WebSocket API Development for Real-Time Web Apps

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
WebSocket API Development for Real-Time Web Apps
Medium
~3-5 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1250
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    956
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    947

Imagine your chat or dashboard lags due to polling requests every 500 ms. Users complain about delays, and the backend is overwhelmed by N+1 queries. The solution is WebSocket: a persistent connection with latency under 10 ms instead of seconds. WebSocket is over 100x faster than traditional polling. Replacing polling with WebSocket cuts network and server load by 10–20 times, reduces server infrastructure costs by 3–5 times (saving $2,000–$5,000 per month), and saves up to 90% of traffic. For example, a fintech client reduced their server costs from $8,000/month to $2,000/month after switching from polling to WebSocket. We have been developing such realtime systems for over 5 years and completed 30+ projects for WebSocket chat applications, notifications, and collaborative work. Bidirectional WebSocket communication instantly delivers ticker updates, cursors, or game events—without unnecessary overhead. WebSocket API development is a core part of our expertise. For Socket.io vs WebSocket decisions, see the comparison table below. We also cover WebSocket API development, WebSocket server setup, implementing WebSocket in apps, WebSocket scaling strategies, WebSocket authentication methods, WebSocket heartbeat mechanisms, Redis Pub/Sub WebSocket scaling, WebSocket rooms management, and the WebSocket protocol.

Problems WebSocket API Solves

  • High polling latency: polling every 2 seconds gives up to 2000 ms lag; WebSocket delivers milliseconds.
  • Excessive traffic: each poll request sends HTTP headers (700+ bytes); WebSocket sends only data (a few bytes).
  • Complexity of realtime features: notifications, cursors, tickers—polling is inefficient.
  • Connection drops: mobile networks and proxies close idle channels—heartbeat is required.
  • Scaling: a single server cannot handle >10K connections—clustering with Redis Pub/Sub is needed.
Feature HTTP Polling WebSocket
Latency 500ms–2s <10ms
Traffic per message ~800 bytes headers ~50 bytes
Server load High (N requests) Low (persistent)
Real-time capability Poor Excellent

How We Develop a WebSocket Solution

We start with architectural design: choose the protocol (native WebSocket or Socket.io), define the message model (JSON schemas), plan authentication, and address scaling. Recently, we implemented a WebSocket server for a fintech startup: 50K concurrent connections, latency under 10 ms, full redundancy via Redis cluster. Below is a typical approach.

Basic Implementation with Rooms (Node.js + ws)

import { WebSocketServer } from 'ws';
import { createServer } from 'http';

const server = createServer(app);
const wss = new WebSocketServer({ server });

const rooms = new Map<string, Set<WebSocket>>();

wss.on('connection', (ws, req) => {
  const roomId = new URL(req.url!, 'http://x').searchParams.get('room');
  if (!roomId) return ws.close(4000, 'Missing room');

  if (!rooms.has(roomId)) rooms.set(roomId, new Set());
  rooms.get(roomId)!.add(ws);

  ws.on('message', (data) => {
    const message = JSON.parse(data.toString());
    rooms.get(roomId)?.forEach(client => {
      if (client !== ws && client.readyState === WebSocket.OPEN) {
        client.send(JSON.stringify(message));
      }
    });
  });

  ws.on('close', () => {
    rooms.get(roomId)?.delete(ws);
  });
});

We structure messages as a typed JSON protocol: { type, roomId, data, timestamp }. This simplifies debugging and processing.

Authentication and Security

Since WebSocket does not support custom headers during the handshake, we use the first message for authentication—send the token immediately after connection. If the token is invalid, we close the connection with code 4001.

ws.on('connection', (socket) => {
  let authenticated = false;
  const authTimeout = setTimeout(() => {
    if (!authenticated) socket.close(4001, 'Auth timeout');
  }, 5000);

  socket.once('message', (data) => {
    const { type, token } = JSON.parse(data.toString());
    if (type === 'auth' && validateToken(token)) {
      authenticated = true;
      clearTimeout(authTimeout);
      socket.send(JSON.stringify({ type: 'auth_success' }));
    } else {
      socket.close(4001, 'Invalid token');
    }
  });
});

This approach is more secure than a query string because the token is not exposed in logs.

Horizontal Scaling with Redis Pub/Sub

When clustering, clients are distributed among different servers. To ensure a message from a client on server 1 reaches a client on server 2, we use Redis Pub/Sub:

import { createClient } from 'redis';
const pub = createClient();
const sub = createClient();

ws.on('message', async (data) => {
  await pub.publish(`room:${roomId}`, data.toString());
});

sub.subscribe(`room:${roomId}`, (message) => {
  rooms.get(roomId)?.forEach(client => {
    if (client.readyState === WebSocket.OPEN) client.send(message);
  });
});

Redis acts as a bus—all servers receive events and deliver them to their clients. This proven solution handles 100K+ connections.

