Configuring the Eagle 3D Streaming Web SDK needs a Streaming API key — it is the
first line of sdk-config.js. This is what it is, where to get
one, and what it produces.
| API key | Streaming API key | |
|---|---|---|
| Can delete or replace your app | Yes | No |
| Use in a web integration | No — support is being withdrawn | Yes |
| Used by | the Control Panel APIs — analytics, apps and versions, health check, billing | streaming, and nothing else |
The account API key is powerful enough to delete your application, which is exactly why it must never reach a browser. The Streaming API key exists because that one is too dangerous for the job. See API keys and tokens for the account key, generating one, and version control.
Then put it in scripts/sdk-config.js:
const STREAMING_API_KEY = "Your Streaming API Key";
The key never starts a session by itself. It authorises a request for a token, and the token is what starts one.
| Streaming API key | Session token | |
|---|---|---|
| Lifetime | Does not expire | Expires in the time you set — a minute is plenty |
| Reusable | Yes, indefinitely | No — single use |
| Safe in a browser | No | Yes, and that is the point |
That difference is the whole design. A leaked token expires harmlessly; a leaked key does not. It is also why restarting a stream needs a fresh token — the previous one is already spent.
With a streaming URL or an iframe, the link itself grants access. You can put a password in front of it, but you cannot revoke it for one person, and the URL inside your page is a working link to anyone who reads the source.
With the Web SDK, your backend decides who gets a token, when, and for which application. That is a different kind of control, and it is the one thing the other two methods cannot be configured into doing. Deciding who is then your own authentication — putting a login in front of a stream.
Last updated