Admin API overview
Your backend talks to MOQOM through two APIs at api.moqom.cloud. Both authenticate with a
backend API key. Neither is for devices: devices join with participant
tokens your backend mints.
| HTTPS billing API | Control-plane gRPC API | |
|---|---|---|
| For | Money, keys, usage, account | Rooms, moderation, tokens, events |
| Transport | JSON over HTTPS | gRPC over TLS (api.moqom.cloud:443) |
| Auth | Authorization: Bearer mqk_… |
Same key, as gRPC call credentials |
| SDKs | curl or any HTTP client |
moqom-go, moqom-rust |
| Out of credit | Still works | Still works; only MintClientToken is refused |
| Reference | Billing & keys REST API | Control-plane gRPC API |
The console at moqom.cloud/account uses the same billing API with the same key.
HTTPS billing API
Section titled “HTTPS billing API”| Method | Path | Auth | Purpose | Docs |
|---|---|---|---|---|
GET |
/v1/rates |
none | Public rate card | Reference |
GET |
/v1/public/stats |
none | Signup and active-tenant counts, cached 60 s | |
POST |
/v1/signup |
none | New tenant, first key, first checkout | Reference |
GET |
/v1/billing |
backend | Balance, status, this month’s spend, recent ledger | Reference |
GET |
/v1/billing/ledger |
backend | Up to 5,000 ledger entries, newest first (?limit=) |
Ledger entry kinds |
POST |
/v1/billing/checkout |
backend | Open a top-up checkout | Reference |
POST |
/v1/billing/portal |
backend | Stripe customer portal | Reference |
PUT |
/v1/billing/auto-top-up |
backend | Configure automatic top-ups | Reference |
PUT |
/v1/billing/spend-alerts |
backend | Monthly spend alert amounts | Guide |
PUT |
/v1/billing/spend-limit |
backend | Set or clear a monthly spend limit | Guide |
GET |
/v1/keys |
backend | List keys | Reference |
POST |
/v1/keys |
backend | Issue a key, shown once | Reference |
DELETE |
/v1/keys/{id} |
backend | Revoke a key | Reference |
POST |
/v1/keys/{id}/rotate |
backend | Replace a key with an overlap | Reference |
GET |
/v1/account/export |
backend | Data export of the account, for access requests | |
POST |
/v1/usage |
relay | Report self-hosted relay usage | Usage reporting API |
GET |
/v1/usage/summary |
backend | Usage by role and tier for ?from&to, beside Agora’s list price |
|
POST |
/v1/usage/estimate |
backend | Price a what-if scenario | |
POST |
/v1/migrate/agora/preview |
backend | Read your Agora projects and usage with credentials used once, and estimate the same minutes on MOQOM | |
POST |
/v1/stripe/webhook |
Stripe signature | Reserved for Stripe |
Conventions shared by every route (money in micro-dollars, unknown fields rejected, errors as
{"error": "…"}) are in Billing & keys REST API.
Control-plane gRPC API
Section titled “Control-plane gRPC API”Package moqom.admin.v1. Every call takes your tenant and, for writes, an actor that is
recorded in the audit trail.
| Service | RPCs | Covers | Guide |
|---|---|---|---|
Rooms |
CreateRoom, GetRoom, ListRooms, UpdateRoomPolicy, CloseRoom, ListParticipants, GetParticipant, AttachWatchdog, DetachWatchdog, ListWatchdogs |
Room lifecycle and policy, rosters, observers | Recording, E2EE |
Moderation |
Kick, Ban, Unban, ForceMute, Unmute, SetGrants, Spotlight, ListModerationLog |
Acting on participants, with an audit entry for each | Moderation |
Tokens |
MintClientToken, ListVerificationKeys |
Participant tokens for devices | API keys |
Events |
StreamRoomEvents |
A live stream of what happens in a room | Events, webhooks & billing |
Moderation and room administration are never blocked by credit or a spend limit: a tenant out of credit can still ban someone. Status codes are listed under Status codes and Error codes.
Device-facing endpoints
Section titled “Device-facing endpoints”These are not admin APIs, but sit beside them:
- Join HTTP endpoint:
POST /join, for deployments without their own backend. It never mints moderation rights. - Relays: devices connect with the participant token over QUIC or WebTransport. See Architecture overview.