06 — Security & best practices

Protect your credentials

  • API key + secret belong on your backend only. Never ship them in a mobile app, web bundle, or public repo — anyone with them can create unlimited calls on your account.
  • Store them in environment variables / a secrets manager, not in source code.
  • Rotate immediately if leaked (ask arzbridge to issue a new pair and revoke the old one).

Mint tokens server-side, per user

  • Always create tokens on your backend after authenticating the user with your own system. Apply your own rules (who can join which room, with what role).
  • Set a sensible ttl — long enough to connect, not forever. The call continues after the token expires; you don't need long-lived tokens.
  • Use a stable, unique identity per user (e.g. your user id). Don't reuse one identity for two simultaneous people in the same room — the later one displaces the earlier.

Use least-privilege grants

  • Give viewers can_publish: false; give broadcasters can_subscribe: false if they shouldn't see others; reserve room_admin: true for moderators only.
  • Don't hand out room_admin to normal participants.

Validate inputs

  • Room names must match ^[A-Za-z0-9][A-Za-z0-9._-]{1,63}$. Generate them from your own ids (e.g. order-{id}) rather than user free-text.
  • Treat metadata/attributes as visible to other participants — don't put secrets there.

Handle limits & failures gracefully

  • Respect 429 + Retry-After; back off rather than hammering.
  • Retry only 5xx/429 (transient). Never auto-retry 401/403/422.
  • Show users a friendly "reconnecting…" state; the client SDK auto-reconnects on brief network drops.

Privacy & compliance

  • You control recording. If you enable it, tell your users and store recordings in your own private storage.
  • Tokens are bearer credentials — deliver them to your app over HTTPS only, and don't log them.

Production checklist

  • API key/secret only on the backend, in env/secrets manager
  • Token endpoint behind your own authentication
  • Sensible ttl and least-privilege grants per role
  • Unique identity per user
  • Retry/backoff on 429/5xx
  • HTTPS everywhere; tokens never logged
  • Client SDK kept up to date

Support

Contact arzbridge for: raising rate limits, enabling recording, enabling webhook forwarding to your backend, additional API keys, or any integration help.