- Test passwords safely with a temporary user and private browser window.
- Fix mismatched user databases, saved credentials, and authentication settings.
- Restore correct per-library access without deleting or rebuilding your library.
- Confirm the Symptom With a Small Safe Test
- Check Content Server Authentication and User Management
- Check Anonymous Access and Library Permissions
- Eliminate Browser, Network, and Operating System Causes
- Use Logs and Command-Line Checks to Find the Mismatch
- Run a Clean Temporary Test Before Reinstalling
- Quick Fix Checklist
- Frequently Asked Questions
When calibre Content server user accounts are not working, the cause is usually narrower than it first appears. Authentication may be disabled, the browser may be reusing an old password, the server may be reading a different user database, or the account may have restrictions that hide a library or some of its books. Network and operating system issues can also resemble an account failure when the browser is not actually reaching the expected server. The safest approach is to confirm the symptom with one temporary account, test it in a private browser window, and change only one setting at a time.

Start with free Canva bundles
Browse the freebies page to claim ready-to-use Canva bundles, then get 25% off your first premium bundle after you sign up.
Free to claim. Canva-ready. Instant access.
1. Confirm the Symptom With a Small Safe Test
Start by separating an authentication problem from a library-access or network problem. Do not delete your library, recreate every user, or reinstall calibre yet. Those actions can hide the original cause without proving what was wrong.
1.1 Verify That You Are Reaching the Correct Content Server
Open calibre on the computer hosting the library and confirm that the Content server is running. In the main calibre window, use the Connect/share menu and check the server status. Then open the server address from a browser on the same computer.
Pay close attention to the hostname, IP address, port, protocol, and any URL path used by a reverse proxy. A saved bookmark may point to an old computer, a previous port, or another calibre installation. If you administer more than one server, temporarily stop the expected server and refresh the page. The page should stop responding. Start it again and confirm that access returns.
Success means you have proved that the browser is reaching the calibre instance whose users you are editing. Stop changing network settings once this is confirmed.
1.2 Create One Temporary Test User
Open Preferences, find the Content server or Sharing over the net settings, and open the user-account management area. Create a temporary user with a unique username and a newly typed password. For the first test, avoid special library restrictions unless access must remain tightly controlled. Do not reuse a username already stored in the browser.
Restart the Content server if calibre indicates that a restart is required. Open a private or incognito browser window, enter the server address manually, and sign in with the temporary account.
- If the test account works, the server-wide authentication system is functioning.
- If the login works but a library is missing, investigate that user's library restrictions.
- If the login repeatedly fails, verify authentication settings, password handling, and the active user database.
- If no login prompt appears, authentication may not be enabled or an anonymous route may be in use.
Success means the temporary user can sign in and see exactly the libraries and books you intentionally allowed. Once that happens, stop changing global server settings and compare the failing account with the working one.
2. Check Content Server Authentication and User Management
The calibre desktop application can manage Content server users through its preferences. A standalone calibre-server process can also maintain users through the command line. Problems occur when the user is changed in one place while the running server reads its accounts from another place.
2.1 Confirm That Username and Password Protection Is Enabled
In calibre, open Preferences and the Sharing over the net settings. Confirm that the option requiring a username and password is enabled. Apply the change and restart the Content server rather than assuming a running process has adopted every edited option.
Test again in a private browser window. A protected server should request credentials from a fresh browser session. If the server opens directly without requesting a login, verify that you are using the correct address and that a proxy, trusted-address rule, or separate server process is not providing anonymous access.
Success means a new private session requests credentials and rejects an intentionally incorrect password. Stop adjusting authentication once both behaviors are confirmed.
2.2 Change the Password Carefully
Edit the affected account and set a temporary password that is easy to type accurately but is not used anywhere else. Check keyboard layout, capitalization, and accidental spaces. Mobile keyboards can capitalize the first character, while password managers may fill credentials saved for a similar hostname.
After saving the password, restart the server and test through a private browser window. Type the username and password manually for this test. If the temporary password works, replace it with a strong, unique password and update authorized clients.
Success means the new password works in a fresh session and the old password no longer works. At that point, do not recreate the user unless its permissions are also incorrect.
2.3 Check for a Different User Database
This check is especially important when calibre-server runs as a service, inside a container, under another operating system account, or from a custom startup command. The standalone server can be given a particular user database with the --userdb option. If you manage one database but the service starts with another path, your edits will appear to be ignored.
Inspect the actual service definition, shortcut, scheduled task, container configuration, or startup script. Look for --userdb and confirm that account management uses the same database path. A standalone configuration can be managed with a command in this form:
calibre-server --userdb /path/to/users.sqlite --manage-users
The running server must then reference that same file and have authentication enabled:
calibre-server --userdb /path/to/users.sqlite --enable-auth /path/to/library
Adapt the paths for Windows, macOS, or Linux. Quote any path containing spaces. Avoid creating a second database in the current working directory by accidentally omitting the intended path.
