Plex token is different for thumbnail images on my Plex server

Server Version#: 1.25.7.5604
Player Version#: 4.76.1

So I have a weird one that I am not sure how to resolve. I am using Dizquetv to setup plex media items to play channels with that content, but I am using the Dizquetv m3u in the Channels app for the media channels.

The weird thing is, thumbnails do not seem to be working for certain items and when I go to the web address of the thumbnail image, I am getting a message the certificate isn’t valid for the site:

this is one of the sites that I am getting that the certificate isn’t valid, and I have to allow chrome to access the site, to go to the untrusted site:

https://192-168-1-50.204b5da3861e44bebbf20d9ab342baf0.plex.direct:32400/library/metadata/143247/thumb/1570056450?X-Plex-Token=***s5

but an image that is allowing and says the certificate is valid is the following:

https://192-168-1-50.9f1476e9b79744498d21b4fa33c24b1f.plex.direct:32400/library/metadata/3022465/thumb/1645954887?X-Plex-Token=***MqM

These have two different Plex Tokens, and it seems the ones that work correctly and certificate is valid all have the second Plex Token, the ones that don’t have the first Plex Token. Is there an easy way to update the plex token for images that it is no longer correct?

Never, ever post Plex tokens publicly! You might as well post your Plex password.

1 Like

Thanks for xxx it out, but why would I have different plex tokens for images?

Sorry, I dont understand your use case.
I also don’t know how you came about these URI’s.
If you captured/sniffed/logged these during the course of Plex server’s interaction with several different Plex clients, it is easily explainable: each client has its own token.

I figured it out, appears that Dizquetv was using an old image thumbnail url that was using an old incorrect token. I just have to update the channel and it appears it is grabbing the correct URL.

Yes, if you use a token from an official Plex client and appropriate it to use with a 3rd-party app/script, you need to keep track of the validity of that token.

Not only was a valid Token publicly visible for several minutes, but also the full URL to your server.
So your plex account is susceptible to a hostile takeover (Plex accounts with Plex Passes on them are offered for sale by perpetrators).

I urge you to change your Plex password immediately and invalidate all tokens during the procedure.

Unfortunately this also means logging out and back in all plex clients and 3rd-party apps.

1 Like

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.