For Agents
The shortest safe contract for agents building OpenRTC applications
Non-negotiable rules
- Import
OpenRTCfromopenrtcand pass only the app's public API key for a prototype. - Treat construction as lazy; activate exactly one required avenue through
devices,spaces,rooms, ortickets. - Retain the returned handle and call
close()orleave()during teardown. - Do not configure OpenRTC platform Firebase, database, storage, app tags, or gateway endpoints in a consumer app.
- Do not add application heartbeats, reconnect timers, presence repair, or parallel peer registries.
- Use
latest-statefor replaceable cursor/transform data and reliable channels for chat, control, and acknowledgements. - Put game semantics in
openrtc-netcode, transfer semantics inopenrtc-file-transfer, and Yjs on an activated room throughy-openrtc. - Import
openrtc/runtimeonly for a low-level adapter or specialized protocol integration.
Prototype
const rtc = OpenRTC({ apiKey });
const space = await rtc.spaces.join('demo', {
access: 'capability',
identity: 'session',
payload: 'latest-state',
});
Authenticated devices
const auth: AuthProvider = {
getAssertion: ({ forceRefresh }) => backend.assertion({ forceRefresh }),
subscribe: (listener) => identity.subscribe(listener),
};
const devices = await rtc.devices.start({ auth, autoConnect: 'online' });
The application owns login and authorization. OpenRTC owns assertion validation, app-scoped principal derivation, device binding, grants, revocation, budgets, live coordination, and metering.
Expensive features
Relay, durable membership, managed attestation, MoQ, and BLE require portal
enablement and explicit runtime opt-in. Rooms default to one room-wide auto
policy: mesh through eight and eligible sparse latest-state fan-out through 50.
Never add a client-side topology chooser. Managed and authority modes must fail
closed until their security, capacity, pricing, and service-registration gates
pass.