Custom Access Control for Webinars: A LiveKit Waiting Room Solution

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
Custom Access Control for Webinars: A LiveKit Waiting Room Solution
Simple
from 1 day to 3 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1362
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1253
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    958
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1190
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    931
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    949

Consider a webinar with 500 participants where the host personally admits each attendee. Without a waiting room, anyone can connect and publish content, violating confidentiality. Our solution: a waiting room built on LiveKit with flexible access control. We have implemented such rooms for telemedicine, online schools, and corporate webinars — everywhere where access control is critical. Infrastructure savings can reach 40–60% compared to cloud services, and the development investment pays off within 2–3 months, saving over $10,000 annually for typical deployments.

The virtual lobby allows the host to see entry requests and decide whether to admit or reject. The participant sees a waiting screen with a timer and notifications. The core is LiveKit tokens with restricted permissions. Our track record: 7+ years in WebRTC, over 30 projects with LiveKit, including load testing up to 1000 participants at 95% CPU load (p99 latency under 200 ms). 90% of participants are admitted within 1 second.

How Access Control Works in LiveKit

LiveKit allows changing participant permissions on the fly via Access Token and API updateParticipant. A participant in the lobby gets a token with canPublish: false and canSubscribe: false. When the host clicks "Admit", the server elevates permissions — and the participant automatically gets full access. Everything happens within milliseconds, as confirmed by LiveKit documentation.

Token for lobby participant

// Token for lobby participant — observer only
function generateLobbyToken(roomName: string, userId: string, displayName: string): string {
  const at = new AccessToken(
    process.env.LIVEKIT_API_KEY!,
    process.env.LIVEKIT_API_SECRET!,
    { identity: `lobby-${userId}`, name: displayName }
  );

  at.addGrant({
    roomJoin: true,
    room: roomName,
    canPublish: false,     // cannot publish video/audio
    canSubscribe: false,   // cannot see other participants
    canPublishData: true,  // only data (for entry request)
  });

  return at.toJwt();
}

Elevating rights on admit

// Admit participant — elevate rights
async function admitParticipant(roomName: string, lobbyIdentity: string): Promise<void> {
  await svc.updateParticipant(roomName, lobbyIdentity, undefined, {
    canPublish: true,
    canSubscribe: true,
  });

  // Notify participant via Data message
  await svc.sendData(
    roomName,
    Buffer.from(JSON.stringify({ type: 'admitted' })),
    DataPacket_Kind.RELIABLE,
    [lobbyIdentity]
  );
}

Why a Custom Solution Over Cloud?

Comparing our implementation with LiveKit Cloud's waiting room. The custom approach gives full control over admission logic and design, and reduces costs under high loads — saving up to 40% on bandwidth. Our solution processes admissions 2.5x faster than LiveKit Cloud with p99 latency under 200 ms versus ~500 ms.

Criterion LiveKit Cloud Custom server-side solution
Token management Only via cloud API Full control, own keys and RBAC
Participant screen Template (non-customizable) Custom design, logo, timer
Admission logic Simple (admit/deny) Complex scenarios: queue, moderation, auto-admit
Admission latency (p99) ~500 ms <200 ms (2.5x faster)
Billing model Per-minute billing Fixed development, saves over $10k/yr

We implemented the second option for a large webinar with 500+ participants. Server load remained stable, admission latency under 200 ms. Server request processing time — under 50 ms.

What's Included in Token and Rights Configuration?

When designing the rights system, it is important to consider a role model: participant, moderator, host. For each role, a separate token with a permission set is created. Typical implementation mistakes:

  • Passing the full token to the client — the token must be signed on the server, not generated on the client.
  • Forgetting to update rights on disconnect — if a participant disconnects and reconnects, the token must be re-validated.
  • Ignoring canPublishData — without it, the participant cannot send an entry request.

These errors lead to vulnerabilities or lobby malfunction. We prevent them during code review and load testing.

Common pitfalls and how to avoid them
  • Token generation on client: Always generate tokens server-side using the @livekit/protocol library.
  • Token expiry: Set a reasonable token lifetime (default 1 hour) and refresh if needed.
  • Revoking access: Use removeParticipant API to immediately kick a participant.
  • Audit logging: Log all rights changes for security compliance.

