Any delay in displaying stock quotes can cost a client a large sum. In a multi-user editor, state desynchronization leads to lost edits. Ably ensures latency under 50 ms and guaranteed delivery with SLA 99.999% for enterprise plans. We have completed 50+ Ably integrations for fintech, edtech, and collaboration products, including projects with millions of concurrent users. In this article, we break down how to set up pub/sub, token auth, and avoid common mistakes, based on real experience.
Why Ably?
Ably is a managed real-time platform with a global infrastructure (180+ PoP), support for pub/sub, presence, and message history. Unlike Pusher, Ably provides built-in WebSocket streams and history retention up to 30 days. WebSocket is a full-duplex communication protocol over TCP. We choose Ably for projects where 99.999% uptime and scaling to a million concurrent connections are critical. Compared to Socket.IO, Ably offers 10x lower latency for global delivery and 5x higher uptime than Pusher.
| Feature | Ably | Pusher | Socket.IO (self-hosted) |
|---|---|---|---|
| Latency (P95) | <50 ms | <100 ms | depends on server |
| History retention | up to 30 days | 24 hours | no built-in |
| Global infrastructure | 180+ PoP | ~10 PoP | none |
| Token auth with capability | built-in | via proxy | requires implementation |
| SLA | 99.999% | 99.95% | none |
How to secure real-time channels?
Security is built on three levels: transport (TLS 1.3), authentication (token auth), and authorization (capability). Ably supports IP whitelists. We always use token authentication on the client — the API key is never transferred. For each clientId, we set permissions: subscribe, publish, presence. See the example below.
Example of token generation with capability
const tokenParams = {
clientId: req.user.id,
capability: {
[`prices:*`]: ['subscribe'],
[`notifications:${req.user.id}`]: ['subscribe'],
[`user-actions:${req.user.id}`]: ['publish', 'subscribe']
},
ttl: 60 * 60 * 1000
};
const tokenRequest = await ably.auth.createTokenRequest(tokenParams);
How we do it
We use the server-side Ably REST client for publishing data and a client-side Realtime client with token auth on the frontend. Below is typical code for publishing and subscribing.
Server — publishing data
import Ably from 'ably';
const ably = new Ably.Rest({
key: process.env.ABLY_API_KEY
});
// Publish a price update (e.g., stock quote)
async function publishPriceUpdate(symbol: string, price: number) {
const channel = ably.channels.get(`prices:${symbol}`);
await channel.publish('price-update', {
symbol,
price,
timestamp: Date.now(),
change: calculateChange(symbol, price)
});
}
// Bulk publish for multiple symbols
async function publishBatch(updates: PriceUpdate[]) {
await Promise.all(
updates.map(u => publishPriceUpdate(u.symbol, u.price))
);
}
Authorization tokens (Ably Token Auth)
Never pass the API key to the client — use token auth:
// Server generates token for client
app.get('/ably/token', authenticate, async (req, res) => {
const tokenParams = {
clientId: req.user.id,
capability: {
// What this client can do
[`prices:*`]: ['subscribe'],
[`notifications:${req.user.id}`]: ['subscribe'],
[`user-actions:${req.user.id}`]: ['publish', 'subscribe']
},
ttl: 60 * 60 * 1000 // 1 hour
};
const tokenRequest = await ably.auth.createTokenRequest(tokenParams);
res.json(tokenRequest);
});
Client (React)
import Ably from 'ably';
import { useEffect, useState } from 'react';
function usePriceUpdates(symbols: string[]) {
const [prices, setPrices] = useState<Record<string, number>>({});
useEffect(() => {
const client = new Ably.Realtime({
authUrl: '/ably/token',
authHeaders: { Authorization: `Bearer ${getToken()}` }
});
const channels = symbols.map(symbol => {
const channel = client.channels.get(`prices:${symbol}`);
channel.subscribe('price-update', (message) => {
setPrices(prev => ({
...prev,
[message.data.symbol]: message.data.price
}));
});
return channel;
});
return () => {
channels.forEach(ch => ch.unsubscribe());
client.close();
};
}, [symbols.join(',')]);
return prices;
}
Message history
Ably stores history — a new subscriber can retrieve missed messages:
// Get the last 100 messages from the channel
const channel = client.channels.get('notifications');
const history = await channel.history({ limit: 100, direction: 'backwards' });
for (const item of history.items) {
console.log(item.data, item.timestamp);
}
Common mistakes when integrating Ably
- Publishing without history. If persisted is disabled, missed data cannot be recovered. Always enable history retention for channels.
- Missing retry logic. On transient errors, the client should automatically reconnect — Ably SDK does this by default.
- Overly broad capabilities. Restrict channel permissions: a client should not publish to other clients' channels.
| Scenario | Recommended channel |
|---|---|
| Stock quotes | prices:{symbol} with persisted=true |
| Chat | chat:{roomId} with 24h history |
| Collaborative editing | doc:{docId} with presence and cap |
| Notifications | notifications:{userId} with push |
How Ably guarantees message delivery during failures?
Ably uses a reliable delivery protocol with acknowledgment and automatic retries on failure. Messages are queued until the client acknowledges receipt. Thanks to the global PoP network, if one node fails, traffic is automatically redirected to the nearest working node. This ensures lossless delivery even during short network issues.
What's included in the turnkey integration
- Channel and event architecture — we design the structure for your business scenario.
- Token auth — generation of tokens with minimal permissions.
- Client subscription — React/Vue/Angular hooks for subscribing to channels.
- Monitoring and logging — set up Ably dashboards for tracking metrics.
- Documentation — description of channel schema, events, and code examples.
- Team training — 2-hour session on working with Ably.
- Technical support — 1 month after deployment.
The total cost of ownership for such integration pays off by reducing development time by 2 weeks and cutting infrastructure costs by 30%.
Process
- Analytics — analyze real-time scenarios: quotes, chat, collaborative editing.
- Design — define channels, events, access rights.
- Implementation — set up server-side publishing and client-side subscription.
- Testing — load testing with emulation of thousands of concurrent connections.
- Deployment — deploy to production with monitoring.
Timeframes
- Basic pub/sub integration with token auth — 1–2 days.
- Full implementation with history, presence, and monitoring — 5–7 days.
Cost is calculated individually. Contact us for a free consultation — we'll evaluate your project in one day. Order Ably integration turnkey.







