern extensions are documented in the open E-RTMP project. Enhanced RTMP at Veovera.

Next steps

9. Common questions about RTMP and RTMPS

What is the difference between RTMP and RTMPS?

RTMP normally sends the live stream unencrypted. RTMPS wraps the same RTMP data stream in a TLS-encrypted connection, much like HTTP and HTTPS. That protects video, audio, and stream key better on the way to the server.

Is it enough to replace rtmp:// with rtmps:// in OBS?

No. The server has to actually accept TLS, with a valid certificate and a matching hostname. What that looks like on your own server is covered in the section RTMPS on your own server.

Does RTMPS make my stream key safe?

TLS protects the connection from simple eavesdropping and from tampering in transit. A published or compromised stream key is still not safe. Keep it secret and replace it if you suspect a leak.

Should I use RTMPS for mobile IRL streaming?

On the unstable cellular leg, SRT or SRTLA is usually more reliable. RTMPS fits after that, on the stable path from OBS to the target platform.

Which port goes with RTMP and RTMPS?

TCP 1935 is commonly used for RTMP and TCP 443 for RTMPS. Those are typical values, not a fixed rule. What counts is always the full address your server or platform gives you.

Last technically reviewed: · Updated: · Published by IRL4YOU