Admit a realtime socket
Issues a ticket that admits one socket connection within one minute, so the bearer credential
never travels in a socket URL. Connect with member_socket_token and subscribe to
MessageChannel. The socket then receives what a member storefront socket for the same
membership receives. The ticket is checked again at connect: a membership that can no longer
act or message is refused. The socket may subscribe to the messaging channels only, and the
membership is checked again before each channel command.
The read-only portal JWT may ask for a ticket: a socket only receives what the credential can already read, and legacy sockets accept a portal JWT. A member session JWT, the kind order and subscription email links carry, may not: legacy sockets refuse it.
curl --request POST \
--url https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"status": 201,
"data": {
"ticket": "eyJfcmFpbHMiOnsiZGF0YSI6eyJtZW1iZXJfaWQiOiJjMGRkNjgxMiJ9fX0--4f1c2b",
"expires_at": "2026-10-01T15:05:05Z",
"url": "wss://websockets.fluid.app/cable",
"channel": "MessageChannel",
"connect_params": {
"member_socket_token": "eyJfcmFpbHMiOnsiZGF0YSI6eyJtZW1iZXJfaWQiOiJjMGRkNjgxMiJ9fX0--4f1c2b"
}
},
"meta": {
"request_uuid": "01a0f4fe-de00-75b3-8d8a-b74b0cde8b07",
"timestamp": "2026-10-01T15:04:05Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}Authorizations
A member credential in the Authorization: Bearer header: a member
session JWT, a portal JWT whose login is linked to a membership in
that company, or a member token. The credential alone
identifies the member and company.
curl --request POST \
--url https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.fluid.app/api/member/v2026-10/messaging/realtime/auth")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"status": 201,
"data": {
"ticket": "eyJfcmFpbHMiOnsiZGF0YSI6eyJtZW1iZXJfaWQiOiJjMGRkNjgxMiJ9fX0--4f1c2b",
"expires_at": "2026-10-01T15:05:05Z",
"url": "wss://websockets.fluid.app/cable",
"channel": "MessageChannel",
"connect_params": {
"member_socket_token": "eyJfcmFpbHMiOnsiZGF0YSI6eyJtZW1iZXJfaWQiOiJjMGRkNjgxMiJ9fX0--4f1c2b"
}
},
"meta": {
"request_uuid": "01a0f4fe-de00-75b3-8d8a-b74b0cde8b07",
"timestamp": "2026-10-01T15:04:05Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}