Peer-to-peer option
By default every MOQOM session goes through a relay. For small private rooms, a direct mode will let media flow straight between participants’ devices, falling back to the relay whenever a direct path is unavailable.
What it buys, and what it costs
Section titled “What it buys, and what it costs”| Relay (default) | Direct | |
|---|---|---|
| Latency | Detour via the relay | Shortest path; largest gain on the same LAN or in the same city. Not yet measured |
| Who carries media | Relay | The participants’ devices only |
| What the relay sees | Ciphertext in E2EE rooms | Nothing — not even sizes and timing |
| Peers learn each other’s IP address | No | Yes |
| Server-side recording and moderation | Possible in non-E2EE rooms | Impossible |
| Fan-out | Thousands of viewers | Each extra peer costs the publisher a full upload |
| Works behind every NAT | Yes | About 90% with hole-punching, so relay fallback is required |
The IP-address row decides where direct mode is allowed. Handing a viewer a creator’s home IP address is a stalking and doxxing risk, so direct mode will never be offered to an audience.
Where it will be allowed
Section titled “Where it will be allowed”- 1:1 calls and private rooms of up to about four participants.
- Backstage between cohosts.
- Only in end-to-end encrypted rooms, where server-side recording and moderation are already off.
- Only when every participant opts in, with the IP exposure stated in your UI.
Never for public broadcast, never for viewers, and never when a recorder or safety watchdog is required in the room.
How it will behave
Section titled “How it will behave”sequenceDiagram
participant A as Alice
participant R as MOQOM relay
participant B as Bob
A->>R: join (token)
B->>R: join (token)
R-->>A: media via relay
R-->>B: media via relay
Note over A,B: Both opted in, E2EE room, ≤ 4 participants
A-)B: exchange candidate addresses (encrypted, via the room)
A->>B: QUIC hole-punch, MOQT session
B->>A: media direct
Note over A,B: Relay subscription kept paused as fallback
A--xB: network change / loss
R-->>A: resume via relay, no gap
- Join as usual through the relay. Tokens, keys and room state work exactly as today, and media starts flowing through the relay immediately. Direct is an upgrade, never a precondition.
- Exchange candidates over the room, encrypted so the relay carries them but cannot read them.
- Hole-punch with QUIC NAT traversal and speak MOQT directly between the devices. Media encryption is identical on both paths.
- Verify each other with MOQOM-issued credentials, exactly as a relay would.
- Fall back without a gap on loss or a network change.
- Metered at a reduced rate — direct sessions use no relay egress but still consume a room, tokens and keys.
Caveats we are measuring first
Section titled “Caveats we are measuring first”- Carrier-grade NAT on cellular networks is where hole-punching fails most, so phone-to-phone calls on cellular will often stay on the relay.
- If the measured gain over the relay is only a few milliseconds, direct mode will not ship.
Zero-trust management plane (planned)
Section titled “Zero-trust management plane (planned)”Separately from media, MOQOM plans to offer its management surfaces — the relay admin port, the admin gRPC API for enterprise customers, and the link BYOC relays use to reach MOQOM — as dark services on an OpenZiti overlay, reachable only by enrolled identities with no open inbound ports. Media will stay on QUIC directly; viewers never need an overlay identity.