Decryption Keys
How freemkv decrypts a disc depends on its format: DVDs need nothing, while Blu-ray and 4K UHD need keys you supply.
DVDs decrypt automatically. There are no keys to install and nothing to configure.
Blu-ray and 4K UHD
Section titled “Blu-ray and 4K UHD”| Format | Encryption |
|---|---|
| Blu-ray | AACS 1.0 |
| 4K UHD | AACS 2.0 / 2.1 |
AACS-encrypted discs decrypt only when you supply AACS keys. No AACS keys are built in.
Provide them one of two ways: an online key service or a local keydb.cfg. Both autorip and
the freemkv CLI support either source.
Online key service
Section titled “Online key service”A third-party web service looks up keys for an inserted disc on demand, so you don’t maintain a local file — and it’s generally much more compatible with AACS 2.0+ discs. Reach out on our support Discord for more access information.
In autorip, enable the online key service and set its URL under Settings. See autorip Service.
In the CLI, point at the service with --key-url (and --key-auth if it requires a
bearer token):
# resolve keys from an online key service — main title onlyfreemkv disc:// -t 1 mkv://Movie.mkv --key-url https://keys.example/keys
# with an authentication tokenfreemkv disc:// -t 1 mkv://Movie.mkv --key-url https://keys.example/keys --key-auth <TOKEN>For title selection and source/destination behavior, see the CLI reference.
For how --key-url and --keydb interact (local-first) and the SSRF guard on the
service URL, see CLI → Flags.
Local keydb.cfg
Section titled “Local keydb.cfg”A keydb.cfg file on disk. It is the single source of AACS truth — no AACS keys are
compiled into the freemkv binary. The file holds the AACS material freemkv draws on to
unlock a disc: device keys (DKs), processing/player keys (PKs), host certificates for the
drive’s secure handshake, and per-disc entries — a Volume Unique Key (VUK),
unit (title) keys, or a Media Key.
By default the CLI looks for it next to the freemkv
executable — a keydb.cfg in the same folder as the program. freemkv is a portable,
self-contained binary, so its key database lives beside it rather than in an OS
configuration directory.
Refresh it from a URL with the update-keys command — see the
CLI reference for the full syntax and supported formats (.txt / .zip /
.gz). The short version writes keydb.cfg next to the executable:
freemkv update-keys --url <KEYDB_URL>The global --keydb flag points the CLI at a keydb.cfg anywhere — on
update-keys to download there, and on a rip to read from there:
freemkv update-keys --keydb /path/to/keydb.cfg --url <KEYDB_URL> # download to a custom pathfreemkv disc:// -t 1 mkv://Movie.mkv --keydb /path/to/keydb.cfg # rip using itautorip is a long-running service rather than a portable binary, so it uses the standard
config location ~/.config/freemkv/keydb.cfg and can also download and refresh the file for
you from Settings. For the Docker image, bind-mount a host keys directory to
/root/.config/freemkv (see autorip → Deploy) so it persists across
restarts.
When keys are missing
Section titled “When keys are missing”If you rip an AACS-encrypted disc with no key source configured, freemkv fails loudly and early — a clear error message, non-zero exit, and no output file written. It never writes a silently-encrypted or partially-decrypted file. autorip marks the disc “Missing keys — no key source has a key for this disc” and, when nothing is configured at all, prompts “No keys are available. Configure a key source in Settings.” DVDs are never affected.