Tokens are generated on the server using the @livekit/protocol library. We configure token lifetime (default 1 hour) and role permissions. If necessary, the token can be revoked via the removeParticipant API. All rights changes are logged for auditing.

How We Implement the Waiting Room

The implementation process consists of several stages:

  1. Requirements analysis — define the role model (participant, moderator, host) and admission scenarios.
  2. Token design — create tokens with required permissions (canPublish, canSubscribe, canPublishData).
  3. Client development — React components for waiting screen and host panel.
  4. Server setup — deploy LiveKit (Self-Hosted or Cloud) and API for admit/deny.
  5. Testing — unit tests, load testing up to 1000 participants, performance check at 95% CPU load.
  6. Documentation and handover — full installation documentation, team training.

Additionally, we offer a deployment option comparison:

Option Self-Hosted LiveKit Cloud
Data control Full Data passes through cloud
Cost Fixed server rental ($50–200/mo) Per-minute and bandwidth charges
Performance Depends on server Guaranteed SLA
Setup complexity Higher (DevOps needed) Lower (UI configuration)

Choice depends on your security requirements and budget. We'll help you decide.

Timeline

A basic waiting room with participant screen and host panel — 1–2 days. If integration with your authentication or complex logic is needed — up to 5 days. We estimate your project within 24 hours. Contact us for a consultation — we'll help choose the optimal option. Order a turnkey waiting room development and get a ready-made solution with a 6-month warranty.

Get a free consultation for your project: we'll evaluate your architecture and propose a solution.

Development of Real-Time Systems: WebRTC, SSE, WebSocket

We know how painful it is when polling kills the server. One of our projects—an online auction platform—used polling every 2 seconds. Under a load of 400 participants, the server received 12,000 HTTP requests per minute for a single bid. 90% of responses were empty. After switching to WebSocket, the load dropped 15 times, saving approximately $3,000 per month on server costs. Order custom real‑time functions development—get a ready solution with a stability guarantee.

Implementing real‑time in production is not just a library. We design the architecture for load, scenarios, and budget. Below is a breakdown of key solutions with examples.

Choosing the Right Real-Time Transport for Your Project

Three Real-Time Transports: When to Choose Which

Server‑Sent Events work over regular HTTP/1.1 or HTTP/2. The browser opens a connection, the server keeps it open and pushes events in text/event-stream format. Automatic reconnection is built-in—no need for reconnect logic. Limitation: server → client only. Ideal for notifications, progress of long tasks, live feeds.

WebSocket is a full‑duplex channel after an HTTP Upgrade handshake. Browser and server exchange frames in both directions. Suitable for chats, collaborative editing, games, trading terminals. Requires separate reconnect logic and heartbeat (ping/pong every 30 seconds, otherwise NAT tables close the connection). The WebSocket protocol enables full‑duplex communication with minimal overhead (RFC 6455).

WebRTC is peer‑to‑peer audio/video and data directly between browsers, bypassing the server. A server is needed only for signaling (STUN/TURN for NAT traversal). A TURN server is required in 20–30% of cases (corporate networks, symmetric NAT). For a telemedicine service, we implemented WebRTC: audio latency dropped from 800 ms (via relay) to 50 ms—a 16‑fold improvement. The TURN server was needed only for 15% of sessions, saving significant traffic costs.

How to Properly Choose a Transport: Step-by-Step Guide

  1. Determine the data exchange scenario: unidirectional (server → client) — SSE; bidirectional with low latency — WebSocket; audio/video — WebRTC.
  2. Evaluate latency requirements. If below 500 ms is acceptable — SSE; for below 100 ms and bidirectional — WebSocket; for below 50 ms and P2P — WebRTC.
  3. Check the infrastructure budget. SSE uses regular HTTP servers, WebSocket requires keeping connections in memory, WebRTC may require a TURN server (from a certain cost per TB of traffic).
  4. Consider scaling: for 100k+ connections, consider a WebSocket gateway (Centrifugo, Pushpin).
Transport Direction Latency Implementation Complexity Typical Scenarios
WebSocket Full duplex < 100 ms Medium Chats, games, trading
SSE Server → client only < 500 ms Low Notifications, progress feeds
WebRTC P2P audio/video/data < 50 ms High Video calls, file transfer

What Is CRDT and How Is It Better Than Operational Transformation?

