Architecture
How a Fah Swe RTC session works end to end: your backend, the token API, the media servers, signaling and the relay, and what travels where.
The components
- Your backend: knows your users, decides who may enter which room, holds the App Secret.
- Token API (
api.fahswertc.com, alsotoken.fahswertc.com): issues short-lived media grants to your backend. - Media servers (
sfu.fahswertc.com, UDP): receive each publisher's media once and forward it to the subscribers of that stream. They do not mix or transcode. - Signaling (
signal.fahswertc.com, HTTPS): room membership, seats, co-hosts and PK state. - TURN relay (
turn.fahswertc.com): carries media for devices whose network blocks direct UDP. - Console (
console.fahswertc.com): projects, credentials, usage and diagnostics.
A session, step by step
- 1. The user opens a room in your app. The app asks your backend for credentials.
- 2. Your backend checks the user and calls
POST /v1/rtc/tokenswith the room, user and role. - 3. The token API checks the credential, the project's allowance and the requested rights, then returns a media grant, a media key and the media server address.
- 4. Your backend passes the grant, key and address to the app.
- 5. The SDK contacts the media server. The server answers only with a challenge until the SDK proves it holds the key for a valid grant.
- 6. Both sides derive session keys with an ECDH P-256 exchange. From then on every packet is encrypted with AES-256-GCM.
- 7. The SDK publishes and subscribes to the stream ids named in the grant. Before the grant expires it asks your backend for a new one and switches without a gap.
What goes through your servers
Only the token request. Audio and video never pass through your backend; they travel between apps and our media servers. This keeps your backend small: one authenticated endpoint.
Forwarding, not mixing
The media servers are selective forwarding units. A room with five speakers and a hundred listeners has five incoming streams, each forwarded to the participants subscribed to it. Listeners receive the speakers' streams and mix them on the device.
Usage measurement
The media servers report every authenticated session. The platform totals participant-seconds per account and, when an allowance is used up, tells both the token API and the media servers to refuse the account's sessions. Apps do not report usage.
Current limits
- One region: Singapore. Participants far from it will see higher latency.
- Media is decrypted on the media server to be forwarded. It is not end-to-end encrypted between participants.
- Signaling keeps room state in memory. After a signaling restart, clients create or join the room again.