# Connect your server

> The welcome walkthrough step by step — iCloud, your NVR's address at home and away, signing in, administrator or viewer — plus certificates, custom headers and changing the connection later.

The first time you open Fregata Mobile, a walkthrough connects it to your NVR. It takes about
three minutes, and the bar across the top shows how far you are. **Do this later**, at the top
right of every step, leaves it: the app keeps what you've entered, and **Settings › Set up this
iPhone again** starts it over.

## Connect for the first time

1. **Welcome.** Tap **Get started**.
2. **Sync with iCloud?** Leave **Sync with iCloud** on to bring your server across from another iPhone or iPad, or to have this one ready for the next. Tap **Continue**.
3. **Where is your NVR?** Type its address under **At home**, and under **Away** if you have one for when you're out. Tap **Next**.
4. **Sign in.** Enter the username and password you use for your NVR's web interface, then tap **Connect**.
5. **Connected.** The app says whether your account is an administrator or a viewer and lists the cameras it found. Tap **Next**.
6. **Alerts on this iPhone.** Tap **Allow notifications**, then choose **Allow** when iOS asks.
7. **Alerts from Frigate.** Tap **Check my server**, and follow [Set up alerts](https://mobile.fregata.app/docs/getting-started/notifications/). To leave it for now, tap **Finish alerts later**.
8. **You're set.** Tap **Start watching**.

The rest of this page explains each step.

## Sync with iCloud

_Picture: The iCloud step of the welcome walkthrough: the Sync with iCloud switch on, and a green card saying it found the setup for the server Home in iCloud._

If you've already set Fregata Mobile up on another device signed in to the same Apple Account,
this step finds it. The card says **Found your setup in iCloud**, and **Continue** takes you
straight to signing in: the address is already filled in. **Set up a different server** ignores
what was found.

On a first device, the step says there's nothing in iCloud yet. Your server is saved there as
you go, ready for the next device.

Turning **Sync with iCloud** off keeps everything on this iPhone only. You can change it later
in **Settings › iCloud Sync**; see [iCloud Sync](https://mobile.fregata.app/docs/reference/icloud-sync/) for exactly what
travels and how it's protected.

## Your NVR's address

_Picture: The Where is your NVR? step: an At home address of https://192.168.1.10:8971, an Away address of https://nvr.example.com, and Advanced below them._

1. **At home**: the address that works on your home Wi-Fi, usually an IP address and port such as `https://192.168.1.10:8971`.
2. **Away**: an address that works from anywhere, such as a Tailscale or VPN address or a domain of your own. Optional.
3. **Advanced**: custom headers, for an NVR behind a login page such as Cloudflare Access.

Not sure of the address? Open your NVR in a browser on a computer and copy what's in the
address bar. Use port 8971, the one that asks for a sign-in, rather than 5000: while sign-in is
on, alerts registered over port 5000 are silently lost. See
[Compatibility](https://mobile.fregata.app/docs/reference/compatibility/#servers).

You don't choose between the two addresses: the app tries both, uses whichever answers, and
remembers which one works on each Wi-Fi network. Either one on its own is enough.

| You reach your NVR… | At home | Away |
|---|---|---|
| Only on your home network | Its local address | Empty |
| At home, and through a VPN or Tailscale when out | Its local address | Its Tailscale or VPN address |
| Through one public address everywhere | Empty | The public address |

Away from home, live video, recordings and the picture in each alert all need the **Away**
address. Without one, alerts still arrive away from home, but with no picture, and in
Frigate's own wording rather than [yours](https://mobile.fregata.app/docs/alerts/wording/). See
[Away from home](https://mobile.fregata.app/docs/getting-started/remote-access/).

If an address looks wrong for its field, a note under the fields says so. For example, a
`192.168.…` address under **Away** won't reach your server from elsewhere, and an `http://`
address under **Away** travels unencrypted unless a VPN encrypts it.

### Custom headers

_Picture: The address step with Advanced open: two headers, CF-Access-Client-Id and CF-Access-Client-Secret, each with a value, and Add a header below._

If your NVR sits behind something that asks for its own sign-in before Frigate's, such as
Cloudflare Access, open **Advanced** and tap **Add a header** for each header it needs.
Cloudflare Access needs two: `CF-Access-Client-Id` and `CF-Access-Client-Secret`. The app sends
them with every request, including the ones made in the background to put a picture in an
alert. The values are kept in the Keychain.

## Sign in

_Picture: The sign-in step: a note advising an administrator account, then the Username and Password fields._

1. If you have an administrator account, sign in with it: the app can then set your server up for alerts by itself.
2. **Username**: the same one you use in your NVR's web interface.
3. **Password**: kept in this iPhone's Keychain and sent only to your own server.

