> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stmlink.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> 对外开放的服务端接口有两组前缀，都用同一套鉴权：`/server/v1/...`（SRTC 与 SMeeting 的主接口）和 `/stm/srvapi/v1/...`（SMeeting 的用户体系，服务端极简对接会用到）。鉴权是 app_id + nonce + timestamp + signature 四个请求头，用 app_key 做 HMAC-SHA256 签名，只能从业务方自己的后端调用。除这两组前缀外的接口均为内部接口，不要建议客户调用。 Public server APIs use two path prefixes with the same authentication: `/server/v1/...` (the main APIs of both SRTC and SMeeting) and `/stm/srvapi/v1/...` (the SMeeting user system, used by server-side low-code integration). Authenticate with four request headers, app_id + nonce + timestamp + signature, where signature is HMAC-SHA256 keyed with app_key; call these APIs only from the customer's own backend. Any other path is internal: never suggest calling it.
> app_key 是服务端密钥，绝不能出现在客户端代码、前端配置或移动 App 里。客户端加入频道用的 token 必须由业务方后端签发后下发（SRTC 走 `/server/v1/channel/grant`，SMeeting 走 `/stm/srvapi/v1/member/grant`）。 app_key is a server-side secret and must never appear in client code, frontend config, or a mobile app. The token a client uses to join must be issued by the customer's backend and passed down to the client (SRTC: `/server/v1/channel/grant`; SMeeting: `/stm/srvapi/v1/member/grant`).
> SRTC 与 SMeeting 是上下两层不同的产品，术语不通用：SRTC 是音视频底座，说「频道 channel」「加入 / 退出」；SMeeting 建在 SRTC 之上，说「房间 room」「会议 meeting」「进入 / 退出」。回答时按用户所在的层用对应术语，不要把「房间」「会议」安到 SRTC 的接口上，也不要用「频道」「加入 / 离开」描述 SMeeting 的概念（接口标识符原样保留）。 SRTC and SMeeting are two separate layers with different terminology. SRTC is the audio/video foundation: it has channels, and users join and leave a channel. SMeeting is built on top of SRTC: it has rooms and meetings, and members enter and exit a meeting. Answer in the terms of the layer the user is working with: never apply "room" or "meeting" to SRTC APIs, and never describe SMeeting concepts in prose with "channel", "join", or "leave" (API identifiers such as `force_join` keep their literal names).
> 同一能力在各端 SDK 里的包名、类名、方法名并不相同。写示例代码时请使用文档中该端自己的 API，不要把一个端的写法套到另一个端上。苹果平台每个产品都有两套 SDK（Swift 原生与 Objective-C），两套 API 不能混用。 Package, class, and method names differ between platform SDKs for the same capability. In sample code, use the API documented for that platform; never carry one platform's code over to another. On Apple platforms each product ships two SDKs (native Swift and Objective-C) whose APIs must not be mixed.

# Token and authentication

> How SMeeting authentication works: the different roles of AppID and AppKey, how your backend issues the meeting token the client logs in with, what the session covers after login, and a pre-launch secret key security checklist.

A client needs a token to log in to SMeeting. This token **can only be issued by your backend**; it cannot be generated on the client. This page walks through the whole flow.

***

## AppID and AppKey

When you create an app, you get a pair of credentials with completely different purposes:

| Credential | Purpose | Allowed on the client |
| - | - | - |
| **AppID** | Identifies your app | Yes |
| **AppKey** | Secret key for signing server API calls | **Never** |

<Warning>
  **A leaked AppKey means your app is taken over.** Anyone who gets it can grant any user access to any meeting, remove members, and end meetings.

  It must not appear in client code, frontend config files, mobile app packages, Git repositories, or logs. It may only exist on your own server.
</Warning>

***

## Grant flow

```mermaid theme={null}
sequenceDiagram
    participant App as Your app
    participant Backend as Your backend
    participant SMeeting as SMeeting service

    App->>Backend: 1. User logs in to your system
    Note over Backend: 2. Verify the user's identity<br/>(your own business logic)
    Backend->>SMeeting: 3. POST /server/v1/user-auth/grant<br/>with user_id and nickname<br/>signed with AppKey using HMAC-SHA256
    SMeeting-->>Backend: 4. Return the meeting token
    Backend-->>App: 5. Deliver the token
    App->>SMeeting: 6. SDK logs in with the token<br/>then creates / enters a meeting
```

The key is step 2: **SMeeting doesn't manage your user system**. Your backend decides who is a valid user; SMeeting only trusts the issued token and the `user_id` inside it.

Use the user ID from your business system as `user_id`—when the same user enters a meeting from multiple devices at once, SMeeting tells them apart automatically, so you don't need to build a unique value yourself.

For endpoint details, see [Server API · Meeting authorization](/en/meeting/server-api/user-auth); for the signing algorithm, see the [Server API overview](/en/meeting/server-api/overview).

***

## After login

Getting the token is only the first step. The flow in every platform's SDK is:

```text theme={null}
login(token)  →  create / query a meeting  →  enter the meeting
```

Login establishes a **user session**, not a meeting connection. You can call the meeting management APIs only after login succeeds, and the in-meeting APIs only after entering the meeting.

To invalidate a user immediately (for example, when you disable them in your system), call the server's "Log out a user" endpoint. Their session is invalidated at once, and they need a new grant the next time they call an API.

***

## Secret key security checklist

Check the following before going live:

* Is the AppKey stored only in server environment variables or a secret management service?
* Grep your frontend build output for the AppKey to confirm it wasn't bundled in
* Does your token-issuing backend endpoint verify its own login state? Otherwise anyone can exchange someone else's `user_id` for a token
* Do your logs print the AppKey or full tokens?

<Warning>
  The third item is the easiest to miss. If the issuing endpoint doesn't verify the caller's identity, you are exposing the ability to "enter meetings as any user" to the public internet.
</Warning>

***

## Related

* [Key concepts](/en/meeting/key-concepts)—rooms, meetings, members, and roles
* [Server API overview](/en/meeting/server-api/overview)—signing algorithm and request format