Success means a user created or changed through the management command can immediately authenticate against the restarted server. Stop changing account records once you have verified that both operations use the same database.
3. Check Anonymous Access and Library Permissions
Successful authentication does not guarantee that every user will see every library or book. calibre can limit the libraries visible to a user and can apply search-based restrictions within a visible library. This distinction explains many reports in which a password works but the expected content does not appear.
3.1 Understand Anonymous and Authenticated Access
Without password authentication, the Content server can permit unrestricted browsing, but anonymous use is normally limited in ways designed to protect library data. Authentication identifies a user and allows calibre to apply that account's permissions. Options that permit local or trusted clients to make changes are not substitutes for properly configured user accounts.
Do not troubleshoot a missing login prompt by broadly allowing unauthenticated writes. That increases risk and does not correct a mismatched account database or browser credential problem. Use a named test user instead.
Success means anonymous behavior matches your intended configuration, while authenticated users receive their assigned access. Once confirmed, leave unrelated write-access options unchanged.
3.2 Review Per-Library Access
Edit the affected account and inspect which libraries it may access. If several libraries are served, confirm that the desired library is explicitly available to that user. Library names, locations, or identifiers may have changed after moving or recreating a library, so verify the current library rather than relying on an old expectation.
Remove restrictions temporarily only if doing so is safe for your environment. Sign in with the test user and check whether the missing library appears. Then restore the intended restriction carefully.
Success means the account sees all allowed libraries and no disallowed libraries. Stop changing server-wide settings if the issue disappears when the account's library assignment is corrected.
3.3 Inspect Search and Virtual Library Restrictions
A user can be allowed into a library while still seeing only books that match a search restriction. A virtual-library expression can provide intentional per-user filtering, but a renamed virtual library, invalid expression, unexpected metadata value, or overly narrow search can produce an empty or incomplete catalog.
Temporarily test the account without the book-level restriction. If all books appear, authentication is working and the restriction is the problem. Reapply a simple known-good restriction and expand it gradually. Test the equivalent search in the main calibre interface to confirm that it returns the books you expect.
Success means the user sees the intended subset of books and the same search produces comparable results in the desktop library. Stop modifying account credentials once the problem has been isolated to a restriction.
4. Eliminate Browser, Network, and Operating System Causes
Browsers cache authentication state, password managers submit stale credentials, and network components can route requests to the wrong process. These issues can make a correct calibre configuration appear broken.
4.1 Test in a Private Browser Window
A private window is one of the most useful tests for calibre Content server user accounts not working. It starts without the ordinary session's saved login state and reduces interference from extensions and stored site data.
- Close any open Content server tabs.
- Open a private or incognito window.
- Type the server address rather than selecting an old bookmark.
- Enter the username and new password manually.
- Sign out, close the private window, and repeat the test once.
If this works, clear the saved password and site data for the server in the regular browser. Also update any password-manager entry associated with the old address or password.
Success means both a new private session and a cleaned regular session accept the current credentials. Stop editing calibre users at that point because the failure was in browser state.
4.2 Compare Browsers and Client Applications
Test with a second current browser on the same computer. If the browser works but an OPDS reader or mobile application fails, review that application's authentication fields and remove its saved catalog entry before adding it again. Confirm that it supports the authentication method used by your server.
If one browser repeatedly submits the wrong credentials, disable password-filling extensions temporarily. Do not weaken server security merely to accommodate one stale client configuration.
Success means at least two clean clients can sign in, or the failure is isolated to one application. Once isolated, troubleshoot that client rather than changing calibre's working account configuration.
4.3 Check Firewall, Antivirus, Proxy, and Network Routing
A firewall normally causes a timeout or connection refusal rather than a rejected password. Still, a reverse proxy, VPN, router rule, or security product can direct the browser to a different service or interfere with requests.
First test from the server computer using its local address. Then test from another device on the same network. Confirm that the firewall allows the calibre Content server on the appropriate network profile. If a reverse proxy is used, test calibre directly on its local port to separate proxy behavior from calibre authentication.
On Linux, confirm that the service account can read the user database and library files. On Windows and macOS, verify that security software has not quarantined, blocked, or isolated the server executable. Cloud-sync software should not be allowed to create conflicting copies of an actively used user database.
Success means the same test account works locally and through the intended network route. Stop changing firewall rules once access is proven, and avoid leaving broad temporary exceptions enabled.

5. Use Logs and Command-Line Checks to Find the Mismatch
Logs are useful when a clean browser test still fails. They can show whether requests reach calibre, whether the service starts with the expected options, and whether file-access errors prevent the server from using its configuration.
5.1 Inspect Server and Access Logs
If you launch calibre-server manually, read the terminal output during startup and while attempting a login. For a service, inspect its service manager output and configured log files. The standalone server supports a server log for errors and an access log for client requests.