Choosing Between Socket.io and Native WebSocket

Characteristic Socket.io Native WebSocket
Overhead Medium (protocol headers) Minimal
Fallback Long-polling/Flash None
Reconnect Automatic Must implement
Rooms Built-in Manual implementation
Performance Up to 10K connections 100K+ connections
Protocol Control Limited Full

For projects with up to 10K connections and non-strict latency requirements, Socket.io is more convenient. Native WebSocket handles 10x more connections than Socket.io under the same resources, so it is better for >10K connections, minimal overhead, and full control over the protocol.

Heartbeat Implementation Importance

Browsers and proxies close idle connections after 20–120 seconds. Heartbeat (ping/pong) every 30 seconds keeps the channel alive and detects disconnections. Without it, clients appear "stuck" in the user list.

wss.on('connection', (ws) => {
  let alive = true;
  ws.on('pong', () => { alive = true; });

  const interval = setInterval(() => {
    if (!alive) return ws.terminate();
    alive = false;
    ws.ping();
  }, 30000);

  ws.on('close', () => clearInterval(interval));
});
Full server example with authentication and heartbeat (Node.js + ws)
import { WebSocketServer } from 'ws';
import { createServer } from 'http';

const server = createServer();
const wss = new WebSocketServer({ server });

wss.on('connection', (socket, req) => {
  const roomId = new URL(req.url!, 'http://x').searchParams.get('room');
  if (!roomId) { socket.close(4000, 'Missing room'); return; }

  let authenticated = false;
  const authTimeout = setTimeout(() => {
    if (!authenticated) socket.close(4001, 'Auth timeout');
  }, 5000);

  socket.once('message', (data) => {
    const { type, token } = JSON.parse(data.toString());
    if (type === 'auth' && validateToken(token)) {
      authenticated = true;
      clearTimeout(authTimeout);
      socket.send(JSON.stringify({ type: 'auth_success' }));
    } else {
      socket.close(4001, 'Invalid token');
    }
  });

  let alive = true;
  socket.on('pong', () => { alive = true; });
  const heartbeat = setInterval(() => {
    if (!alive) { socket.terminate(); return; }
    alive = false;
    socket.ping();
  }, 30000);

  socket.on('close', () => {
    clearInterval(heartbeat);
    clearTimeout(authTimeout);
  });
});

server.listen(8080);

Our Work Process

  1. Analysis and prototype—determine load, scenarios, message protocol.
  2. Design—architecture, stack selection, authentication scheme.
  3. Development—server and client implementation, Redis integration.
  4. Testing—load tests (10K+ connections), fault tolerance tests.
  5. Deployment and monitoring—CI/CD, SRE dashboards, latency alerts.

What's Included

  • Full architectural documentation (PDF/Markdown)
  • Repository with server and client code (TypeScript)
  • Redis Pub/Sub integration for scaling
  • Heartbeat and reconnect mechanism setup
  • Deployment guide for your infrastructure
  • 1 month of free support after release

Development Timeline

  • MVP with rooms and authentication: 2–3 weeks
  • Full solution with Redis, tests, and documentation: 3 to 5 weeks

Exact timeline depends on protocol complexity and required load. We will assess your project for free—contact us. Order WebSocket API development, and we guarantee a stable connection even under peak loads.

WebSocket protocol is described in RFC 6455.

Development of Real-Time Systems: WebRTC, SSE, WebSocket

We know how painful it is when polling kills the server. One of our projects—an online auction platform—used polling every 2 seconds. Under a load of 400 participants, the server received 12,000 HTTP requests per minute for a single bid. 90% of responses were empty. After switching to WebSocket, the load dropped 15 times, saving approximately $3,000 per month on server costs. Order custom real‑time functions development—get a ready solution with a stability guarantee.

Implementing real‑time in production is not just a library. We design the architecture for load, scenarios, and budget. Below is a breakdown of key solutions with examples.

Choosing the Right Real-Time Transport for Your Project

Three Real-Time Transports: When to Choose Which

Server‑Sent Events work over regular HTTP/1.1 or HTTP/2. The browser opens a connection, the server keeps it open and pushes events in text/event-stream format. Automatic reconnection is built-in—no need for reconnect logic. Limitation: server → client only. Ideal for notifications, progress of long tasks, live feeds.

WebSocket is a full‑duplex channel after an HTTP Upgrade handshake. Browser and server exchange frames in both directions. Suitable for chats, collaborative editing, games, trading terminals. Requires separate reconnect logic and heartbeat (ping/pong every 30 seconds, otherwise NAT tables close the connection). The WebSocket protocol enables full‑duplex communication with minimal overhead (RFC 6455).

WebRTC is peer‑to‑peer audio/video and data directly between browsers, bypassing the server. A server is needed only for signaling (STUN/TURN for NAT traversal). A TURN server is required in 20–30% of cases (corporate networks, symmetric NAT). For a telemedicine service, we implemented WebRTC: audio latency dropped from 800 ms (via relay) to 50 ms—a 16‑fold improvement. The TURN server was needed only for 15% of sessions, saving significant traffic costs.

