Authentication & security

App key

An app key is the client-facing identifier used to connect to a particular realtime application. In Pubb, it is designed to be included in browser or mobile configuration.

Also found under: Public key, Application key, appKey

How it works

A public application key is not the same as a cryptographic public key, and it is not a user login credential. Anyone who can inspect a distributed client can read it. Sensitive events therefore need restricted channels with a backend access check, regardless of how the key is distributed.

In a Pubb integration

Pubb clients use the app key when connecting to the socket service. It identifies the application but does not grant the server-side publishing authority of an app secret.

Set up application credentials

A practical example

A browser's Pubb configuration includes YOUR_APP_KEY. It can join a public updates channel, but needs a signed authorization response to join private-user-42.