FairPlay
FairPlay in C21 Live Control
FairPlay is Apple's DRM. It reaches Safari, iOS, iPadOS, tvOS and macOS — the Apple device ecosystem. In Live Control it appears as one of the three systems exposed by DrmProvider.supported_systems and one of the values a Destination's drm.systems[] array can carry.
This page covers what goes into the provider record when the upstream multi-DRM service supports FairPlay. For the end-to-end flow, see DRM workflow. For the provider catalogue and CRUD, see Providers.
Where the configuration comes from
FairPlay integrations are issued by Apple to content owners. The upstream multi-DRM vendor (for example AXINOM or EZDRM) handles the FairPlay Streaming (FPS) handshake on the customer's behalf: it manages the FairPlay certificate, derives content keys, and serves the Content Key Context (CKC) response when a player issues a Server Playback Context (SPC) request.
The vendor hands over the same SPEKE endpoint and credentials used for Widevine and PlayReady — there is no separate FairPlay form in Live Control. The provider record's supported_systems declares whether the vendor's FairPlay support is enabled for this account.
Packaging requirement: CBCS
FairPlay only consumes content encrypted in cbcs mode (AES-CBC with subsample-based pattern encryption). A Destination with systems = [FairPlay] requires encryption_mode = cbcs. The API always rejects FairPlay with cenc. Because cbcs also carries Widevine and PlayReady, one CMAF Destination in cbcs can serve all three systems from a single packaging.
Attaching FairPlay to a Destination
DRM is applied to a Destination via its drm block (see Destinations):
active = true.provider_idset to the FairPlay-capable provider.systems = ['FairPlay']for Apple only, or['Widevine', 'PlayReady', 'FairPlay']to serve every ecosystem from one CMAF Destination.encryption_mode = cbcs. The server derives it for a FairPlay-only selection; send it explicitly when FairPlay is combined with the other systems.contentidset to the content identifier the upstream vendor expects.
FAQ
cenc / AES-CTR scheme used by classical DASH-only Widevine and PlayReady deployments is not accepted by FairPlay clients.encryption_mode = cbcs: players pick the system they support from the same segments. Devices that only support cenc need a separate cenc Destination for Widevine and PlayReady; bundle both under a Destination group to bind them to a Live stream through one reference.