Authentication & security

App secret

An app secret is a confidential server credential that authorizes privileged operations for an application, such as publishing events and signing restricted subscriptions.

Also found under: Server credential, Bearer token

How it works

A secret must stay in trusted server configuration, outside browser bundles and distributed mobile apps. Public environment variable prefixes do not protect values. Validate the user's requested action in your backend before using the secret on their behalf, and replace credentials that have been exposed.

In a Pubb integration

Pubb server SDKs use the app secret, and HTTP publishing and authorization requests send it as a Bearer credential. Client subscriptions use the public app key and receive only the signed authorization result when needed.

Set up application credentials

A practical example

An authenticated backend route checks that the user may send a chat message, then uses PUBB_APP_SECRET to publish the approved event.