Skip to content
Fah Swe RTC Docs
Site
AvailableLast reviewed

Authentication

The three kinds of credential in Fah Swe RTC and where each is used: App ID and App Secret on your server, media grants in the app, and signaling tokens.

Three credentials

  • App ID and App Secret: your server to the token API. Long-lived until you rotate them.
  • Media grant and media key: an app to the media servers. Minutes.
  • Signaling token: an app or your server to signaling. Minutes.

Your server to the token API

HTTP Basic authentication over HTTPS: the App ID as the user name and the App Secret as the password. The project is derived from the credential. Requests with a browser Origin header are refused.

POST /v1/rtc/tokens HTTP/1.1
Host: api.fahswertc.com
Authorization: Basic base64(APP_ID:APP_SECRET)
Content-Type: application/json

An app to the media servers

The app never authenticates with a password. It presents the media grant, a statement signed by the platform that names one project, room, user, role and set of streams, and proves it holds the matching media key during the handshake. The key itself is never sent. See /docs/security/media-encryption.

Signaling

The signaling token is returned by the token API when the request contains "signaling": true. POST requests carry it in the body as token; GET requests carry it as a Bearer header. /docs/rtc/signaling

Your own users

Fah Swe RTC does not know your users and does not sign them in. Your backend authenticates the user however your app already does, then decides which room and role they get. The user_id you send is taken on trust from your server, which is why the App Secret must never reach a client.

Lifetimes and revocation

  • Grants last 10 minutes by default and one hour at most (ttl_seconds).
  • The SDK renews through your backend before expiry.
  • To cut a user off at once, call POST /v1/rtc/tokens/revoke with the revocation_handle and stop issuing them new tokens.
Was this page helpful?