E2EE - iOS
End-to-end encryption (E2EE) encrypts the audio and video of a room on the sender's device. Only participants who have the key can decrypt it. You create a BaseKeyProvider, pass it to VideoSDK.setKeyProvider(_:) before you join, and set the keys. For a step-by-step setup, see E2EE Setup.
There are two kinds of keys:
- A shared key encrypts the whole room. Every participant uses the same key. Set it with
setSharedKey(_:). - Participant keys encrypt each participant's media with that participant's own key. Set them with
VideoSDK.setParticipantKey(_:key:). They are used only when no shared key is set. The media of a participant who has no key is not encrypted.
BaseKeyProvider
final class BaseKeyProvider
Holds the encryption keys for a room. Create it with BaseKeyProvider().
setSharedKey()
func setSharedKey(_ key: String) throws
- Sets one key for the whole room. Every participant must set the same key.
- The key is used exactly as you pass it. Spaces and line breaks are not removed.
- While a shared key is set, participant keys are not used.
Parameters
- key:
String
Throws
ERROR_INVALID_PARAMETER(3073) when the key is empty.
Example
do {
let keyProvider = BaseKeyProvider()
try keyProvider.setSharedKey("<YOUR_SHARED_KEY>")
VideoSDK.setKeyProvider(keyProvider)
} catch {
print("Could not set the encryption key: \(error)")
}
removeKey()
func removeKey(_ participantId: String)
- Removes the key of one participant.
- On the provider you passed to
VideoSDK.setKeyProvider(_:), it stops decrypting this participant on this device until a new key is set, likeVideoSDK.setParticipantKey(_:key:)withkey: nil. No event is raised:onE2EEStateChangeddoes not report decryption failures. - On any other provider, it only forgets the stored key.
Parameters
- participantId:
String
Example
func stopDecrypting(with keyProvider: BaseKeyProvider) {
keyProvider.removeKey("<PARTICIPANT_ID_2>")
}
exportSharedKey()
func exportSharedKey() -> Data?
- Returns the shared key as UTF-8 data, or
nilwhen no shared key is set.
Example
func printSharedKeyLength(of keyProvider: BaseKeyProvider) {
if let keyData = keyProvider.exportSharedKey() {
print("The shared key has \(keyData.count) bytes")
}
}
ratchetSharedKey()
func ratchetSharedKey() -> Data?
- Returns the current shared key, the same value as
exportSharedKey(). It does not change the key.
Using the key provider
VideoSDK.setKeyProvider(_:)sets the provider. Call it beforejoin().VideoSDK.removeKeyProvider()turns E2EE off for the next join.VideoSDK.getKeyProvider()returns the provider you set, ornil.VideoSDK.setParticipantKey(_:key:)sets, changes or removes the key of one participant, also while in a room. Set a provider first, or it throwsERROR_INVALID_PARAMETER(3073). The key is also saved in the provider, so a rejoin uses the same keys.- Every participant needs the keys of all participants, including its own. Use the
participantIdthat each participant passes toVideoSDK.createRoom(). - The
e2eeEnabledproperty ofRoomistruewhen you joined with a shared key or at least one participant key. - The provider stays set for every later room in your app.
// one key for each participant, including yourself
VideoSDK.setKeyProvider(BaseKeyProvider())
do {
try VideoSDK.setParticipantKey("<PARTICIPANT_ID_1>", key: "<KEY_1>")
try VideoSDK.setParticipantKey("<PARTICIPANT_ID_2>", key: "<KEY_2>")
} catch {
print("Could not set the participant keys: \(error)")
}
// join the next room without E2EE
VideoSDK.removeKeyProvider()
Got a Question? Ask us on discord

