Android: media credentials
Give the Android SDK the grant from your server and let it renew by itself.
Overview
From SDK 1.5.0 a session takes a credentials provider: a function that asks your backend for a fresh media grant. The SDK calls it when it needs one, so your app does not track expiry.
Code
- Available on FsLivestreamSession, FsVoiceSession and FsPkSession.
- The provider may block on the network. If it throws or returns null, the SDK retries with a growing delay (1 to 15 seconds).
- Set a new provider when the user's role changes (for example audience to speaker): the SDK drops the old grant and fetches a new one at once.
// 1. Tell the session how to get media credentials from YOUR backend.
session.setMediaCredentialsProvider(() -> {
// Runs on a background thread. Ask your own server; it calls the token API.
MyBackend.RtcToken t = myBackend.fetchRtcToken(roomId); // your HTTPS call
return FsMediaCredentials.fromBase64Url(t.grant, t.key);
});
// 2. Start as usual, with the media endpoint your backend returned.
session.startAsHost(sfuHost, sfuPort, videoStreamId, audioStreamId);
// The SDK fetches the first grant, renews it before it expires, and asks again
// after a refusal or revocation. Until a grant is accepted, nothing is sent.
String state = session.mediaAuthState(); // WAITING_FOR_CREDENTIALS, HANDSHAKING, READY ...Behaviour
- With a provider set, the session is encrypted-only: before the first grant is accepted nothing leaves the device.
- Renewal starts a quarter of the lifetime before expiry (at least 5 seconds, at most a minute), measured on the device's monotonic clock, so a wrong date setting does not matter.
- Renewal does not interrupt media: the old keys stay in use until the new session is confirmed.
- After a revocation the SDK asks the provider again; whether the user gets a new grant is your server's decision.
- diagnostics().mediaEncryption reads aes-256-gcm+ecdh-p256 when media is encrypted.
Status
1.5.0-rc1 is a release candidate. Its transport passes the automated suite, including a live chain of token API, token service and media server. It has not yet been verified on physical devices; audio and video quality results from earlier releases do not carry over until that is done.
Source references
sdk/android/fahswe-rtc/src/main/java/com/fahswe/rtc/FsMediaCredentialsProvider.javasdk/android/fahswe-rtc/src/test/java/com/fahswe/rtc/media/SecureMediaEndToEndTest.java
Was this page helpful?