Skip to main content
A client needs a token to join a channel. This token can only be issued by your backend; it can’t be generated on the client. This page explains the whole flow.

AppID and AppKey

After you create an app, you get a pair of credentials with completely different responsibilities:
A leaked AppKey means your app is taken over. Anyone who gets it can issue tokens for any user identity, remove users, and destroy channels.It must not appear in client code, frontend config files, mobile app packages, Git repositories, or logs. It may only exist on your own server.

Issuance flow

The key is step 2: SRTC doesn’t manage your user system. Who is allowed into this channel and what identity they have once inside are entirely decided by your backend. SRTC only trusts the issued token. For endpoint details, see Server API · Get a channel join token; for the signing algorithm, see Server API overview.
If you don’t want to set up a backend while debugging, you can generate a temporary token directly in the developer console to get the client flow working. Temporary tokens are for debugging only; production must issue tokens from your backend.

Choosing the uid

The uid signed into the token is this user’s identity in the channel. Think through two rules first:
  • One uid can join multiple different channels at the same time
  • When the same uid joins the same channel, the later join replaces the earlier one
So:
If what you need is meeting semantics such as “one user attending from multiple devices at once”, SMeeting has a built-in mechanism that distinguishes identities by device type, so you don’t have to build uids yourself. See Choosing SRTC or SMeeting.

Validity and invalidation

A token is bound to one session and can’t be reused after it has been used: For the full list of error codes, see Server API · Error codes.
Issue a separate token for each client instance. If you start two processes with the same token, the second one gets 1032. When testing interoperability across devices, each one gets its own token.