Authentication & security

TLS

Transport Layer Security, or TLS, protects network traffic with encryption and integrity checks and supports authenticating the server through a certificate.

Also found under: Transport Layer Security, HTTPS

How it works

HTTPS and WSS use TLS to protect their transport connections. TLS does not replace application permissions and is not automatically end-to-end encryption between users: infrastructure terminating TLS can process the application data. Keep secrets out of payloads even when the network connection is encrypted.

In a Pubb integration

Pubb's hosted HTTP API uses HTTPS and its socket endpoint uses WSS. Applications still need backend authorization before publishing or joining restricted channels.

Set up application credentials

A practical example

Your backend sends the app secret in an HTTPS Authorization header. Browser clients use WSS with the public app key and receive only data their subscriptions permit.