Overview
When your client is on the same network as a Rhombus device, it can pull live video, recorded footage, and audio straight from the device instead of through the Rhombus cloud. You get lower latency and use no internet bandwidth. This guide covers:- How API tokens and federated tokens differ, and which one to use where
- Minting a federated token and finding a device’s LAN URIs
- Authenticating LAN requests with headers or query parameters
- Live H.264 and two-way audio over WebSocket, plus DASH/HLS for live and recorded video
- Browser limitations and troubleshooting
API tokens vs federated tokens
These are two different credentials with different jobs.
A federated token is a bearer credential: anyone holding it can act with its role. For LAN streaming, mint device-scoped tokens with
deviceUUid. A device-scoped token can only fetch that one device’s media, and the cloud API rejects it. Also mint from an API token whose role is no broader than the viewer needs, and keep durationSec short.
The
x-auth-scheme value is exactly federated-token. There is no federated-session-token scheme, and a federated token never goes in x-auth-apikey.Prerequisites
- A Rhombus API key with permission to view the cameras or audio gateways you’ll stream (get one here)
- A client on the same network as the device, able to reach it on TCP port
8000 - A device that can reach the Rhombus cloud. The device checks every new token with Rhombus, so a device without internet access can’t authorize new clients.
Implementation
1
Mint a federated token on your server
Call Example response:
generateFederatedSessionToken with your API key. Your API key never leaves your server.The token can never do more than the API token that minted it. If that role only allows live video, the device serves live streams and refuses recorded footage.
2
Get the device's LAN URIs
On your server, call
POST /api/camera/getMediaUris with cameraUuid, or /api/audiogateway/getMediaUris with gatewayUuid, using your API key. A device-scoped federated token can’t call the cloud API.Python
- Each field is an array because a device can have more than one LAN address. Use the first one your client can reach.
- In the VOD templates, replace
{START_TIME}with a Unix timestamp in seconds and{DURATION}with a length in seconds. - The LAN hostname is public DNS that resolves to the device’s private IP, and the device serves a publicly trusted certificate for it. Connect using the hostname exactly as returned, not the raw IP, and keep normal TLS verification on. Devices in the EU region use
.lan.eu.rhombussystems.comhostnames (API Regions).
3
Present the federated token to the device
Send the federated token on every request to the device, including each DASH/HLS segment and the WebSocket upgrade. Use whichever form your client supports:The device checks the token with Rhombus: it must be unexpired, belong to the device’s organization, and carry a role that can view this device. The device caches a successful check for up to 60 seconds, so an expired or revoked token can keep working for up to a minute.
- Headers
- Query parameters
For native apps, servers, curl, and ffmpeg:
Code examples
Live DASH manifest
cURL
200). A missing, expired, or unauthorized token returns 401.
Recorded footage with ffmpeg
ffmpeg passes-headers on to every playlist and segment request. This saves 60 seconds of footage starting at 1767225600 (2026-01-01 00:00:00 UTC):
ffmpeg
Live H.264 over WebSocket
RhombusRealtimePlayer with connectionMode="lan" from the React SDK.
Audio over WebSocket
ThelanLiveOpusUris socket carries audio in both directions and uses the same federated token authentication.
Listening
Each binary message from the device holds three TLV records. Each record header is 1 bit (echo flag), 7 bits (type), and a 24-bit big-endian length, followed by the value.Talking
To play audio on the device’s speaker, send binary messages on the same socket. Each record is a 4-byte ASCII type, a 4-byte big-endian length, then the payload. Each audio record carries exactly 20 ms of audio.
By default the device plays every Opus packet, even late ones, and drops late PCM to stay real time.
Browser apps
- WebSocket streams (
lanLiveH264Uris,lanLiveOpusUris) work from any origin with the token in the query string. - LAN DASH and HLS (
lanLive*andlanVod*URLs) can’t be loaded by browser JavaScript such as dash.js or hls.js on your own domain, because devices only allow Rhombus origins for cross-origin requests. Play LAN DASH/HLS from a native app or server, or use the WebSocket stream in the browser. - Never put an API key in browser code. Mint federated tokens on your server and hand only those to the browser.
Devices on older firmware
Devices running firmware released before mid-April 2026 only read the token from a cookie. If a native client must support them, also send:Troubleshooting
401 on every request
401 on every request
No token reached the device,
x-auth-scheme isn’t exactly federated-token, or you sent an API key instead of a federated token. Devices never accept API keys.401 after working for a while
401 after working for a while
The federated token expired. Mint a new one before
durationSec runs out.401 for one device, fine for others
401 for one device, fine for others
The token was minted with
deviceUUid for a different device, or its role can’t view this device.Live works, recorded footage is refused
Live works, recorded footage is refused
The token’s role, inherited from the API key that minted it, only allows live video.
Connection closes with no response
Connection closes with no response
The device couldn’t reach the Rhombus cloud to check the token.
Works in curl, fails in a browser
Works in curl, fails in a browser
Browsers block cross-origin DASH/HLS requests to the device. See Browser apps.
TLS or hostname errors
TLS or hostname errors
Use the LAN hostname from
getMediaUris, not the raw IP address.Next steps
React SDK
Drop-in LAN and WAN players that handle federated tokens for you.
LAN Realtime Detection
Full H.264 TLV format and AI bounding-box overlays.
Streaming Video
Thumbnails, shared streams, and recorded clips through the cloud.
Retrieving Audio
Audio gateway streams and recordings.