06 — Security & best practices
Protect your credentials
- API key + secret belong on your backend only. Never ship them in a mobile app, web bundle, or public repo — anyone with them can create unlimited calls on your account.
- Store them in environment variables / a secrets manager, not in source code.
- Rotate immediately if leaked (ask arzbridge to issue a new pair and revoke the old one).
Mint tokens server-side, per user
- Always create tokens on your backend after authenticating the user with your own system. Apply your own rules (who can join which room, with what role).
- Set a sensible
ttl— long enough to connect, not forever. The call continues after the token expires; you don't need long-lived tokens. - Use a stable, unique
identityper user (e.g. your user id). Don't reuse one identity for two simultaneous people in the same room — the later one displaces the earlier.
Use least-privilege grants
- Give viewers
can_publish: false; give broadcasterscan_subscribe: falseif they shouldn't see others; reserveroom_admin: truefor moderators only. - Don't hand out
room_adminto normal participants.
Validate inputs
- Room names must match
^[A-Za-z0-9][A-Za-z0-9._-]{1,63}$. Generate them from your own ids (e.g.order-{id}) rather than user free-text. - Treat
metadata/attributesas visible to other participants — don't put secrets there.
Handle limits & failures gracefully
- Respect
429+Retry-After; back off rather than hammering. - Retry only
5xx/429(transient). Never auto-retry401/403/422. - Show users a friendly "reconnecting…" state; the client SDK auto-reconnects on brief network drops.
Privacy & compliance
- You control recording. If you enable it, tell your users and store recordings in your own private storage.
- Tokens are bearer credentials — deliver them to your app over HTTPS only, and don't log them.
Production checklist
- API key/secret only on the backend, in env/secrets manager
- Token endpoint behind your own authentication
- Sensible
ttland least-privilege grants per role - Unique
identityper user - Retry/backoff on
429/5xx - HTTPS everywhere; tokens never logged
- Client SDK kept up to date
Support
Contact arzbridge for: raising rate limits, enabling recording, enabling webhook forwarding to your backend, additional API keys, or any integration help.