Library / SDK
rawnaldclark/Stash avatar
rawnaldclark/Stash

Stash: Mirror Spotify and YouTube Music to Android as FLAC

Your Spotify + YouTube Music library & daily mixes. Stream or download in lossless FLAC. Free and open source forever.

1,106 stars44 forksKotlinGPL-3.0

At a glance

What is it?
Stash is an Android app that connects to your Spotify and YouTube Music accounts through browser cookies and syncs playlists and daily mixes either as lossless FLAC files or as a streaming index. It is for people who want their library on their own device, and it costs storage or a connection depending on the mode you pick.
Who is it for?
Adopt Stash if you are on Android 8.0 or later, you already keep Spotify or YouTube Music subscriptions, and you have 9 to 15 GB of storage to spare for a medium library in Offline mode. Skip it if you need iOS, if you want an official API integration that survives upstream changes, or if you cannot accept pasting a session cookie that a web logout revokes.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 5 days ago.
What is it written in?
Mainly Kotlin, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Stash actually solves for Android listeners

Spotify and YouTube Music both keep your library in their cloud. Neither ships a supported way for a third-party Android app to pull a playlist down as lossless files, and neither lets you keep two services in a single view. Stash targets exactly that gap. It mirrors liked songs, playlists and daily mixes from both services into one library on the phone, then lets you choose what a sync means: real FLAC files on disk, or a local index that streams through your existing connection. The README frames the choice as "Same library, two modes, one tap to switch."

The audience is narrow and specific. You need an Android device, an account on at least one of the two services, and a tolerance for the cookie-based login the README describes. Desktop users are not served. iPhone users are not served. Anyone who wants a hosted service with a web player is not served, because there is no Stash account and no Stash server. The project is GPL-3.0 and the README states there are no ads, no analytics and no third-party crash reporters.

How the cookie login and the FLAC backbone fit together

Stash does not use the official Spotify or YouTube APIs. The README is direct about why: those APIs do not permit a third-party app to do what Stash does. Instead, Stash authenticates with your existing browser session cookies. For Spotify that is a single cookie named sp_dc; for YouTube Music it is the whole cookie header, because YouTube authenticates with several cookies together, including SAPISID, __Secure-3PAPISID and LOGIN_INFO. Cookies are stored on-device and encrypted with AES-256-GCM through Google's Tink library. The README states the only network requests Stash makes go to Spotify and YouTube directly.

Lossless files do not come from Spotify or YouTube. The README credits a "FLAC backbone" made of QBDLX, a program that downloads streams directly from Qobuz, and arcod. That is the part worth pausing on. Stash is the library manager and player; the actual lossless source sits in separate projects maintained, in the README's words, by people "mostly solo, mostly free." If those projects stall, the FLAC path is the part of Stash most exposed.

Matching is the other mechanism the README calls out. It claims to find the right version of a track "99% of the time" and provides a wrong-match flag from Now Playing that queues a re-search. Treat that percentage as the project's own claim, not a measured figure.

Installing Stash and running a first sync

The README gives three install paths. The simplest is the direct APK: open the Releases page on the Android device, download the latest Stash-v*.apk, allow installs from unknown sources for the browser if Android warns, then tap Install. Obtainium is the auto-update route; add the repository URL and Obtainium tracks GitHub Releases for you.

Building from source is the third path, and the README lists the toolchain: Android Studio Hedgehog (2023.1.1) or later, JDK 17, and Android SDK 35.

bash
git clone https://github.com/rawnaldclark/Stash.git
cd Stash
./gradlew assembleDebug
# APK lands in app/build/outputs/apk/debug/

After the build finishes, the debug APK is in app/build/outputs/apk/debug/ as the comment notes.

Once installed, setup is per service. In the app, go to Settings, tap Spotify or YouTube under Accounts, and tap Connect. The in-app login opens the service's own login page; Stash extracts the cookie when login succeeds. If that fails, the manual route for Spotify is to log in at open.spotify.com on a computer, open DevTools with F12, go to the Application tab (Storage on Firefox), expand Cookies for https://open.spotify.com, copy the value of the sp_dc cookie, then paste it into Stash under Settings, Spotify, Connect, "Paste cookie". The README warns that cookies from incognito or private windows sometimes fail to sync, so use a regular window.

For YouTube Music the manual route is different: open music.youtube.com, press F12, switch to the Network tab, refresh, filter for browse, click a request, and copy the entire value after cookie: in Request Headers. Then paste it into Settings, YouTube Music, Connect. After setup, open the Sync tab; the README notes that before tapping Sync Now you should expand the Spotify Sync Preferences card and pick your playlists.

