Identity & Avenues
Choose capability access or authenticated identity for each OpenRTC avenue
OpenRTC makes identity and live topology explicit. A client starts no global discovery mode; each capability handle activates one avenue.
| Use case | API | Identity | Persistence |
|---|---|---|---|
| User-owned device mesh | devices.start() | Authenticated | Durable device roster |
| Shared cursor or lightweight presence | spaces.join() | Session capability | Live only |
| Match, call, document, or group | rooms.join() | Capability or authenticated | Ephemeral by default |
| Explicit handoff session | tickets.issue() | Device-bound capability | Live and bounded |
Authenticated devices
const devices = await rtc.devices.start({
auth,
autoConnect: 'online',
});
const stop = devices.watch((event) => renderDevice(event));
Known devices may remain in the durable roster while offline, but autoConnect: 'online' never dials a persisted offline device merely because it exists.
Capability space
const cursors = await rtc.spaces.join('portfolio-cursors', {
access: 'capability',
identity: 'session',
payload: 'latest-state',
});
This path needs no product account or consumer backend. It still uses a device-bound proof and bounded grant, and it creates no Firebase Auth principal.
Room
const match = await rtc.rooms.join('match-123', {
access: 'capability',
membership: 'ephemeral',
identity: 'session',
payload: 'latest-state',
});
Use identity: 'session' for an anonymous room where each tab or client run
must appear as a different peer. The signing key lives only for that client
run; it is not copied into local storage or the installed device-key database.
It is available only with capability access. payload: 'latest-state' lets
OpenRTC replace older queued state and use the bounded sparse room path when
the room grows beyond a small mesh.
Use access: 'authenticated' when membership must be associated with your
product identity. Use membership: 'durable' only when the product truly needs
membership to survive the live session.
Identity refresh
The auth provider notifies OpenRTC only when the consumer identity epoch
changes: login, logout, account switch, explicit revocation, or equivalent
product state. Do not forward ordinary Firebase ID-token or OAuth access-token
refresh notifications through subscribe. A refreshed assertion for the same
app-scoped principal updates the grant in place; it does not reopen a healthy
socket or rewrite presence. A real principal or avenue change retires the old
scope.
For the lifecycle, defaults, and TypeScript/Rust samples for all four paths, see Avenues.
Attestation
Attestation is optional unless the app manifest requires it. It strengthens device enrollment; it is not a liveness signal and must never run as a recurring connection timer.
Reusable Firebase App Check and Apple DeviceCheck tokens are app-session evidence. Apple App Attest and Play Integrity can bind their evidence to the exact OpenRTC enrollment challenge. In every case, OpenRTC independently requires a nonce-bound signature from the install's device key and derives the authoritative evidence strength from the server-side provider registration.