Server SDK · PHP & Laravel

PHP SDK

PHP 8.1+ with JSON, hash and HTTP streams enabled (allow_url_fopen). No external runtime dependencies.

Install from GitHub

The SDK source is public on the main branch. These instructions use Git or a locally built package; package registry releases are a separate step.

Installation
composer config repositories.pubb vcs https://github.com/pubbio/sdk-php
composer require pubb/sdk:dev-main

Run these commands in your application and commit composer.lock to pin the resolved revision.

Publish an event

Set PUBB_APP_ID, PUBB_APP_KEY and PUBB_APP_SECRET in your server environment, then publish after checking the caller's permissions.

publish.php
<?php
require 'vendor/autoload.php';

$pubb = new Pubb\PubbServer(
    appId: getenv('PUBB_APP_ID'), appKey: getenv('PUBB_APP_KEY'),
    appSecret: getenv('PUBB_APP_SECRET'),
);
$result = $pubb->trigger('notifications', 'message.sent', ['message' => 'Hello from Pubb!']);
echo $result->publicationId;

trigger accepts optional socketId and idempotencyKey named arguments. Calls are synchronous. ApiException exposes status and retryAfter; ProtocolException indicates an invalid acceptance response. The configurable timeout applies to stream operations.

HTTP 202 confirms acceptance for processing, not delivery. The response includes publicationId and duplicate. SDKs do not automatically retry publications; reuse an idempotency key when retrying the same event. The API accepts 1–100 channels and up to 10 KiB of UTF-8 JSON data.

Private and presence channels

Use authorizeChannel($socketId, $channel) or authorizePresenceChannel($socketId, $channel, $verifiedUserId, $userInfo) in an authenticated backend route after checking channel permissions; return the array as JSON.

Your backend receives socket_id and channel_name, checks the authenticated user’s access, and returns auth plus channel_data for presence. Derive the presence user ID from the session and forward the signed channel_data unchanged.

Keep the app secret on your trusted server. Public channels must not carry personal or restricted data. Read the channel access reference for the protocol.

Verify your integration

  1. Subscribe to notifications in your app or the dashboard’s Live console.
  2. Publish message.sent to the same application and channel from your backend.
  3. Check the event payload, connection cleanup and recovery after a disconnect. Test denied access as well as successful private subscriptions.

The repositories include automated tests and examples. Verify end-to-end delivery with your own application before sending production traffic. Refetch durable state after reconnecting; missed events are not replayed.

Legacy pusher:* and pusher_internal:* control names are retained where required by the protocol. Their presence alone does not imply drop-in compatibility with every Pusher client or server.