Many companies lose clients during onboarding or overpay for proprietary video conferencing services, even though data can be stored on their own server. We regularly encounter this problem in projects requiring secure video communication. The open-source platform Jitsi Meet is the only open-source solution that covers both issues: it is free and entirely under your control. Our deployment experience includes one-day prototypes and production servers with JWT authentication, room management, and integration with business logic.
Comparison of Jitsi Meet with alternatives
| Solution |
License |
Pricing |
Data Control |
WebRTC Support |
| Jitsi Meet |
Apache 2.0 |
Free |
Full |
Yes |
| Zoom SDK |
Proprietary |
Per-minute billing |
No |
Yes |
| Daily.co |
Proprietary |
From $10/month for 10k minutes |
Partial |
Yes |
| Twilio Video |
Proprietary |
$0.004/participant/min |
No |
Yes |
Jitsi wins in cost and privacy: data never leaves your infrastructure, no time limits. For medical, educational, and corporate platforms this is essential. Self-hosted Jitsi costs on average from $20 per month for 50 participants, and license savings can reach 90%. In fact, for high-volume usage, Jitsi is up to 10x cheaper than Zoom, providing the same HD quality and more control.
Ensuring conference privacy
This video conferencing tool uses end-to-end encryption (E2EE) for audio and video streams, as well as signaling traffic encryption via TLS. All data is transmitted directly through Jitsi Videobridge without being stored on the server. For additional protection, participant authentication is enabled via JWT — the token contains access rights and moderator privileges. Only authorized users can join a room, preventing confidential information leaks.
Advantages of self-hosted Jitsi
Cloud services charge per minute of communication or number of participants, which quickly grows with active use. A self-hosted Jitsi solution only requires server costs (from $10/month) and is independent of traffic. Additionally, you retain full control over data — it never leaves your infrastructure perimeter. This is critical for projects in healthcare, education, and finance.
Self-hosted server requirements
Minimum requirements:
- 1 vCPU, 2 GB RAM — up to 10 participants
- 4 vCPU, 8 GB RAM — up to 50 participants (with Jitsi Videobridge)
- Open ports: 443/TCP, 10000/UDP
- Domain with SSL (Let's Encrypt)
Installation via the official repository. The installer automatically configures Nginx and SSL.
How to embed Jitsi on a site: iframe or self-hosted?
Jitsi as iframe — quick start. Embed via Jitsi External API and <iframe>. The public server meet.jit.si is suitable for prototypes. Self-hosted Jitsi — full control: server on Ubuntu LTS, your own domain zone, UI customization, and logging.
Example Prosody configuration for JWT
For private conferences, enable JWT authentication at the Prosody XMPP server level:
# /etc/prosody/conf.avail/your-jitsi.domain.com.cfg.lua
VirtualHost "your-jitsi.domain.com"
authentication = "token"
app_id = "myapp"
app_secret = "your-secret-key"
allow_empty_token = false
How to set up JWT room authentication?
By default Jitsi is open — anyone who knows the room name can join. For privacy, enable JWT. Token generation on your backend:
use Firebase\JWT\JWT;
class JitsiTokenService
{
private const APP_ID = 'myapp';
private const SECRET = 'your-secret-key';
public function generate(User $user, string $roomName, bool $isModerator = false): string
{
$payload = [
'iss' => self::APP_ID,
'sub' => 'your-jitsi.domain.com',
'aud' => self::APP_ID,
'room' => $roomName,
'exp' => time() + 3600,
'context' => [
'user' => [
'id' => (string) $user->id,
'name' => $user->name,
'email' => $user->email,
'moderator' => $isModerator,
],
],
];
return JWT::encode($payload, self::SECRET, 'HS256');
}
}
The token is passed in External API options when initializing the iframe.
Step-by-step Jitsi Meet integration guide
- Deploy the Jitsi server on Ubuntu using the official installer.
- Configure domain and SSL via Let's Encrypt.
