Realtime API
Client Secrets
Mint a short-lived secret that lets a browser open a realtime session without an API key.
POST
Authorization header on a WebSocket, and an API key shipped to a browser
is an API key anyone can read. A client secret solves both: your server, which holds the API key,
mints a secret that lasts minutes and is tied to one deployment, and the browser connects to
realtime sessions with it.
The request and response have the shape of OpenAI’s client_secrets API, so code written to mint
an OpenAI ephemeral key needs only the gateway URL and your Bud credential.
Headers
Body
Response
The secret is opaque and encrypted. Do not parse it: it carries no project, user or deployment ID
anyone holding it could read, and changing any character makes it invalid.
How long a secret lasts
A secret never outlives the credential that minted it:expires_at is the earlier of the time you
asked for and the parent credential’s expiry. When it is shortened, the response says so through
expires_at rather than failing.
- Minted with a Keycloak access token. The token’s own expiry caps the secret. Keycloak access
tokens usually last about 5 minutes, so a secret minted from one lasts at most that long. A token
with fewer than 10 seconds left is refused with
401 credential_expiring. - Minted with an API key. The secret’s own expiry applies, and the secret stops working as soon as its API key is deleted or expires, whichever comes first.
Using a secret
Open the socket with the secret in the WebSocket subprotocol, andmodel naming the deployment the
secret was minted for:
- the secret is intact and has not expired (otherwise
401); modelnames the deployment it was minted for (otherwise403);- the credential that minted it is still valid and can still use that deployment.
expires_at. A session that is already open keeps
running after the secret expires, but not after its parent credential is revoked: it is closed
with session_revoked within 30 seconds for an API key, or within 30 seconds plus the gateway’s
authorization cache lifetime (5 minutes by default) for a Keycloak token.
Usage from a session opened with a secret is attributed and billed to the project, user and API key
that minted it.