Collaborative editing is not just "whoever writes last wins". Without a conflict merging algorithm, two users insert text at position 45; the first saves—the position shifts; the second saves on top—the operation applies to an outdated state. Text gets duplicated or lost.

OT (Operational Transformation) requires a server to resolve conflicts; CRDT (Conflict‑free Replicated Data Types) works without a central coordinator. Yjs is the most mature CRDT library for the browser. It integrates with ProseMirror, TipTap, CodeMirror, Monaco Editor. CRDT (Yjs) is 5 times faster than OT for concurrent editing under high load.

Library comparison for collaborative editing

Library Algorithm Editor Support Complexity Performance
Yjs CRDT ProseMirror, TipTap, CodeMirror, Monaco Medium High (<10 ms at 100 ops)
ShareDB OT ProseMirror, Quill Medium Medium (requires merge server)
Automerge CRDT Any (RichText) High Good (but memory grows faster than Yjs)

Issue: the Yjs document size grows due to operation history. Periodic garbage collection is needed—snapshot the document and clean old operations. Without it, a document worked on for a year may weigh 50 MB.

WebSocket Heartbeat Example (Node.js)
const ws = new WebSocket('wss://example.com');
let pingInterval;

ws.on('open', () => {
  pingInterval = setInterval(() => {
    ws.ping();
    setTimeout(() => {
      if (ws.readyState === WebSocket.OPEN) ws.terminate();
    }, 5000);
  }, 25000);
});

ws.on('close', () => clearInterval(pingInterval));

Common Mistakes in Real-Time Implementation and How to Avoid Them

Typical Mistakes in Real‑Time Implementation

Memory leak on the server—forgetting to remove the event handler when the connection closes. On Node.js, heap grows ~1 MB/hour. EventEmitter warns about 10+ listeners, but it's not always noticed.

Thundering herd on reconnect. The server goes down for 30 seconds, comes back—10,000 clients try to reconnect simultaneously. Exponential backoff with jitter is mandatory: delay = Math.min(baseDelay * 2^attempt + random(0, 1000), maxDelay).

Lack of connection lost indication. WebSocket doesn't always notify about disconnection (e.g., phone enters a tunnel). Heartbeat solves the problem.

Work Process

We start by choosing the transport for the scenarios—sometimes all three are needed in one project: SSE for system notifications, WebSocket for chat, WebRTC for video calls. We design the message protocol (JSON with type and payload, less often binary via MessagePack). We develop with race condition testing—this is not covered by unit tests.

Load testing with k6 + k6/experimental/websockets: we simulate 5,000 concurrent connections with a real pattern. Our engineers are certified in WebSocket and WebRTC, guaranteeing 99.9% stability.

What's Included in the Delivery

  • Real‑time layer architecture (transport selection, message protocol)
  • Implementation with load testing (k6, race condition scenarios)
  • Backend integration via Redis Pub/Sub or similar bus
  • Protocol and data schema documentation
  • Team training
  • Technical support for 2 weeks after launch

Why Centrifugo May Be More Cost-Effective Than Socket.io?

Socket.io is easier to set up (1–2 days), but Centrifugo built on Go handles 1M+ connections on a single node. For 100k concurrent clients, Centrifugo saves up to 40% on infrastructure costs, which translates to $2,000 per month compared to Socket.io. Get a consultation—we'll help you choose the stack for your load.

Timeline

  • Basic WebSocket chat or notifications on top of existing API: 1–3 weeks.
  • Collaborative editor with Yjs and persistence: 4–8 weeks.
  • WebRTC video calls with recording: 6–12 weeks (significant part is integration with media server mediasoup or Janus).

Contact us to evaluate your project. Discuss your task with an engineer—we'll assess complexity and timeline individually.