Docs
Get started

Keys and permissions

Keep management credentials on the server and grant only the permissions a call needs.

API keys

Secret API keys authorize REST administration. Their project and environment define the resource scope. A publishable key cannot create rooms, issue tokens or administer participants.

The Node SDK accepts secret keys only. Its key format starts with rk_sk_.

Participant permissions

PermissionAllows
room:joinJoin the room. Required in every token.
audio:publishPublish microphone audio.
video:publishPublish camera video.
screen:publishPublish screen video and screen audio.
messages:sendSend text messages and custom events.
metadata:updateUpdate participant metadata.

The token endpoint defaults to ['room:join']. Grant media permissions explicitly.

Your token endpoint

Authenticate the caller with your own user session. Check their right to join the requested room. Derive their name and permissions on the server.

Do not expose an unrestricted token endpoint

A public endpoint that signs arbitrary room IDs, names or permissions lets callers impersonate users and access calls. A participant token is a bearer credential.

Webhooks

Verify the original request body before parsing JSON. Reject old signatures and store event IDs atomically with your processing result to avoid duplicate work.

Use verifyWebhookRequest. Keep the endpoint signing secret on your backend.

Camera access

Use HTTPS in production. Provide clear controls for camera, microphone and screen sharing. To turn a camera off completely, call camera.disable(). Local mute pauses sending but does not release the device.

Logs and errors

Log request IDs and error codes. Keep tokens, API keys and webhook signing secrets out of logs.