Self-hosted MyAnonamouse auto-downloader in the spirit of autobrr: IRC #announce snatching, wishlist/search polling, filter rules, and push to qBittorrent (or a watch folder).
For people who already have a MAM account. Not affiliated with MyAnonamouse.
- Live IRC announce listener (TLS to
irc.myanonamouse.net) - Filter rules (authors, series, formats, freeleech, size, regex, daily/weekly limits)
- Wishlist watches that poll MAM JSON search on an interval
- Manual search + one-click snatch
mam_idcookie persistence (use a dedicated MAM security session)- Discord webhooks (stream / errors / snatch)
- Multi-user auth (
admin/viewer) with SQLite sessions - Optional Discord OAuth and generic OIDC (e.g. Authentik)
- Scoped API keys +
/api/v1for bots and monitors - Optional companion Discord bot (
discord-bot/) - Audit log + settings version history (admin UI)
git clone https://github.com/crisprintsstuff/mybookbrr.git
cd mybookbrr
cp .env.example .env
# set BOOTSTRAP_ADMIN_PASSWORD to something strong
export BOOTSTRAP_ADMIN_PASSWORD='your-secure-password'
docker compose up -d --buildOpen http://127.0.0.1:7480 → sign in as admin → change password if prompted.
More detail: DOCKER.md.
Requires Node 18+ (20/22 recommended).
cp .env.example .env
# set BOOTSTRAP_ADMIN_PASSWORD
npm install
npm run rebuild:native # if better-sqlite3 fails to load
npm run build && npm start # http://127.0.0.1:7480Dev:
npm run dev # API :7480
npm run dev:client # UI :5174 (proxies /api)- Sign in as
adminwithBOOTSTRAP_ADMIN_PASSWORD - Connections → MAM & IRC — paste dedicated
mam_id→ Test MAM - Connections → Download client — qBittorrent host/user/pass → Test
- Create at least one Filter (or a match-all with a daily limit)
- Dashboard → Start IRC (and/or add wishlist watches)
- Optional: Discord webhooks under Admin → Notifications
- Optional: API keys for bots under Admin → API keys
- Log into MyAnonamouse
- Preferences → Security → create a new session only for MyBookBRR
- Bind the IP of the machine that runs MyBookBRR
- Copy the
mam_idcookie into Connections → MAM & IRC - Do not share this session with Autobrr, browser, Prowlarr, etc. — MAM rotates
mam_idand concurrent clients invalidate each other
Authorize your public IP for IRC under MAM security if #announce connections reset.
| Actor | How they authenticate | Access |
|---|---|---|
| Web UI | Username + password; optional Discord OAuth or OIDC | admin full control; viewer read-only |
| Bots / monitors | Authorization: Bearer mbb_… or X-API-Key |
Scopes per key |
Bootstrap: first start with an empty users table creates admin from BOOTSTRAP_ADMIN_PASSWORD (or legacy AUTH_PASSWORD). Env passwords are not used for day-to-day login after that.
- Discord Developer Portal → OAuth2 → Redirects, add e.g.
https://YOUR.DOMAIN/api/auth/discord/callback - Set
DISCORD_CLIENT_ID,DISCORD_CLIENT_SECRET,DISCORD_REDIRECT_URI,DISCORD_ALLOWED_USER_IDS
(or pointDISCORD_AUTH_CONFIGat a JSON file withclient_id/client_secret/allowed_user_ids) - Behind HTTPS:
COOKIE_SECURE=trueandTRUST_PROXY=true
Set OIDC_ENABLED=true and discovery/client/redirect env vars (see .env.example). Works with Authentik and other standard providers.
If you run a separate control plane that issues one-time tickets, set SSO_SHARED_SECRET and HUB_SSO_REDEEM_URL. Standalone installs leave these unset.
Build the client with a hub URL if you want a sidebar link:
VITE_HUB_URL=https://your-hub.example.com npm run build:clientWithout VITE_HUB_URL, the link is hidden.
Optional control bot: discord-bot/. Talks to /api/v1 with an API key. See discord-bot/README.md.
Create keys under Admin → API keys. Raw key shown once (mbb_…).
| Scope | Access |
|---|---|
status:read |
Status + public settings summary |
filters:read / filters:write |
List / mutate filters |
wishlist:read / wishlist:write |
List / mutate / run watches |
history:read |
Recent snatches |
events:read |
Recent events + SSE stream |
irc:control |
Start / stop IRC |
snatch:write |
Manual snatch |
curl -sS -H "Authorization: Bearer mbb_YOUR_KEY" \
http://127.0.0.1:7480/api/v1/status
curl -sS -H "X-API-Key: mbb_YOUR_KEY" \
http://127.0.0.1:7480/api/v1/eventsUI routes remain under /api/* (cookie or API key, role-gated).
IRC #announce ─┐
Wishlist poll ─┼→ normalize → filters → dedup → MAM download → qBittorrent
Manual search ─┘
Data: DATA_DIR (./data/mybookbrr.db by default).
| Script | Purpose |
|---|---|
npm run dev |
API with hot reload |
npm run dev:client |
Vite React UI |
npm run build |
Compile server + client |
npm start |
Run compiled server |
npm run rebuild:native |
Rebuild better-sqlite3 for current Node |
See SECURITY.md. Never commit .env or data/.
- IRC uses direct TLS (6697/7000). Starting IRC persists
irc_enabledacross restarts. /api/v1/healthreports liveness + readiness (mam, IRC, qBit, lockouts).- Failed snatches use per-torrent backoff so wishlist polling does not hammer MAM/qBit.
- SQLite backups land in
DATA_DIR/backups/(default keeps 7). - CORS defaults to localhost; set
CORS_ORIGINSfor your public origin.
