SpotiFLAC: Wails Desktop App for True FLAC from Tidal, Qobuz and Amazon Music
Get Spotify tracks in true FLAC from Tidal, Qobuz & Amazon Music — no account required.
At a glance
- What is it?
- SpotiFLAC is a Wails desktop application that resolves Spotify track links into lossless FLAC files pulled from Tidal, Qobuz and Amazon Music, with no Spotify account involved. The build is a single Go binary plus a web frontend, and the README's own FAQ already names the two things that break it: IP rate limits and antivirus flags.
- Who is it for?
- Adopt SpotiFLAC if you want a desktop, account-free path from a Spotify link to a FLAC file and you accept that metadata lookups can fail on a rate-limited IP. Skip it if you need a headless CLI, a server-side pipeline, or anything with a support commitment: the README explicitly says the software is provided as is, and the FAQ's fix for a broken fetch is to wait or use a VPN.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 45 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The gap SpotiFLAC fills between Spotify links and lossless files
Spotify does not serve FLAC. A user who has built a library of Spotify links and wants those tracks as lossless files has to either re-find each track on a service that does offer lossless, or run a tool that does the matching. SpotiFLAC is that second option, packaged as a desktop application rather than a script.
The target user is someone with a collection of Spotify track, album or playlist links who wants the audio as FLAC and is willing to run a GUI. The README's FAQ states the software is completely free and needs no account, login or subscription, only an internet connection. It also states that the tool has no connection to your Spotify account: Spotify data comes from reverse engineering the Spotify Web Player rather than user authentication. That is the design decision that removes the account-ban question, and it is also why the tool lives or dies on the quality of its metadata lookups rather than on anything you log into.
This is not a Spotify client. It is a resolver plus a downloader, and the metadata layer is the part most likely to fail in practice.
How the Wails app, Go backend and metadata APIs fit together
The repository layout makes the architecture plain. There is a Go module at the root with app.go and main.go, a backend/ directory, a frontend/ directory, and a wails.json. That is the standard Wails v2 shape: a Go process that owns the system side and a web frontend that renders the interface, with the two talking over Wails bindings. The go.mod lists github.com/wailsapp/wails/v2 v2.13.0, so the desktop shell is Wails rather than Electron or Tauri.
The Go dependencies describe what the backend actually does. github.com/go-flac/go-flac, go-flac/flacvorbis and go-flac/flacpicture handle FLAC containers, Vorbis comments and embedded cover art. github.com/bogem/id3v2/v2 covers ID3 tagging for the formats that need it. go.senan.xyz/taglib is a second tagging path. github.com/Eyevinn/mp4ff suggests MP4-family parsing, which fits a pipeline that receives audio in more than one container. go.etcd.io/bbolt is an embedded key-value store, which points to local persistence for job state or a library index rather than a server database. github.com/pquerna/otp and github.com/ulikunitz/xz are both present, though the README does not explain what either is used for, so their role is not something the documentation confirms.
On the data side, the README credits MusicBrainz, LRCLIB, Songlink/Odesli, Songstats, hifi-api and Qobuz-DL. MusicBrainz is a metadata source, LRCLIB is a lyrics database, Songlink/Odesli maps a track across services, and hifi-api is the piece that reaches the lossless catalogues. The README's answer to where the audio comes from is short: the audio is fetched using third-party APIs. So the flow is roughly a Spotify link in, a cross-service match through the metadata providers, a fetch from the lossless backend, then tagging and FLAC assembly in Go. The README does not document retry behaviour, cache invalidation or what happens when a match is ambiguous.
Installing SpotiFLAC and running a first download
There is no package manager step. The README's download section points at the GitHub releases page, and the release badges cover Windows, macOS and Linux, so the intended install is a prebuilt binary for your platform from the latest release. There is no documented Homebrew formula, npm package, Docker image or CLI entry point.
If you would rather not run a prebuilt binary, the FAQ's own advice for antivirus flags is to fork the repository and build the software yourself from source. The repository is a Wails project, so the build depends on the Wails CLI and a Go toolchain matching the go directive in go.mod, which is go 1.26. The README does not spell out those build commands, so the only install path it documents is the releases page, and the fallback it names is forking and building from source yourself.
Once the binary is running, paste a Spotify track link into the input and start the download. What you should see is the app resolve the track against its metadata sources and then write a FLAC file with tags and cover art. If the metadata step fails, the README already explains the likely cause and the two remedies it offers are waiting or using a VPN, so a first run that errors out is a rate-limit symptom rather than a bug report.
Rate limits, false positives and the missing command line
The most concrete limitation is documented by the project itself. The FAQ asks why metadata fetching sometimes fails and answers that your IP address has probably been rate-limited, with the suggested fixes being to wait and try again later or to use a VPN. That is a real operational constraint: the tool depends on third-party APIs it does not control, and the failure mode is a hard stop in the middle of a job rather than a degraded result. There is no documented backoff, queue or retry configuration in the README.
