Browse documentation

Authentication

The handshake is authenticated with an API key created in your dashboard; the key is shown once at creation. The WebSocket itself is authenticated with the short-lived token the handshake returns, never with the key.

CredentialKindUsed for
lk_live_…API keySent as a Bearer header on POST /v1/realtime/connect. Created in the dashboard and shown once.
tokenShort-livedReturned by connect. Opens exactly one WebSocket, then is spent. Never send the API key over the socket.

Revoking a key takes effect immediately, including on streams that are already running.

expiresAt is a deadline for opening the connection, not a limit on how long it may stay open. A stream ends after 4 hours, or after 60 seconds with no audio. session.ping does not reset that idle timer.

Key expiry and Playground

Create a named key with a validity of 1, 7, 30, 180, or 365 days, or no expiry. Existing keys have no expiry. At key expiry, new connections and reserved tickets are rejected and online streams stop; accepted audio is settled normally. Key validity is separate from the short-lived connect response expiresAt. Playground uses your signed-in account and charges the same balance without a key. Copied examples call the public API and require your own LECSYNC_API_KEY.