What you’ll accomplish
You will understand the WebSocket data path, create a small Node.js relay, emit validRuntimeDataEnvelope v1 snapshots, test locally, and prepare a production wss:// endpoint.
Who must provide the WebSocket server?
Layarva Player is a WebSocket client. It connects to an endpoint and listens; it does not create the server that publishes your data. For the current Secure WebSocket mode, the customer or integration partner normally provides the relay. You can:- host a small relay on your own server or container platform;
- use a managed service that supports WebSocket broadcasting; or
- connect directly to an existing provider only when its endpoint already satisfies the Layarva message and security requirements.
How it works
sourceId does not exactly match the Widget ID. When the connection closes, it reconnects with exponential backoff up to five minutes.
Prerequisites
- Node.js 20 or later for this example.
- A host that supports long-lived WebSocket connections.
- A DNS name and valid TLS certificate for production.
- The Unique Widget ID and workspace ID.
- Data that can be transformed into the selected Widget’s semantic schema.
Create the relay
Create a new server project outside browser code:server.mjs:
buildWidgetData() with a database query, event subscription, or provider call.
Run locally
macOS or Linux:ws://localhost address only for local testing. Do not publish a Design with a localhost endpoint; a remote Player would interpret localhost as the Player device itself.
Understand RuntimeDataEnvelope v1
Use this ordering:
{ "envelope": { ... } }.
Deploy with TLS
Production Studio configuration acceptswss://. Deploy the Node process behind a TLS-terminating load balancer or reverse proxy that supports WebSocket upgrades.
Example reverse-proxy requirements:
- the TLS certificate is valid for the hostname;
- the endpoint is reachable from every Player network;
- idle connections are not closed too aggressively by the proxy;
- the service restarts automatically after a crash or host restart;
- the relay can handle one connection per online Player using that Widget source.
Configure Studio
- Select the Widget in Studio.
- Open Properties → Data Source.
- Select Secure WebSocket.
- Enter
wss://stream.example.com/widgets/<WIDGET_ID>. - Set Reconnect to five seconds initially.
- Keep valid Static JSON as a fallback.
- Save and publish the Design.
Security model and current limitation
TLS protects data in transit, butwss:// alone does not decide which client may subscribe.
The current Studio WebSocket configuration does not provide arbitrary authentication headers, cookies, or a configurable subprotocol. Therefore:
- never put API keys, passwords, or long-lived bearer tokens in the URL;
- keep provider credentials inside the relay, not in Studio or the Player;
- expose only display-safe data;
- use network allowlisting, private connectivity, or a gateway appropriate to your deployment when access must be restricted;
- do not use the current direct WebSocket mode for sensitive data on an unauthenticated public endpoint.
Reconnect and Last Known Good
- The Player connects using the configured initial reconnect delay.
- A valid message becomes the current snapshot and is persisted as Last Known Good.
- A malformed message is rejected without replacing the valid snapshot.
- On close, retries back off exponentially up to 300 seconds.
- After
expiresAt, data is treated as stale. - After
staleAtor the Player’s maximum stale policy, the snapshot is no longer eligible. - Static JSON remains the final safe fallback.
Production validation
-
wss://is used with a valid certificate. - The endpoint is reachable from the actual Player network.
- A snapshot is sent immediately after connection.
- Every message is less than 1 MiB.
-
sourceIdexactly matches the Widget ID. -
sequenceincreases andcontentHashis recomputed fromdata. - Timestamps are parseable and ordered correctly.
-
datapasses the selected Widget schema after declarative mapping. - Relay restart and Player reconnect have been tested.
- Last Known Good and Static JSON fallback have been observed during an outage.
- Capacity testing accounts for every connected Player.

