Issue RTC tokens
Your server exchanges its App ID and App Secret for short-lived media credentials for one user in one room.
Overview
An app cannot reach the media server on its own. Your server decides who may join which room and in which role, asks the platform for a token for exactly that, and hands the result to the app. The token is valid for minutes and only for that user, room and set of streams.
The App Secret never leaves your server. The app receives a media grant and a media key; the SDK uses them to authenticate to the media server and to encrypt audio and video.
Steps
- Create a project and a credential in the console. Store the App ID and App Secret in your server's secret store.
- When one of your signed-in users opens a room, check on your server that this user may do so, and in which role.
- Call POST /v1/rtc/tokens with HTTP Basic authentication (App ID as user name, App Secret as password).
- Return media.grant, media.key, media.sfu_host and media.sfu_port to the app over your own authenticated HTTPS API.
- The app passes them to the SDK. The SDK asks your server again shortly before the token expires.
Request a token
Server-side only. A request that carries a browser Origin header is refused.
Keep the App Secret in an environment variable or secret store.
curl -sS https://api.fahswertc.com/v1/rtc/tokens \
-u "$FAHSWE_APP_ID:$FAHSWE_APP_SECRET" \
-H "Content-Type: application/json" \
-d '{
"room_id": "live-42",
"user_id": "u-1001",
"role": "host",
"publish_streams": [1, 2],
"subscribe_room": true,
"ttl_seconds": 600
}'What comes back
- media.grant: what the SDK presents to the media server. Not secret by itself.
- media.key: secret. It proves the grant is yours. Send it to the app over HTTPS only; never log it.
- media.revocation_handle: keep it on your server if you may need to cut this user off before the token expires.
{
"project_id": "prj_...",
"app_id": "app_...",
"room_id": "live-42",
"user_id": "u-1001",
"role": "host",
"publish_streams": [1, 2],
"subscribe_streams": [],
"subscribe_room": true,
"issued_at": 1791500000,
"expires_at": 1791500600,
"media": {
"grant": "<base64url>",
"key": "<base64url, secret>",
"sfu_host": "sfu.fahswertc.com",
"sfu_port": 5004,
"encryption": "aes-256-gcm",
"revocation_handle": "<opaque>"
}
}Rules
- The project is taken from your credential. A token can never reach a room of another project, even with the same room id.
- Publishing is granted per stream id. The audience role can never publish.
- subscribe_room lets the user receive every stream of the room; use subscribe_streams to limit it to a list.
- ttl_seconds is at most 3600 and at most the limit set on the credential. The default is 600.
- room_id and user_id: 1 to 128 printable ASCII characters without spaces. Use opaque ids, not names or e-mail addresses.
Source references
developer-platform/internal/httpserver/rtc_tokens.godeveloper-platform/internal/httpserver/rtc_tokens_test.gotoken-service/internal/e2e
Was this page helpful?