Server SDK · C# & ASP.NET Core

.NET SDK

.NET 8+. The Pubb.Server library has no additional runtime dependencies.

Install from GitHub

The SDK source is public on the main branch. These instructions use Git or a locally built package; package registry releases are a separate step.

Installation
git clone --branch main https://github.com/pubbio/sdk-dotnet.git
cd sdk-dotnet
dotnet pack src/Pubb.Server -c Release -o artifacts
dotnet add /path/to/your/project package Pubb.Server --version 0.2.0 --source /absolute/path/to/sdk-dotnet/artifacts

A project reference to src/Pubb.Server/Pubb.Server.csproj is also supported. Add the package to your trusted backend, including the server project of a Blazor application.

Publish an event

Set PUBB_APP_ID, PUBB_APP_KEY and PUBB_APP_SECRET in your server environment, then publish after checking the caller's permissions.

Publish.cs
using Pubb.Server;

using var pubb = new PubbServer(new()
{
    AppId = Environment.GetEnvironmentVariable("PUBB_APP_ID")!,
    Key = Environment.GetEnvironmentVariable("PUBB_APP_KEY")!,
    Secret = Environment.GetEnvironmentVariable("PUBB_APP_SECRET")!,
});
var result = await pubb.TriggerAsync("notifications", "message.sent",
    new { message = "Hello from Pubb!" });
Console.WriteLine(result.PublicationId);

TriggerOptions supports SocketId and IdempotencyKey; requests accept a CancellationToken. Dispose the SDK when its owner ends. A supplied HttpClient remains caller-owned and should have redirects disabled.

HTTP 202 confirms acceptance for processing, not delivery. The response includes publicationId and duplicate. SDKs do not automatically retry publications; reuse an idempotency key when retrying the same event. The API accepts 1–100 channels and up to 10 KiB of UTF-8 JSON data.

Private and presence channels

After authenticating the user and checking access, return AuthenticatePrivateChannel(socketId, channelName) or AuthenticatePresenceChannel(socketId, channelName, verifiedUserId, userInfo). Request DTOs should map socket_id and channel_name explicitly; the authorization response uses auth and channel_data.

Your backend receives socket_id and channel_name, checks the authenticated user’s access, and returns auth plus channel_data for presence. Derive the presence user ID from the session and forward the signed channel_data unchanged.

Keep the app secret on your trusted server. Public channels must not carry personal or restricted data. Read the channel access reference for the protocol.

Verify your integration

  1. Subscribe to notifications in your app or the dashboard’s Live console.
  2. Publish message.sent to the same application and channel from your backend.
  3. Check the event payload, connection cleanup and recovery after a disconnect. Test denied access as well as successful private subscriptions.

The repositories include automated tests and examples. Verify end-to-end delivery with your own application before sending production traffic. Refetch durable state after reconnecting; missed events are not replayed.

Legacy pusher:* and pusher_internal:* control names are retained where required by the protocol. Their presence alone does not imply drop-in compatibility with every Pusher client or server.