If your NVR has no sign-in at all, leave both empty and tap **Connect**.

If **Connect** fails, a message under the fields says why, in plain words: the address doesn't
answer, the password was refused, the certificate needs a decision, and so on. Each message and
its fix is in [Can't connect](https://mobile.fregata.app/docs/troubleshooting/connection/).

## Administrator or viewer

Frigate gives every account a role. The app reads it when you sign in and says which you have.

_Picture: The Connected step for a viewer account: it says the account is a viewer, lists five cameras, and explains that the app will give you the text to send to whoever runs the server._

Both can watch every camera, scrub recordings, browse Review and Explore, and receive alerts.
An administrator can also change the server itself:

| | Administrator | Viewer |
|---|---|---|
| Live view, recordings, Review, Explore | ✓ | ✓ |
| Receive alerts, and choose which reach this iPhone | ✓ | ✓ |
| Let the app [set up alerts](https://mobile.fregata.app/docs/getting-started/notifications/) on the server | ✓ | Gives you the steps to send to an administrator |
| Turn a camera's detection, recording or snapshots on or off | ✓ | — |
| [Turn a camera's alerts off for everyone](https://mobile.fregata.app/docs/alerts/server-wide/) | ✓ | — |
| Create and edit [camera groups](https://mobile.fregata.app/docs/cameras/groups/) | ✓ | — |
| Restart the server, and read its logs | ✓ | Logs only, where the server allows it |

A viewer that wants to do more can tap **Back** and sign in with an administrator account
instead. You can also change the account at any time in **Settings › Connection**.

## Alerts on this iPhone

_Picture: The Alerts on this iPhone step, after notifications are allowed: switches for Show a picture, Upgrade to a short video and Break through Focus, all on._

1. **Show a picture**: the frame the camera saw, in the alert itself.
2. **Upgrade to a short video**: replaces the picture with a few seconds of footage, about 25 seconds after the alert. Uses mobile data when you're not on Wi-Fi.
3. **Break through Focus**: alerts arrive as Time Sensitive, so they show while a Focus, Do Not Disturb included, is on. It doesn't make a sound on a silenced iPhone.

All three are on to begin with, and all three are in **Settings › Device Notification
Settings** later. See [Pictures, video and sound](https://mobile.fregata.app/docs/alerts/pictures-video-sound/) and
[Focus and Time Sensitive alerts](https://mobile.fregata.app/docs/alerts/focus/).

**Set up notifications later** skips alerts for now. Nothing else depends on them.

## Certificates

_Picture: An alert over the Cameras tab asking Trust this server's certificate?, with the certificate's SHA-256 fingerprint, and the buttons Trust it and Not now._

Frigate secures its web interface with a certificate it makes for itself, which iOS can't
check on its own. How the app handles it depends on the address:

- **An address on your home network**, such as `192.168.1.10`: the app trusts the certificate
  the first time and remembers it. There's no question to answer.
- **Any other address**: the app asks first, showing the certificate's fingerprint. If you
  want to be sure, compare it with the one your server shows, then tap **Trust it**.
- **A certificate iOS already trusts**, such as one from Let's Encrypt on a reverse proxy: no
  question either.

Once trusted, the certificate is pinned. If your server ever presents a different one, the app
stops and asks again, under **This server's certificate has changed**. That's expected after
you rebuild or reinstall Frigate, which makes a new certificate. If you haven't, tap **Not now**
and find out why before trusting it. See [Certificate questions](https://mobile.fregata.app/docs/troubleshooting/certificates/).

## Change the connection later

**Settings › Connection** holds everything the walkthrough asked for.

_Picture: Settings › Connection: the server's Name field, the Now section showing Connected at home, the At home and Away addresses, Advanced, the Administrator account, and Test connection with a result for each address._

1. **Name**: optional. Used instead of the address wherever the app names this server. Worth setting if you have more than one.
2. **Now**: which address the app is using at this moment, and its host.
3. **At home** and **Away**: the two addresses.
4. **Advanced**: custom headers.
5. **Administrator account**: the username and password.
6. **Test connection**: signs in, then asks each address for Frigate's version. It changes nothing, and shows a result under each address.

After changing the address or the password, the app uses the new ones straight away. If an
alert's picture is missing afterwards, tap **Refresh connection** in **Settings ›
Diagnostics**: it hands the new details to the part of the app that fetches pictures in the
background.

## More than one server

**Settings › Add another server** adds a second NVR, such as a holiday home or a relative's
house. It opens the same Connection screen for the new server.

With more than one server, a server button appears at the top left of every tab. It shows which
server you're looking at, and switches between them. Settings follows it: the **Server**
section is about the server it names. See [More than one server](https://mobile.fregata.app/docs/cameras/several-servers/).
