Privacy-focused Windows media client for movies, TV, and anime.
NetWatch is a Windows 11 media client built with Electron/React, FastAPI, libtorrent, Prowlarr, WireGuard, FlareSolverr, and mpv.
Torrent, metadata, subtitle, and indexer traffic runs inside a shared Docker/WSL network namespace behind an inner WireGuard tunnel. The Windows app talks to the local backend; it does not directly make provider or torrent connections.
- Home, Discover, and search for movies, TV, and anime through TMDB.
- Torrent discovery through your Prowlarr indexers, with bundled FlareSolverr support for indexers that need it.
- Direct libtorrent streaming with seek-aware buffering.
- Native mpv playback with fullscreen, seeking, audio tracks, subtitles, buffering, and network stats.
- Optional OpenSubtitles and SubDL integration.
- Inner WireGuard routing with fail-closed startup checks, VPN-side DNS, and optional VPNBook profile reminders.
NetWatch 1.0 supports x64/AMD64 Windows 11 23H2 (build 22631) or newer.
You need:
- WSL2 with a normal Linux distribution; Ubuntu is recommended.
- Docker Desktop using the WSL2 backend and integrated with that distribution.
- A full-tunnel WireGuard client configuration. Generic WireGuard and VPNBook profiles are supported.
- A TMDB API key.
- Prowlarr with at least one usable indexer and a 32-character API key.
Optional subtitle providers:
- OpenSubtitles: 32-character API key.
- SubDL:
subdl_plus a 43-character key suffix. NetWatch supplies thesubdl_prefix in the UI.
The installer can help install or enable WSL, Ubuntu, and Docker Desktop. Launch Setup normally; do not use Run as administrator. Only the WSL servicing step requests UAC when needed.
- Select Generic WireGuard or VPNBook and import the provider
.conf. - NetWatch verifies the VPN, DNS path, kill switch, and egress.
- Enter the required TMDB API key. OpenSubtitles and SubDL can be skipped.
- Configure Prowlarr and enter its API key.
- Start NetWatch.
OpenSubtitles and SubDL can be added or replaced later in Settings. Settings shows only whether a key is configured; stored key values are never displayed.
NetWatch rewrites imported WireGuard profiles into its managed format. Provider command hooks are rejected, a full IPv4 tunnel (0.0.0.0/0) is required, and the profile must provide an IPv4 DNS resolver.
VPNBook uses the same WireGuard path as any other provider. Its profile-expiry estimate is only a reminder.
Private state is stored in the selected WSL distribution under:
~/.local/share/netwatch/
Normal reinstall/upgrade preserves this state.
Upgrades preserve existing API credentials. Users upgrading from 1.0.4 or earlier may be asked to re-import their provider WireGuard .conf once because the managed firewall format changed in 1.0.5. Re-import the original provider profile rather than copying an old NetWatch-managed wg0.conf. Missing optional subtitle keys do not reopen first-run setup.
NetWatch uses Prowlarr as its only indexer interface. Configure indexers in Prowlarr, not in NetWatch.
For Cloudflare-protected indexers, the bundled FlareSolverr service is available to Prowlarr at:
http://127.0.0.1:8191
Assign the same Prowlarr proxy tag to the indexers that should use it.
Build from a normal Windows NTFS path, not \\wsl.localhost\....
Required Node range: >=22.12 <23.
npm ci
npm run package:dirTest the unpacked application:
release\win-unpacked\NetWatch.exe
Build the installer:
npm run package:winOutput:
release\NetWatch-Setup-1.0.8.exe
Use npm ci for reproducible builds. See packaging/PACKAGING.md for Windows packaging details.
Private source-mode configuration is ignored by Git:
backend/.env
docker/wireguard/wg_confs/wg0.conf
docker/prowlarr/config/
When running Electron from a Windows checkout, point it at the matching WSL path:
$env:NETWATCH_WSL_DISTRO = "Ubuntu"
$env:NETWATCH_WSL_PROJECT_PATH = "/mnt/c/NetWatchBuild/netwatch"
npx electron .Start the source Compose stack from WSL:
docker compose -f docker/docker-compose.yml up -d
python3 docker/verify-networking.pyTreat the shared VPN namespace as a unit; do not recreate only the VPN container while leaving dependent services attached to the old namespace.
Backend:
python3 -m unittest discover -s backend -p 'test_*.py'Torrent engine:
python3 -m unittest -v torrent-engine/test_engine.pyConfigured-environment smoke scripts are under backend/scripts/. Some make real provider, indexer, or torrent requests.
Prerequisite setup was interrupted
Let any trusted Microsoft, Ubuntu, or Docker installer already running finish, then use Refresh checks. Do not disable endpoint protection for NetWatch.
Prowlarr is not ready
Open Prowlarr, finish its setup, configure at least one indexer, and enter its API key in NetWatch.
VPN or DNS verification fails
Run:
wsl -d Ubuntu -- sh -lc 'cd ~/.local/share/netwatch/runtime && python3 docker/verify-networking.py'Replace Ubuntu if NetWatch uses another distribution.
The Windows host VPN changed while NetWatch was running
Restart NetWatch. Host-VPN changes can interrupt Docker/WSL networking.
Packaging fails from a WSL UNC path
Move the checkout to Windows NTFS and rerun npm ci and the packaging command.
The inner WireGuard tunnel is the authoritative Internet path for NetWatch's backend services. Windows-facing services are published on loopback only, and VPN-side control ports are blocked from WireGuard peers.
A Windows host VPN can be used as an extra layer, but it does not replace the inner tunnel.
NetWatch does not promise anonymity or protection from a compromised host, VPN provider, dependency, or third-party service. See docs/network-threat-model.md for the full model and SECURITY.md for vulnerability reporting.
NetWatch is licensed under GPL-3.0-only. See LICENSE.
Third-party components keep their own licenses. See THIRD_PARTY_NOTICES.md. Bundled mpv provenance and corresponding-source details are under resources/mpv/.
See DISCLAIMER.md for the project disclaimer.





