Skip to content
Fah Swe RTC Docs
Site
ImplementedLast verified 2026-10-10

Security overview

How Fah Swe RTC protects your credentials, users and media.

Overview

Security is layered: your App Secret never leaves your server, apps receive short-lived scoped grants, and every media packet is authenticated and encrypted.

What the platform does

  • Media: signed grants, ECDH P-256 key agreement, AES-256-GCM encryption and replay protection
  • Tokens: lifetime capped at one hour (10 minutes by default); grants can be revoked
  • Token API refuses browser calls, so a leaked secret in a web page fails immediately
  • Optional IP allowlists and publish/subscribe scopes per credential
  • Console: CSRF protection, exact-origin CORS, role-based access, tenant isolation, audit log
  • Transport: HTTPS/TLS everywhere; TURN over TLS for restrictive networks

What you should do

  • Keep App Secrets in your server's secret store, never in apps or repositories
  • Issue the smallest role and stream set each user needs
  • Rotate credentials if you suspect exposure, and revoke grants for removed users

Source references

  • apps/local-site/lib/product-status.ts
Was this page helpful?