Authentication & security
Channel authorization
Channel authorization is the server-side decision that a particular connection may subscribe to a restricted channel, followed by proof of that decision for the messaging service.
Also found under: Auth endpoint, Subscription signature
How it works
The application receives the requested channel name and socket ID, identifies the requester and checks access to the underlying resource. Only after that check should it issue a signature. The authorization endpoint is part of your application's security boundary and must not trust a client-supplied user ID as proof of identity.
In a Pubb integration
Use a Pubb server SDK or the authenticated authorization API to produce private or presence subscription signatures. Presence also needs a user identity. Return the signature to the client while keeping the app secret server-side.
Understand channel accessA practical example
A project member requests presence-project-42. Your backend checks membership in project 42 before returning a signed response for that socket and channel.