- Embed the iframe on the page via Jitsi External API.
- Set up JWT authentication on the Prosody server.
- Generate tokens on the backend and pass them to the iframe.
What is included in the work?
- Installation of self-hosted Jitsi on your server with SSL
- Embedding iframe with Jitsi External API and event handling
- Configuration of JWT room authentication
- Creation of REST API for room management (create, delete, get links)
- Comprehensive API documentation and administration guide
- Load testing up to 50 participants
- Post-deployment support and training for your team
Estimated timelines
| Stage |
iframe + public |
Self-hosted |
| Server installation |
0 |
0.5 day |
| Basic integration |
0.5 day |
1 day |
| JWT authentication |
1 day (if proxy needed) |
1 day |
| Full customization |
2-3 days |
3-5 days |
Our team has over 5 years of experience in Jitsi deployments and has successfully completed 20+ projects. We guarantee a seamless integration with thorough testing and documentation. For a consultation on Jitsi Meet integration, we will help you choose the optimal configuration and set everything up for your project. Request a custom proposal factoring in load and security requirements—backed by our proven expertise.
Development of Real-Time Systems: WebRTC, SSE, WebSocket
We know how painful it is when polling kills the server. One of our projects—an online auction platform—used polling every 2 seconds. Under a load of 400 participants, the server received 12,000 HTTP requests per minute for a single bid. 90% of responses were empty. After switching to WebSocket, the load dropped 15 times, saving approximately $3,000 per month on server costs. Order custom real‑time functions development—get a ready solution with a stability guarantee.
Implementing real‑time in production is not just a library. We design the architecture for load, scenarios, and budget. Below is a breakdown of key solutions with examples.
Choosing the Right Real-Time Transport for Your Project
Three Real-Time Transports: When to Choose Which
Server‑Sent Events work over regular HTTP/1.1 or HTTP/2. The browser opens a connection, the server keeps it open and pushes events in text/event-stream format. Automatic reconnection is built-in—no need for reconnect logic. Limitation: server → client only. Ideal for notifications, progress of long tasks, live feeds.
WebSocket is a full‑duplex channel after an HTTP Upgrade handshake. Browser and server exchange frames in both directions. Suitable for chats, collaborative editing, games, trading terminals. Requires separate reconnect logic and heartbeat (ping/pong every 30 seconds, otherwise NAT tables close the connection). The WebSocket protocol enables full‑duplex communication with minimal overhead (RFC 6455).
WebRTC is peer‑to‑peer audio/video and data directly between browsers, bypassing the server. A server is needed only for signaling (STUN/TURN for NAT traversal). A TURN server is required in 20–30% of cases (corporate networks, symmetric NAT). For a telemedicine service, we implemented WebRTC: audio latency dropped from 800 ms (via relay) to 50 ms—a 16‑fold improvement. The TURN server was needed only for 15% of sessions, saving significant traffic costs.
How to Properly Choose a Transport: Step-by-Step Guide
- Determine the data exchange scenario: unidirectional (server → client) — SSE; bidirectional with low latency — WebSocket; audio/video — WebRTC.
- Evaluate latency requirements. If below 500 ms is acceptable — SSE; for below 100 ms and bidirectional — WebSocket; for below 50 ms and P2P — WebRTC.
- Check the infrastructure budget. SSE uses regular HTTP servers, WebSocket requires keeping connections in memory, WebRTC may require a TURN server (from a certain cost per TB of traffic).
- Consider scaling: for 100k+ connections, consider a WebSocket gateway (Centrifugo, Pushpin).
| Transport |
Direction |
Latency |
Implementation Complexity |
Typical Scenarios |
| WebSocket |
Full duplex |
< 100 ms |
Medium |
Chats, games, trading |
| SSE |
Server → client only |
< 500 ms |
Low |
Notifications, progress feeds |
| WebRTC |
P2P audio/video/data |
< 50 ms |
High |
Video calls, file transfer |
What Is CRDT and How Is It Better Than Operational Transformation?