The second limitation is distribution. The FAQ addresses Windows Defender or antivirus flagging or deleting the file, attributes it to the executable being compressed with UPX, and calls it a false positive. Whether you accept that explanation or not, the practical effect is the same: on managed Windows machines the download may simply disappear, and the project's own answer is to build from source. For anyone in an environment with endpoint protection they do not administer, that is close to a blocker.
Third, this is a GUI application. The dependency list and the Wails shell point at a desktop process, and the README documents no headless mode, no server mode and no scriptable interface. If your workflow is a cron job that processes a playlist nightly, or a container in a CI pipeline, SpotiFLAC is the wrong shape of tool regardless of how well the download itself works. The README also does not document rollback, partial-file cleanup or resume, so a job interrupted by a rate limit is an open question rather than a documented behaviour.
SpotiFLAC against Soulseek and against SpotiFLAC Next
The comparison people actually search for is SpotiFLAC versus Soulseek, and the difference is structural rather than a matter of quality. Soulseek is a peer-to-peer network where files come from other users' shares. Availability depends on who is online, quality depends on what each user ripped, and you get a client with search, chat and queueing built around a social protocol. SpotiFLAC inverts all of that: it is a single-user desktop app that queries commercial lossless catalogues through third-party APIs, so the file is whatever Tidal, Qobuz or Amazon Music serves for that track. You get consistent provenance and predictable quality, and you give up the long tail. A live bootleg, an out-of-print pressing or a track absent from the streaming catalogues is not something SpotiFLAC can find, because there is no catalogue entry to resolve. Soulseek has no such boundary and no such consistency.
The second comparison is internal. The README lists SpotiFLAC Next as another project by the same author, described as getting Spotify tracks in true lossless from Tidal, Qobuz, Amazon Music and Deezer, with no account required. The stated difference is the extra source: Next adds Deezer to the list. The README does not explain whether Next replaces the desktop build or sits alongside it, and it does not describe a different architecture. If you are choosing between them, the README only tells you that one has a fourth catalogue. It also notes that the mobile and Python variants are community-maintained and not affiliated with the core desktop build, which matters if you were expecting the same support path across platforms.
Licence, maintenance and what an upgrade costs you
The repository is MIT licensed, which is permissive: you can fork it, modify it and redistribute it, and the README's antivirus advice explicitly assumes you might fork and build your own binary. MIT also means there is no warranty, which lines up with the README's disclaimer that the software is provided as is and the author assumes no liability for bans, damages or legal issues arising from its use. The disclaimer further states the project is for educational and private use only and that you are responsible for complying with local law and with the terms of service of the platforms involved. That is a statement about the project's intent, not a legal shield for the user, and it is worth reading in full before running anything.
Maintenance looks current on the evidence available. The last push to the default branch was on 2026-08-17, and the releases list shows v7.2.2 on 2026-08-17, v7.2.1 on 2026-08-11 and v7.2.0 on 2026-07-18. Three releases in about a month, with the newest on the same day as the last push. The repository is not archived.
Upgrade cost is low by construction. There is no server, no database migration and no config file documented in the README, so upgrading means replacing a binary. The bbolt dependency implies local state that could in principle need migration between versions, but the README does not document any upgrade procedure or state format, so treat that as unverified. The real cost of staying current is not the upgrade, it is that the tool's usefulness depends on third-party APIs and reverse-engineered endpoints that can change without notice, and a release that fixes a broken source is the only remedy the project offers.
Editorial conclusion
Adopt SpotiFLAC if you want a desktop, account-free path from a Spotify link to a FLAC file and you accept that metadata lookups can fail on a rate-limited IP. Skip it if you need a headless CLI, a server-side pipeline, or anything with a support commitment: the README explicitly says the software is provided as is, and the FAQ's fix for a broken fetch is to wait or use a VPN. Before you commit, check the latest release page for your platform, and if antivirus deletes the binary, build from source instead of trusting the download.
Frequently asked questions
What does SpotiFLAC do?
It takes Spotify tracks and produces true FLAC files, with the audio fetched from Tidal, Qobuz and Amazon Music through third-party APIs. It runs as a desktop application and requires no account, login or subscription, only an internet connection.
Is SpotiFLAC safe to use?
The README states the tool has no connection to your Spotify account, since Spotify data is obtained by reverse engineering the Spotify Web Player rather than through user authentication. It also warns that antivirus software may flag or delete the executable because it is compressed with UPX, which the project calls a false positive, and suggests building from source if that concerns you.
Why does SpotiFLAC not work?
The README's FAQ attributes metadata fetching failures to your IP address being rate-limited by the third-party APIs. The two remedies it gives are waiting and trying again later, or using a VPN to bypass the rate limit.
Is SpotiFLAC open source?
Yes. The repository is public and licensed under MIT, and the README's own advice for antivirus concerns is to fork the repository and build the software yourself from source.
What is the difference between SpotiFLAC and SpotiFLAC Next?
The README describes SpotiFLAC Next as getting Spotify tracks in true lossless from Tidal, Qobuz, Amazon Music and Deezer with no account required, so the stated difference is the addition of Deezer as a fourth source. The README does not explain whether Next replaces the desktop build or is meant to be used alongside it.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/spotbye-spotiflac)