Streaming API key and tokens

Configuring the Eagle 3D Streaming Web SDK needs a Streaming API key — it is the first line of sdk-config.js. This is what it is, where to get one, and what it produces.

API keyStreaming API key
Can delete or replace your appYesNo
Use in a web integrationNo — support is being withdrawnYes
Used bythe Control Panel APIs — analytics, apps and versions, health check, billingstreaming, and nothing else

The account API key is powerful enough to delete your application, which is exactly why it must never reach a browser. The Streaming API key exists because that one is too dangerous for the job. See API keys and tokens for the account key, generating one, and version control.

Where to get one

  1. Open the Control Panel.
  2. Go to the Developer section.
  3. Open the Streaming API Key tab and copy the key there — not the one on the API Key tab. (Developer Section is shown to the account owner only.)

Then put it in scripts/sdk-config.js:

const STREAMING_API_KEY = "Your Streaming API Key";

What it actually does: it makes tokens

The key never starts a session by itself. It authorises a request for a token, and the token is what starts one.

Streaming API keySession token
LifetimeDoes not expireExpires in the time you set — a minute is plenty
ReusableYes, indefinitelyNo — single use
Safe in a browserNoYes, and that is the point

That difference is the whole design. A leaked token expires harmlessly; a leaked key does not. It is also why restarting a stream needs a fresh token — the previous one is already spent.

Why this is the reason to choose the SDK

With a streaming URL or an iframe, the link itself grants access. You can put a password in front of it, but you cannot revoke it for one person, and the URL inside your page is a working link to anyone who reads the source.

With the Web SDK, your backend decides who gets a token, when, and for which application. That is a different kind of control, and it is the one thing the other two methods cannot be configured into doing. Deciding who is then your own authentication — putting a login in front of a stream.

Last updated