Realtime
Sessions
Each Running product maps to one managed Woven session. Woven Host provisions the namespace and session, applies its CCU allocation, and returns the exact assigned scope in a private connection descriptor.
This is the active managed path. Reveal the Running product's connection details in the console and treat the returned token and TLS material as secrets. The descriptor is the source of truth for connecting.
The descriptor defines the session boundary
- Endpoint and TLS
- Native clients use
endpointandcaPemor an application-provided trusted root store. The Online browser path useswebTransport.urland the optional lowercase-hexwebTransport.certificateSha256pin. Browser JavaScript cannot installcaPemas an arbitrary trust root. - Managed scope
namespaceIdandsessionIdidentify the one session authorized by this descriptor. The token is limited to that managed product.- Spaces
- The Lite connection descriptor returns spaces
1and2, both at epoch1, with aLogicalcoordinate frame andBroadcastAllrouting. - Channels
- Both spaces expose exactly channels
1and4: reliable ordered delivery on channel1(ReliableOrdered) and unreliable sequenced delivery on channel4(UnreliableSequenced). Both areEphemeralwith a 64 KiB payload ceiling and generic opaque payloads. Channels2and3remain disallowed. Channel policy is server-controlled and cannot be overridden by a client. Host refuses to reveal a descriptor if the live node does not match this exact contract.
Admission joins the managed session
Connect with the descriptor token using explicit Bearer authentication. Before subscribing or publishing, call request_admission or admit_with_cancellation in Rust, or requestAdmission or admitWithCancellation in the TypeScript browser client. An admitted result atomically consumes one CCU slot and joins the session. The ordinary session join path is rejected for managed sessions.
- Admitted
- The connection is already a session member and may proceed to subscribe.
- Queued
- The connection owns a queue ticket. Use
queue_heartbeatwhile waiting andqueue_claimafter an offer;queue_statusandqueue_cancelare also available. - Paused or rejected
- Treat the result as a semantic outcome. Do not invent a session, bypass admission, or silently retry transport I/O.
Disconnecting releases the managed admission and makes capacity available to the queue. See the Rust client or TypeScript client requirements before opening a managed connection.
Availability scope
The Lite tier uses the logical and managed 3D spatial definitions plus Ephemeral channels returned in its descriptor. Native QUIC, browser WebTransport, the TypeScript browser client, and managed spatial routing are Online. Persistence beyond Ephemeral remains Preview. Pro and Dedicated Preview access begins privately with founders; every client continues to follow the exact supported scope returned by Woven Host.