Skip to content

Self-hosting relays

With a BYOC (bring your own cloud) licence you run MOQOM relays on your own machines while MOQOM’s control plane keeps handling rooms, moderation, tokens and billing. You pay for your own bandwidth and compute; MOQOM charges only a per-GiB platform fee.

flowchart LR
    subgraph Yours["Your infrastructure"]
        R1["Relay"]
        R2["Relay"]
    end
    subgraph MOQOM["MOQOM Cloud"]
        CP["Control plane"]
        B["Billing API<br/>POST /v1/usage"]
    end
    Clients(("Your users")) -- QUIC / WebTransport --> R1 & R2
    R1 & R2 -- "usage reports<br/>Bearer relay key" --> B
    CP -. "rooms · policy · moderation" .- R1 & R2

The relay is source-available under the Business Source License 1.1, which permits self-hosting for your own applications and users — including commercially — and prohibits only offering MOQOM to third parties as a competing hosted service. Each release converts to Apache-2.0 four years after it ships. Contact us through moqom.cloud for a BYOC licence and relay distribution.

Relay keys can only report usage. They cannot call the admin API, mint tokens, or read billing, so a leaked relay key cannot be used to take over rooms.

Terminal window
curl -sS https://api.moqom.cloud/v1/keys \
-H "Authorization: Bearer $MOQOM_API_KEY" \
-H 'Content-Type: application/json' \
-d '{"name":"relay-us-east-1","kind":"relay"}'
{
"key": {
"id": "5b7e0d2a9c3f1e48",
"name": "relay-us-east-1",
"kind": "relay",
"created_at": "2026-10-06T09:12:44Z"
},
"api_key": "mqk_5b7e0d2a9c3f1e48_Jt3k…"
}

Issue one key per relay (or per region) so you can revoke one without touching the others.

Each relay reports per-participant usage intervals to POST /v1/usage, authenticated with its relay key. Every record is charged to the key’s tenant, whatever the record says.

Terminal window
curl -sS https://api.moqom.cloud/v1/usage \
-H "Authorization: Bearer $MOQOM_RELAY_KEY" \
-H 'Content-Type: application/json' \
-d '{
"records": [{
"id": "relay-us-east-1:2026-10-06T09:15:00Z:alice/9f2c41e0",
"room": "live/42",
"participant": "alice/9f2c41e0",
"role": "host",
"tier": "hd",
"seconds": 60,
"egress_bytes": 52428800,
"ingress_bytes": 9437184
}]
}'
{
"charged": 1,
"duplicates": 0,
"unbilled": 0,
"total": { "micros": 488, "display": "$0.000488" },
"admitted": true
}

The full schema is in the Usage reporting API. The important rules:

  • id makes a report idempotent. Retry freely; a record whose id was already charged is counted in duplicates and charged nothing.
  • At most 5,000 records per request.
  • admitted tells your relay whether the tenant may still admit new sessions. When it turns false (balance spent, tenant suspended), stop admitting new sessions until it is true again. Existing sessions and moderation are unaffected.

Self-hosted usage is charged the platform fee on egress only — no bandwidth or compute cost from MOQOM, because you paid for those yourself — and is still capped by the same per-minute ceiling as cloud usage. See Self-hosted fee.

  • Rotate a relay key with POST /v1/keys/{id}/rotate: the replacement works at once and the old key keeps working for the overlap (24 hours by default), so relays never stop reporting.
  • Observability: the relay exposes Prometheus metrics, health/readiness and JSON session snapshots on a separate admin port, off by default and unauthenticated — bind it to a private interface only.
  • Ports: QUIC and WebTransport share one UDP port.