Skip to main content
Version: 4.x.x

E2EE - iOS

End-to-end encryption (E2EE) encrypts the audio and video of a room on the sender's device. Only participants who have the key can decrypt it. You create a BaseKeyProvider, pass it to VideoSDK.setKeyProvider(_:) before you join, and set the keys. For a step-by-step setup, see E2EE Setup.

There are two kinds of keys:

  • A shared key encrypts the whole room. Every participant uses the same key. Set it with setSharedKey(_:).
  • Participant keys encrypt each participant's media with that participant's own key. Set them with VideoSDK.setParticipantKey(_:key:). They are used only when no shared key is set. The media of a participant who has no key is not encrypted.

BaseKeyProvider​

final class BaseKeyProvider

Holds the encryption keys for a room. Create it with BaseKeyProvider().

setSharedKey()​

func setSharedKey(_ key: String) throws

  • Sets one key for the whole room. Every participant must set the same key.
  • The key is used exactly as you pass it. Spaces and line breaks are not removed.
  • While a shared key is set, participant keys are not used.

Parameters​

  • key: String

Throws​

  • ERROR_INVALID_PARAMETER (3073) when the key is empty.

Example​

do {
let keyProvider = BaseKeyProvider()
try keyProvider.setSharedKey("<YOUR_SHARED_KEY>")
VideoSDK.setKeyProvider(keyProvider)
} catch {
print("Could not set the encryption key: \(error)")
}

removeKey()​

func removeKey(_ participantId: String)

Parameters​

  • participantId: String

Example​

func stopDecrypting(with keyProvider: BaseKeyProvider) {
keyProvider.removeKey("<PARTICIPANT_ID_2>")
}

exportSharedKey()​

func exportSharedKey() -> Data?

  • Returns the shared key as UTF-8 data, or nil when no shared key is set.

Example​

func printSharedKeyLength(of keyProvider: BaseKeyProvider) {
if let keyData = keyProvider.exportSharedKey() {
print("The shared key has \(keyData.count) bytes")
}
}

ratchetSharedKey()​

func ratchetSharedKey() -> Data?

  • Returns the current shared key, the same value as exportSharedKey(). It does not change the key.

Using the key provider​

  • VideoSDK.setKeyProvider(_:) sets the provider. Call it before join().
  • VideoSDK.removeKeyProvider() turns E2EE off for the next join.
  • VideoSDK.getKeyProvider() returns the provider you set, or nil.
  • VideoSDK.setParticipantKey(_:key:) sets, changes or removes the key of one participant, also while in a room. Set a provider first, or it throws ERROR_INVALID_PARAMETER (3073). The key is also saved in the provider, so a rejoin uses the same keys.
  • Every participant needs the keys of all participants, including its own. Use the participantId that each participant passes to VideoSDK.createRoom().
  • The e2eeEnabled property of Room is true when you joined with a shared key or at least one participant key.
  • The provider stays set for every later room in your app.
// one key for each participant, including yourself
VideoSDK.setKeyProvider(BaseKeyProvider())
do {
try VideoSDK.setParticipantKey("<PARTICIPANT_ID_1>", key: "<KEY_1>")
try VideoSDK.setParticipantKey("<PARTICIPANT_ID_2>", key: "<KEY_2>")
} catch {
print("Could not set the participant keys: \(error)")
}

// join the next room without E2EE
VideoSDK.removeKeyProvider()

Got a Question? Ask us on discord