Docs
REST API v1

Issue a participant token

Issue a short-lived bearer token for one participant in a room.

POST/v1/rooms/{roomId}/tokens

Requirements

A secret API key with tokens:create. Resources are restricted to the key's project and environment.

Path parameters

NameTypeRequired / defaultDescription
roomIdstringRequiredID of a room in the key's environment.

Request body

NameTypeRequired / defaultDescription
participantNamestringRequiredTrimmed name, 1–120 characters.
permissionsstring[]['room:join']Unique permissions. Must include room:join.
metadataJSON object{}Initial participant metadata.
ttlSecondsinteger600From 60 to 3,600 seconds.

Example

Set RELAYRTC_API_URL to your API base including /v1, such as http://localhost:8082/v1.

Shell
curl -X POST "$RELAYRTC_API_URL/rooms/room_example/tokens" \
  -H "Authorization: Bearer $RELAYRTC_SECRET_KEY" \
  -H "Content-Type: application/json" \
  -d '{"participantName":"Alice","permissions":["room:join","audio:publish","video:publish"],"ttlSeconds":3600}'

Response

201 with token, participantId, tokenId and expiresAt. The example token is a placeholder.

JSON
{
  "token": "participant-jwt",
  "participantId": "participant_example",
  "tokenId": "token_example",
  "expiresAt": "2026-01-01T13:00:00.000Z"
}

Notes

Permissions are room:join, audio:publish, video:publish, screen:publish, messages:send and metadata:update.

Every call creates a new participant identity. This is not an identity-preserving renewal endpoint. Authenticate your own user and check room access before issuing a token.

Errors

Invalid fields return 400. Invalid credentials return 401; a missing scope returns 403. A missing resource returns 404. See error responses.