Look for the listening address and port, the libraries loaded, permission errors, missing files, startup-option mistakes, and requests arriving from your test browser. Avoid sharing logs publicly without removing usernames, internal addresses, file paths, tokens, and other private details.
Success means the log shows the expected server starting cleanly and receiving your test request. If the request never appears, return to network routing. If startup reports a user-database problem, correct its path or file permissions.
5.2 Verify the Process and Service Account
On Linux, check the running service definition and confirm which user and group launch calibre-server. That account should have suitable access to the library and user-database files. On Windows, inspect Task Manager, Services, startup shortcuts, and scheduled tasks for duplicate calibre-server processes. On macOS, check for launch agents, login items, or manually started instances.
Stop duplicate instances safely and start only the intended one. A second process may use another port or configuration, leading to inconsistent login results.
Success means one known process owns the intended port and starts with the expected options. Stop terminating processes once the server identity is clear.
5.3 Use calibre-debug Only When It Adds Evidence
The calibre-debug utility can help identify configuration and startup conditions, but it should not be used as a reason to reset everything. Record the exact command, output, and operating system account involved. Compare behavior when the server is started manually with behavior under its normal service manager.
If manual startup works but the service does not, the likely difference is the service account, environment, working directory, file permissions, or command-line arguments. Fix that difference rather than reinstalling the application.
6. Run a Clean Temporary Test Before Reinstalling
A controlled temporary test can distinguish damaged account data from a server-wide problem without risking your real library. Back up relevant configuration files before changing them, and do not move or delete the original library.
6.1 Build the Smallest Useful Test
- Create a temporary folder outside the active calibre library.
- Create or select a small temporary library containing one non-sensitive test book.
- Use a separate temporary user database if testing the standalone server.
- Create one user with a new username and password.
- Enable authentication and start the server on an unused port.
- Connect through a private browser window.
If the clean server works, calibre's authentication mechanism is operating and the original problem lies in its user database, startup options, restrictions, permissions, proxy, or browser state. Compare those elements one at a time.
If the clean test also fails, capture the exact error and inspect the server output, port ownership, executable path, and operating system permissions. Reinstallation should be considered only after you have shown that a clean configuration fails with the correct executable.
6.2 Avoid Destructive Shortcuts
Do not delete the main library, remove its metadata database, or erase all calibre preferences to fix a login problem. Content server user accounts are separate from book conversion, metadata editing, device transfer, and e-book file quality. Rebuilding unrelated data adds risk without addressing authentication.
Stop troubleshooting when the intended account can sign in from a clean session, sees the correct libraries and books, and behaves consistently after a server restart. Additional changes after that point can reintroduce the problem.
7. Quick Fix Checklist
- Confirm the browser is reaching the calibre server you are actually configuring.
- Enable the setting that requires a username and password.
- Restart the Content server after changing authentication settings.
- Create one temporary user with a unique username and password.
- Test the account in a private browser window.
- Remove stale credentials from the browser and password manager.
- Check the user's allowed libraries and book-level search restrictions.
- Confirm standalone management and startup commands use the same user database.
- Check that the server account can read the user database and library.
- Look for duplicate server processes or an old service configuration.
- Test calibre directly before troubleshooting a reverse proxy.
- Use logs to determine whether the request reaches the intended server.
- Run a separate temporary server test before reinstalling or deleting anything.
8. Frequently Asked Questions
8.1 Why Does calibre Keep Rejecting a Password I Just Changed?
The browser or password manager may still be submitting the old password, the running server may not have been restarted, or you may have edited a different user database from the one the server uses. Test the new password manually in a private window and verify the active --userdb path if you run calibre-server separately.
8.2 Why Can a User Sign In but Not See a Library?
The account probably has per-library permissions that do not include that library. Edit the user, review the visible or allowed libraries, save the setting, and test again. If the library appears but contains no books, inspect any search or virtual-library restriction.
8.3 Why Does calibre Open Without Asking for a Username?
Authentication may be disabled, the browser may already have an authenticated session, or the address may lead to another server. Use a private browser window and intentionally enter a wrong password. If no login is required, confirm the username-and-password requirement and restart the server.
8.4 Can Anonymous Users and Authenticated Users Have Different Access?
Yes. Authentication allows calibre to identify a user and apply account-specific library or book restrictions. Anonymous access does not behave like a named account, and options that allow local or trusted clients to make changes should not be confused with user authentication.
8.5 Should I Reinstall calibre to Fix User Accounts?
Usually not. Reinstallation may leave the same configuration, service command, browser credentials, and user database in place. First test a temporary user, a private browser window, the active user-database path, account restrictions, and a clean temporary server.
8.6 Does This Problem Affect Book Files or Metadata?
Normally, no. A Content server login failure concerns authentication, permissions, browser state, server configuration, or network routing. Do not delete books or rebuild metadata unless separate evidence shows an actual library problem. Authentication is fixed when a clean client can sign in and see only the content assigned to that user.