Skip to content

Mint a WebSocket handshake ticket

POST
/api/v1/realtime/ticket
curl --request POST \
--url http://localhost:3000/api/v1/realtime/ticket \
--header 'Authorization: Bearer <token>'

Returns a short-lived, single-use ticket bound to the caller and the resolved organization. Redeem it once as wss://<host>/ws?ticket=<ticket>. A ticket is consumed on redemption, so each connection attempt — including every reconnect — requires a freshly minted ticket.

Ticket minted

Media typeapplication/json
object
ticket
required

Opaque single-use handshake ticket. Pass it as the ticket query parameter on the WebSocket upgrade. It carries no claims and is consumed on first redemption.

string
expiresIn
required

Ticket lifetime in seconds. Redeem it immediately; it is not a session token.

number
Example
{
"ticket": "a3f1c0de9b2447e8a1d6f05c7b3e9821a3f1c0de9b2447e8a1d6f05c7b3e9821",
"expiresIn": 60
}

Unauthorized — invalid or missing authentication

Forbidden — no accessible organization context