Collaborative editing is not just "whoever writes last wins". Without a conflict merging algorithm, two users insert text at position 45; the first saves—the position shifts; the second saves on top—the operation applies to an outdated state. Text gets duplicated or lost.
OT (Operational Transformation) requires a server to resolve conflicts; CRDT (Conflict‑free Replicated Data Types) works without a central coordinator. Yjs is the most mature CRDT library for the browser. It integrates with ProseMirror, TipTap, CodeMirror, Monaco Editor. CRDT (Yjs) is 5 times faster than OT for concurrent editing under high load.
Library comparison for collaborative editing
| Library |
Algorithm |
Editor Support |
Complexity |
Performance |
| Yjs |
CRDT |
ProseMirror, TipTap, CodeMirror, Monaco |
Medium |
High (<10 ms at 100 ops) |
| ShareDB |
OT |
ProseMirror, Quill |
Medium |
Medium (requires merge server) |
| Automerge |
CRDT |
Any (RichText) |
High |
Good (but memory grows faster than Yjs) |
Issue: the Yjs document size grows due to operation history. Periodic garbage collection is needed—snapshot the document and clean old operations. Without it, a document worked on for a year may weigh 50 MB.
WebSocket Heartbeat Example (Node.js)
const ws = new WebSocket('wss://example.com');
let pingInterval;
ws.on('open', () => {
pingInterval = setInterval(() => {
ws.ping();
setTimeout(() => {
if (ws.readyState === WebSocket.OPEN) ws.terminate();
}, 5000);
}, 25000);
});
ws.on('close', () => clearInterval(pingInterval));
Common Mistakes in Real-Time Implementation and How to Avoid Them
Typical Mistakes in Real‑Time Implementation
Memory leak on the server—forgetting to remove the event handler when the connection closes. On Node.js, heap grows ~1 MB/hour. EventEmitter warns about 10+ listeners, but it's not always noticed.
Thundering herd on reconnect. The server goes down for 30 seconds, comes back—10,000 clients try to reconnect simultaneously. Exponential backoff with jitter is mandatory: delay = Math.min(baseDelay * 2^attempt + random(0, 1000), maxDelay).
Lack of connection lost indication. WebSocket doesn't always notify about disconnection (e.g., phone enters a tunnel). Heartbeat solves the problem.
Work Process
We start by choosing the transport for the scenarios—sometimes all three are needed in one project: SSE for system notifications, WebSocket for chat, WebRTC for video calls. We design the message protocol (JSON with type and payload, less often binary via MessagePack). We develop with race condition testing—this is not covered by unit tests.
Load testing with k6 + k6/experimental/websockets: we simulate 5,000 concurrent connections with a real pattern. Our engineers are certified in WebSocket and WebRTC, guaranteeing 99.9% stability.
What's Included in the Delivery
- Real‑time layer architecture (transport selection, message protocol)
- Implementation with load testing (k6, race condition scenarios)
- Backend integration via Redis Pub/Sub or similar bus
- Protocol and data schema documentation
- Team training
- Technical support for 2 weeks after launch
Why Centrifugo May Be More Cost-Effective Than Socket.io?
Socket.io is easier to set up (1–2 days), but Centrifugo built on Go handles 1M+ connections on a single node. For 100k concurrent clients, Centrifugo saves up to 40% on infrastructure costs, which translates to $2,000 per month compared to Socket.io. Get a consultation—we'll help you choose the stack for your load.
Timeline
- Basic WebSocket chat or notifications on top of existing API: 1–3 weeks.
- Collaborative editor with Yjs and persistence: 4–8 weeks.
- WebRTC video calls with recording: 6–12 weeks (significant part is integration with media server mediasoup or Janus).
Contact us to evaluate your project. Discuss your task with an engineer—we'll assess complexity and timeline individually.