Skip to main content

Overview

When your client is on the same network as a Rhombus device, it can pull live video, recorded footage, and audio straight from the device instead of through the Rhombus cloud. You get lower latency and use no internet bandwidth.
Devices on your LAN never accept API tokens. Use your API token on your server to mint a short-lived federated token, then present the federated token to the device.
This guide covers:
  • How API tokens and federated tokens differ, and which one to use where
  • Minting a federated token and finding a device’s LAN URIs
  • Authenticating LAN requests with headers or query parameters
  • Live H.264 and two-way audio over WebSocket, plus DASH/HLS for live and recorded video
  • Browser limitations and troubleshooting

API tokens vs federated tokens

These are two different credentials with different jobs. A federated token is a bearer credential: anyone holding it can act with its role. For LAN streaming, mint device-scoped tokens with deviceUUid. A device-scoped token can only fetch that one device’s media, and the cloud API rejects it. Also mint from an API token whose role is no broader than the viewer needs, and keep durationSec short.
The x-auth-scheme value is exactly federated-token. There is no federated-session-token scheme, and a federated token never goes in x-auth-apikey.

Prerequisites

  • A Rhombus API key with permission to view the cameras or audio gateways you’ll stream (get one here)
  • A client on the same network as the device, able to reach it on TCP port 8000
  • A device that can reach the Rhombus cloud. The device checks every new token with Rhombus, so a device without internet access can’t authorize new clients.

Implementation

1

Mint a federated token on your server

Call generateFederatedSessionToken with your API key. Your API key never leaves your server.
Example response:
The token can never do more than the API token that minted it. If that role only allows live video, the device serves live streams and refuses recorded footage.
2

Get the device's LAN URIs

On your server, call POST /api/camera/getMediaUris with cameraUuid, or /api/audiogateway/getMediaUris with gatewayUuid, using your API key. A device-scoped federated token can’t call the cloud API.
Python
  • Each field is an array because a device can have more than one LAN address. Use the first one your client can reach.
  • In the VOD templates, replace {START_TIME} with a Unix timestamp in seconds and {DURATION} with a length in seconds.
  • The LAN hostname is public DNS that resolves to the device’s private IP, and the device serves a publicly trusted certificate for it. Connect using the hostname exactly as returned, not the raw IP, and keep normal TLS verification on. Devices in the EU region use .lan.eu.rhombussystems.com hostnames (API Regions).
3

Present the federated token to the device

Send the federated token on every request to the device, including each DASH/HLS segment and the WebSocket upgrade. Use whichever form your client supports:
For native apps, servers, curl, and ffmpeg:
The device checks the token with Rhombus: it must be unexpired, belong to the device’s organization, and carry a role that can view this device. The device caches a successful check for up to 60 seconds, so an expired or revoked token can keep working for up to a minute.

Code examples

Live DASH manifest

cURL
A valid token returns the DASH manifest (200). A missing, expired, or unauthorized token returns 401.

Recorded footage with ffmpeg

ffmpeg passes -headers on to every playlist and segment request. This saves 60 seconds of footage starting at 1767225600 (2026-01-01 00:00:00 UTC):
ffmpeg

Live H.264 over WebSocket

Example output from the Python script:
Each binary message is a sequence of TLV records (1-byte type, 3-byte big-endian length, value) ending with the H.264 frame data. The full type table, including embedded AI detections, is in LAN Realtime Detection Overlay. For a ready-made browser player, use RhombusRealtimePlayer with connectionMode="lan" from the React SDK.

Audio over WebSocket

The lanLiveOpusUris socket carries audio in both directions and uses the same federated token authentication.

Listening

Each binary message from the device holds three TLV records. Each record header is 1 bit (echo flag), 7 bits (type), and a 24-bit big-endian length, followed by the value.

Talking

To play audio on the device’s speaker, send binary messages on the same socket. Each record is a 4-byte ASCII type, a 4-byte big-endian length, then the payload. Each audio record carries exactly 20 ms of audio. By default the device plays every Opus packet, even late ones, and drops late PCM to stay real time.

Browser apps

  • WebSocket streams (lanLiveH264Uris, lanLiveOpusUris) work from any origin with the token in the query string.
  • LAN DASH and HLS (lanLive* and lanVod* URLs) can’t be loaded by browser JavaScript such as dash.js or hls.js on your own domain, because devices only allow Rhombus origins for cross-origin requests. Play LAN DASH/HLS from a native app or server, or use the WebSocket stream in the browser.
  • Never put an API key in browser code. Mint federated tokens on your server and hand only those to the browser.

Devices on older firmware

Devices running firmware released before mid-April 2026 only read the token from a cookie. If a native client must support them, also send:
Current firmware accepts this cookie too, so a native client can send it alongside the headers.

Troubleshooting

No token reached the device, x-auth-scheme isn’t exactly federated-token, or you sent an API key instead of a federated token. Devices never accept API keys.
The federated token expired. Mint a new one before durationSec runs out.
The token was minted with deviceUUid for a different device, or its role can’t view this device.
The token’s role, inherited from the API key that minted it, only allows live video.
The device couldn’t reach the Rhombus cloud to check the token.
Browsers block cross-origin DASH/HLS requests to the device. See Browser apps.
Use the LAN hostname from getMediaUris, not the raw IP address.

Next steps

React SDK

Drop-in LAN and WAN players that handle federated tokens for you.

LAN Realtime Detection

Full H.264 TLV format and AI bounding-box overlays.

Streaming Video

Thumbnails, shared streams, and recorded clips through the cloud.

Retrieving Audio

Audio gateway streams and recordings.
Last modified on October 5, 2026