brave-author-62043
07/25/2025, 12:09 PMtall-airline-16756
07/25/2025, 12:09 PMtall-airline-16756
07/25/2025, 12:10 PMBearer {your_generated_token}.
Here’s how you can generate the token:
• API Credentials: You need your LiveKit API key and secret to sign the tokens.
• SIP-Specific Grants: SIP tokens require specific grants that differ from regular video tokens. These grants include participant identity, name, and other metadata as needed.
• Token Validity: SIP tokens are typically set to be valid for 24 hours.
Below are examples of how to generate SIP tokens in different programming languages:
• Go:
func BuildSIPToken(params SIPTokenParams) (string, error) {
t := true
at := auth.NewAccessToken(params.APIKey, params.APISecret).
SetVideoGrant(&auth.VideoGrant{
RoomJoin: true,
Room: params.RoomName,
CanSubscribe: &t,
CanPublish: &t,
CanPublishData: &t,
CanUpdateOwnMetadata: &t,
}).
SetIdentity(params.ParticipantIdentity).
SetName(params.ParticipantName).
SetMetadata(params.ParticipantMetadata).
SetValidFor(24 * time.Hour)
return at.ToJWT()
}
• Python:
def _auth_header(self, grants: VideoGrants | None, sip: SIPGrants | None = None) -> dict[str, str]:
tok = AccessToken(self.api_key, self.api_secret)
if grants:
tok.with_grants(grants)
if sip is not None:
tok.with_sip_grants(sip)
token = tok.to_jwt()
headers = {}
headers[AUTHORIZATION] = "Bearer {}".format(token)
return headers
• Ruby:
def auth_header(video_grant: nil, sip_grant: nil)
headers = {}
t = ::LiveKit::AccessToken.new(api_key: @api_key, api_secret: @api_secret)
if video_grant != nil
t.video_grant = video_grant
end
if sip_grant != nil
t.sip_grant = sip_grant
end
headers["Authorization"] = "Bearer #{t.to_jwt}"
headers
end
• Rust: Sources: sip/token.go | livekit-api/livekit/api/_service.py | lib/livekit/auth_mixin.rb | livekit-api/src/services/mod.rs | pkg/auth/auth.go