Skip to main content

Core Concepts

The handful of ideas every MediaSFU integration uses, whether you work through an SDK or the HTTP API.

Rooms​

Everything happens inside a room: meetings, calls, webinars, broadcasts, recordings and AI agents. A room has:

  • a room ID (meetingID), used to join, manage and end it;
  • a host (userName on create), unique among your active rooms;
  • a duration, from 5 to 1440 minutes, after which it closes;
  • a capacity, the most people allowed in at once.

Create one with the Rooms API or any SDK's create flow. The response includes the room ID, the host's secureCode, and a publicURL that opens the room in a browser.

Room types​

The eventType decides who can speak and how many people can join.

TypeWho speaksUp to
conferenceEveryone3,000 participants
webinarHost and panel; others watch3,000 participants
broadcastOne-to-many stream500,000 viewers
chatPrivate one-to-one2 participants

Roles​

RoleWhoWhat they can do
HostWhoever created the room (islevel "2" in the SDKs)Everything: admit people, moderate, record, end the room for everyone
Co-hostA participant the host promotes (allow it with meetingRoomParams.addCoHost)The moderation powers the host grants
ParticipantEveryone else (islevel "0")What the room's settings allow: microphone, camera, screen share and chat can each be allowed, need approval, or be disallowed

The host's secureCode proves host rights. Keep it on your server, like an API key.

Keys and credentials​

CredentialWhere it livesUse it for
API username + API keyYour server onlyEvery HTTP call and every room create or join. Find them under API keys.
Disposable keyShort-lived; can be scoped and cappedWidgets and one-off integrations that shouldn't hold your main key. See the disposable keys API.
Room resultThe clientWhat your server returns after it creates or joins a room for a signed-in user. It opens that one room.

Send HTTP calls with Authorization: Bearer <api-username>:<api-key>. In apps, the client asks your backend to create or join a room, and your backend calls MediaSFU with the key. See Keep API keys on your backend.

Sandbox and production​

Your account has separate sandbox and production usage, which the balance API reports. Use sandbox for building and testing. Disposable keys are created for one environment or the other. Production create and join requests must come from a domain on your allowed domains list when they are sent from a web app.

Room lifecycle​

  1. Create: your server creates the room (now, or at a scheduledDate).
  2. Join: each person joins with the room ID; your server can also request a join over HTTP (action: "join").
  3. Leave vs end: a participant leaving affects only them. The host ending the room closes it for everyone.
  4. Close: the room closes when the host ends it or its duration runs out.
  5. After: recordings stay in MediaSFU staging for 72 hours unless you send them to your own storage.

See Leave, end and rejoin for how each SDK handles these moments.

Where to go next​