Skip to content

Peer-to-peer option

By default every MOQOM session goes through a relay. For small private rooms, a direct mode will let media flow straight between participants’ devices, falling back to the relay whenever a direct path is unavailable.

Relay (default) Direct
Latency Detour via the relay Shortest path; largest gain on the same LAN or in the same city. Not yet measured
Who carries media Relay The participants’ devices only
What the relay sees Ciphertext in E2EE rooms Nothing — not even sizes and timing
Peers learn each other’s IP address No Yes
Server-side recording and moderation Possible in non-E2EE rooms Impossible
Fan-out Thousands of viewers Each extra peer costs the publisher a full upload
Works behind every NAT Yes About 90% with hole-punching, so relay fallback is required

The IP-address row decides where direct mode is allowed. Handing a viewer a creator’s home IP address is a stalking and doxxing risk, so direct mode will never be offered to an audience.

  • 1:1 calls and private rooms of up to about four participants.
  • Backstage between cohosts.
  • Only in end-to-end encrypted rooms, where server-side recording and moderation are already off.
  • Only when every participant opts in, with the IP exposure stated in your UI.

Never for public broadcast, never for viewers, and never when a recorder or safety watchdog is required in the room.

sequenceDiagram
    participant A as Alice
    participant R as MOQOM relay
    participant B as Bob
    A->>R: join (token)
    B->>R: join (token)
    R-->>A: media via relay
    R-->>B: media via relay
    Note over A,B: Both opted in, E2EE room, ≤ 4 participants
    A-)B: exchange candidate addresses (encrypted, via the room)
    A->>B: QUIC hole-punch, MOQT session
    B->>A: media direct
    Note over A,B: Relay subscription kept paused as fallback
    A--xB: network change / loss
    R-->>A: resume via relay, no gap
  1. Join as usual through the relay. Tokens, keys and room state work exactly as today, and media starts flowing through the relay immediately. Direct is an upgrade, never a precondition.
  2. Exchange candidates over the room, encrypted so the relay carries them but cannot read them.
  3. Hole-punch with QUIC NAT traversal and speak MOQT directly between the devices. Media encryption is identical on both paths.
  4. Verify each other with MOQOM-issued credentials, exactly as a relay would.
  5. Fall back without a gap on loss or a network change.
  6. Metered at a reduced rate — direct sessions use no relay egress but still consume a room, tokens and keys.
  • Carrier-grade NAT on cellular networks is where hole-punching fails most, so phone-to-phone calls on cellular will often stay on the relay.
  • If the measured gain over the relay is only a few milliseconds, direct mode will not ship.

Separately from media, MOQOM plans to offer its management surfaces — the relay admin port, the admin gRPC API for enterprise customers, and the link BYOC relays use to reach MOQOM — as dark services on an OpenZiti overlay, reachable only by enrolled identities with no open inbound ports. Media will stay on QUIC directly; viewers never need an overlay identity.