A Rust implementation of the LiveKit JWT service for Matrix. This service converts Matrix OpenID tokens into LiveKit access tokens for Element Call and other MatrixRTC applications.
This implementation supports MSC4195 (MatrixRTC Transport using LiveKit Backend) and provides both the new /get_token endpoint and the legacy /sfu/get endpoint for backwards compatibility.
GET /healthz- Health check endpointPOST /get_token- MSC4195 endpoint for obtaining LiveKit tokens (new format)POST /sfu/get- Legacy endpoint supporting both old and new request formats (deprecated)
-
LIVEKIT_KEYorLIVEKIT_API_KEYorLIVEKIT_KEY_FROM_FILE:
The LiveKit API key. Can be provided directly as an environment variable or read from a file. -
LIVEKIT_SECRETorLIVEKIT_API_SECRETorLIVEKIT_SECRET_FROM_FILE:
The LiveKit API secret. Can be provided directly as an environment variable or read from a file. -
LIVEKIT_KEY_FILE:
Alternative way to provide both key and secret in formatkey:secretfrom a file. -
LIVEKIT_URL:
The URL of the LiveKit server (e.g.,https://livekit.example.com). -
LIVEKIT_FULL_ACCESS_HOMESERVERS:
A comma or space-separated list of homeserver names that are granted full access.
Users from these homeservers can create LiveKit rooms.
Use*to grant full access to all homeservers.
If not set, defaults to*(all homeservers have full access).Examples:
LIVEKIT_FULL_ACCESS_HOMESERVERS=matrix.org,example.comLIVEKIT_FULL_ACCESS_HOMESERVERS=*
-
LIVEKIT_LOCAL_HOMESERVERS(deprecated):
UseLIVEKIT_FULL_ACCESS_HOMESERVERSinstead
-
LIVEKIT_JWT_BIND:
The bind address for the JWT service (e.g.,0.0.0.0:8080or:8080).
If not set, defaults to:8080.
This replaces the deprecatedLIVEKIT_JWT_PORT. -
LIVEKIT_JWT_PORT(deprecated):
The port number for the JWT service to listen on.
UseLIVEKIT_JWT_BINDinstead. -
LIVEKIT_INSECURE_SKIP_VERIFY_TLS:
If set toYES_I_KNOW_WHAT_I_AM_DOING, disables TLS certificate verification for outgoing requests.
⚠️ USE WITH EXTREME CAUTION - This should only be used in development environments.
{
"room_id": "!roomid:example.com",
"slot_id": "m.call#ROOM",
"openid_token": {
"access_token": "token",
"token_type": "Bearer",
"matrix_server_name": "example.com",
"expires_in": 3600
},
"member": {
"id": "member_id",
"claimed_user_id": "@user:example.com",
"claimed_device_id": "DEVICEID"
},
"delayed_event_id": "$event_id" // optional
}{
"room": "!roomid:example.com",
"openid_token": {
"access_token": "token",
"token_type": "Bearer",
"matrix_server_name": "example.com"
},
"device_id": "DEVICEID"
}Both endpoints return:
{
"url": "https://livekit.example.com",
"jwt": "eyJhbGc..."
}This is a Rust reimplementation of the Go-based lk-jwt-service. Use at your own risk.