Where Stash is the wrong tool

The cookie dependency is the biggest constraint. A cookie is a session credential, and the README states it can be revoked by logging out of Spotify on the web. That means an innocent logout on a desktop browser can break your phone's sync until you paste a fresh cookie. Nothing in the README describes a rollback path for a failed sync, and there is no documented migration or backup format for a library already downloaded. If you sync a large library and something goes wrong, the recovery story is not written down.

Storage is the second constraint. Offline mode needs roughly 9 to 15 GB free for a medium library, and the README says that scales with how much you sync. Online mode avoids the storage cost but requires a connection to play anything, which makes it useless on a flight or in a dead zone. Neither mode is a compromise-free middle.

Platform is the third. Android 8.0 (API 26) is the floor and there is no iOS build, no desktop build and no web player mentioned anywhere in the README. If your listening happens on a laptop, Stash does not address it. And if you need an integration that survives upstream authentication changes without you touching anything, a cookie-based client is structurally the wrong choice.

Stash against the official API route

The obvious alternative is an app built on Spotify's and YouTube's official APIs. The trade-off is not subtle. An official-API client gets a supported authentication flow, so tokens refresh without the user copying anything from DevTools, and it is far less likely to break when the service changes how it authenticates. What it cannot do is what Stash exists for: the README states plainly that the official APIs do not let third-party apps do what Stash does, which is why the cookie path exists at all. A Spotify-API client also cannot unify YouTube Music into the same library, and it will not hand you a FLAC file, because the official APIs do not serve lossless downloads to third-party clients.

So the choice is between a supported integration with a ceiling on features and an unsupported one with a manual setup step and a dependency on external downloader projects. Stash picks the second. That is a defensible pick for a personal library on your own phone, and a poor one for anything you need to keep running unattended.

Maintenance cost, releases and the GPL-3.0 licence

The repository is not archived, and the last push was on 2026-08-24, which is recent. The release history is dense: v0.9.100 on 2026-08-24, v0.9.99 on 2026-08-18, v0.9.98 on 2026-08-16. Three releases inside nine days is a fast cadence, and it cuts both ways. Fixes arrive quickly; so do changes you may not want mid-library. Obtainium users get notified on each release, which means the update decision lands on you repeatedly.

Stash is GPL-3.0. If you fork it, build on it or redistribute a modified APK, the licence's copyleft terms apply to what you distribute, and the README points at the LICENSE file for the text. Running it on your own phone is not distribution. This is a description of the licence, not legal advice; read LICENSE and, if you plan to ship a modified build, get proper counsel.

The other maintenance cost is external and easy to miss. The FLAC path depends on QBDLX and arcod, separate projects the README describes as run by people doing it for the love of it. Your Stash build can be perfectly healthy while the thing that produces lossless files is not. Nothing in the repository makes that dependency disappear.

Editorial conclusion

Adopt Stash if you are on Android 8.0 or later, you already keep Spotify or YouTube Music subscriptions, and you have 9 to 15 GB of storage to spare for a medium library in Offline mode. Skip it if you need iOS, if you want an official API integration that survives upstream changes, or if you cannot accept pasting a session cookie that a web logout revokes. Before committing, verify three things: that your device has the free space the README quotes, that the cookie you paste is from a regular browser window rather than incognito, and that the FLAC backbone projects the README credits are still reachable, since Stash depends on them for real lossless files rather than re-encodes.

Frequently asked questions

How do I install Stash on Android?

Download the latest Stash-v*.apk from the Releases page, allow installs from unknown sources for your browser if Android warns, and tap Install. Obtainium can track the repository and notify you about new releases, or you can build from source with ./gradlew assembleDebug.

How do I use the Stash app after installing it?

Go to Settings, tap Spotify or YouTube under Accounts, and tap Connect to sign in, or paste a cookie manually if in-app login fails. Then open the Sync tab, expand the Spotify Sync Preferences card to pick your playlists, and tap Sync Now.

Does Stash need a Stash account or a subscription?

No. The README states there is no Stash account, no subscription, no ads and no analytics, and that credentials live encrypted on your phone. You do need a Spotify and/or YouTube Music account to sync anything.

What is the difference between Online and Offline mode in Stash?

Offline mode downloads each track as a FLAC file and stores it on the phone, so playback works with no connection at the cost of storage. Online mode builds a streamable local index, which uses almost no storage but requires a connection to play.

Why does Stash ask for a browser cookie instead of using Spotify login?

The README says the official APIs do not let third-party apps do what Stash does, and that Spotify's mobile login API does not allow third-party apps at all. Cookies are stored on-device encrypted with AES-256-GCM via Google's Tink and are only sent back to Spotify or YouTube.

Official sources

  1. Official README
  2. Project repository
  3. Release notes
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/rawnaldclark-stash.svg)](https://hysenlabs.com/projects/rawnaldclark-stash)