Authentication & security

Authentication

Authentication establishes who a requester is, usually by verifying a session, token or other credential before treating the requester as a particular user or service.

Also found under: User identity, Sign-in

How it works

Identity verification does not answer every permission question. A signed-in user may still be unable to read another team's messages. Realtime applications typically authenticate the user through their existing backend, then evaluate access separately for each protected resource or channel.

In a Pubb integration

Your application remains responsible for authenticating its users before authorizing Pubb private and presence subscriptions. The public app key identifies the Pubb application, not the human using it.

Understand channel access

A practical example

A channel auth route validates the session cookie to identify user 42. It then checks whether that user belongs to the project named in the requested channel.