Docs
REST API v1

Issue TURN credentials

Create temporary STUN/TURN ICE server credentials.

POST/v1/turn/credentials

Requirements

A secret API key with tokens:create. Resources are restricted to the key's project and environment.

Request body

NameTypeRequired / defaultDescription
roomIdstringOptional with sessionIdRoom of the active session.
sessionIdstringOptional with roomIdActive participant session.

Example

Set RELAYRTC_API_URL to your API base including /v1, such as http://localhost:8082/v1.

Shell
curl -X POST "$RELAYRTC_API_URL/turn/credentials" \
  -H "Authorization: Bearer $RELAYRTC_SECRET_KEY" \
  -H "Content-Type: application/json" \
  -d '{"roomId":"room_example","sessionId":"session_example"}'

Response

201 with TURN credentials. URLs, username, lifetime and password depend on the deployment.

JSON
{
  "expiresAt": "2026-01-01T12:10:00.000Z",
  "username": "issued-turn-username",
  "ttlSeconds": 600,
  "iceServers": [
    {
      "urls": [
        "stun:turn.your-domain.example:3478"
      ]
    },
    {
      "urls": [
        "turn:turn.your-domain.example:3478?transport=udp"
      ],
      "username": "issued-turn-username",
      "credential": "issued-turn-password",
      "credentialType": "password"
    }
  ]
}

Notes

Supply both IDs for session-bound credentials or send {} for environment-scoped credentials. A browser joining through the SDK receives initial TURN credentials from signaling. Keep the secret API key on the backend when renewing them.

Errors

Invalid fields return 400. Invalid credentials return 401; a missing scope returns 403. A missing resource returns 404. See error responses.