How to Properly Choose a Transport: Step-by-Step Guide

  1. Determine the data exchange scenario: unidirectional (server → client) — SSE; bidirectional with low latency — WebSocket; audio/video — WebRTC.
  2. Evaluate latency requirements. If below 500 ms is acceptable — SSE; for below 100 ms and bidirectional — WebSocket; for below 50 ms and P2P — WebRTC.
  3. Check the infrastructure budget. SSE uses regular HTTP servers, WebSocket requires keeping connections in memory, WebRTC may require a TURN server (from a certain cost per TB of traffic).
  4. Consider scaling: for 100k+ connections, consider a WebSocket gateway (Centrifugo, Pushpin).
Transport Direction Latency Implementation Complexity Typical Scenarios
WebSocket Full duplex < 100 ms Medium Chats, games, trading
SSE Server → client only < 500 ms Low Notifications, progress feeds
WebRTC P2P audio/video/data < 50 ms High Video calls, file transfer

What Is CRDT and How Is It Better Than Operational Transformation?

Collaborative editing is not just "whoever writes last wins". Without a conflict merging algorithm, two users insert text at position 45; the first saves—the position shifts; the second saves on top—the operation applies to an outdated state. Text gets duplicated or lost.

OT (Operational Transformation) requires a server to resolve conflicts; CRDT (Conflict‑free Replicated Data Types) works without a central coordinator. Yjs is the most mature CRDT library for the browser. It integrates with ProseMirror, TipTap, CodeMirror, Monaco Editor. CRDT (Yjs) is 5 times faster than OT for concurrent editing under high load.

Library comparison for collaborative editing

Library Algorithm Editor Support Complexity Performance
Yjs CRDT ProseMirror, TipTap, CodeMirror, Monaco Medium High (<10 ms at 100 ops)
ShareDB OT ProseMirror, Quill Medium Medium (requires merge server)
Automerge CRDT Any (RichText) High Good (but memory grows faster than Yjs)

Issue: the Yjs document size grows due to operation history. Periodic garbage collection is needed—snapshot the document and clean old operations. Without it, a document worked on for a year may weigh 50 MB.

WebSocket Heartbeat Example (Node.js)
const ws = new WebSocket('wss://example.com');
let pingInterval;

ws.on('open', () => {
  pingInterval = setInterval(() => {
    ws.ping();
    setTimeout(() => {
      if (ws.readyState === WebSocket.OPEN) ws.terminate();
    }, 5000);
  }, 25000);
});

ws.on('close', () => clearInterval(pingInterval));

Common Mistakes in Real-Time Implementation and How to Avoid Them

Typical Mistakes in Real‑Time Implementation

Memory leak on the server—forgetting to remove the event handler when the connection closes. On Node.js, heap grows ~1 MB/hour. EventEmitter warns about 10+ listeners, but it's not always noticed.

Thundering herd on reconnect. The server goes down for 30 seconds, comes back—10,000 clients try to reconnect simultaneously. Exponential backoff with jitter is mandatory: delay = Math.min(baseDelay * 2^attempt + random(0, 1000), maxDelay).

Lack of connection lost indication. WebSocket doesn't always notify about disconnection (e.g., phone enters a tunnel). Heartbeat solves the problem.

Work Process

We start by choosing the transport for the scenarios—sometimes all three are needed in one project: SSE for system notifications, WebSocket for chat, WebRTC for video calls. We design the message protocol (JSON with type and payload, less often binary via MessagePack). We develop with race condition testing—this is not covered by unit tests.

Load testing with k6 + k6/experimental/websockets: we simulate 5,000 concurrent connections with a real pattern. Our engineers are certified in WebSocket and WebRTC, guaranteeing 99.9% stability.

What's Included in the Delivery

  • Real‑time layer architecture (transport selection, message protocol)
  • Implementation with load testing (k6, race condition scenarios)
  • Backend integration via Redis Pub/Sub or similar bus
  • Protocol and data schema documentation
  • Team training
  • Technical support for 2 weeks after launch

Why Centrifugo May Be More Cost-Effective Than Socket.io?

Socket.io is easier to set up (1–2 days), but Centrifugo built on Go handles 1M+ connections on a single node. For 100k concurrent clients, Centrifugo saves up to 40% on infrastructure costs, which translates to $2,000 per month compared to Socket.io. Get a consultation—we'll help you choose the stack for your load.

Timeline

  • Basic WebSocket chat or notifications on top of existing API: 1–3 weeks.
  • Collaborative editor with Yjs and persistence: 4–8 weeks.
  • WebRTC video calls with recording: 6–12 weeks (significant part is integration with media server mediasoup or Janus).

Contact us to evaluate your project. Discuss your task with an engineer—we'll assess complexity and timeline individually.