Identity & Avenues

Choose capability access or authenticated identity for each OpenRTC avenue

OpenRTC makes identity and live topology explicit. A client starts no global discovery mode; each capability handle activates one avenue.

Use caseAPIIdentityPersistence
User-owned device meshdevices.start()AuthenticatedDurable device roster
Shared cursor or lightweight presencespaces.join()Session capabilityLive only
Match, call, document, or grouprooms.join()Capability or authenticatedEphemeral by default
Explicit handoff sessiontickets.issue()Device-bound capabilityLive and bounded

Authenticated devices

const devices = await rtc.devices.start({
  auth,
  autoConnect: 'online',
});

const stop = devices.watch((event) => renderDevice(event));

Known devices may remain in the durable roster while offline, but autoConnect: 'online' never dials a persisted offline device merely because it exists.

Capability space

const cursors = await rtc.spaces.join('portfolio-cursors', {
  access: 'capability',
  identity: 'session',
  payload: 'latest-state',
});

This path needs no product account or consumer backend. It still uses a device-bound proof and bounded grant, and it creates no Firebase Auth principal.

Room

const match = await rtc.rooms.join('match-123', {
  access: 'capability',
  membership: 'ephemeral',
  identity: 'session',
  payload: 'latest-state',
});

Use identity: 'session' for an anonymous room where each tab or client run must appear as a different peer. The signing key lives only for that client run; it is not copied into local storage or the installed device-key database. It is available only with capability access. payload: 'latest-state' lets OpenRTC replace older queued state and use the bounded sparse room path when the room grows beyond a small mesh. Use access: 'authenticated' when membership must be associated with your product identity. Use membership: 'durable' only when the product truly needs membership to survive the live session.

Identity refresh

The auth provider notifies OpenRTC only when the consumer identity epoch changes: login, logout, account switch, explicit revocation, or equivalent product state. Do not forward ordinary Firebase ID-token or OAuth access-token refresh notifications through subscribe. A refreshed assertion for the same app-scoped principal updates the grant in place; it does not reopen a healthy socket or rewrite presence. A real principal or avenue change retires the old scope.

For the lifecycle, defaults, and TypeScript/Rust samples for all four paths, see Avenues.

Attestation

Attestation is optional unless the app manifest requires it. It strengthens device enrollment; it is not a liveness signal and must never run as a recurring connection timer.

Reusable Firebase App Check and Apple DeviceCheck tokens are app-session evidence. Apple App Attest and Play Integrity can bind their evidence to the exact OpenRTC enrollment challenge. In every case, OpenRTC independently requires a nonce-bound signature from the install's device key and derives the authoritative evidence strength from the server-side provider registration.