Specifications
Protocol and transport
Section titled “Protocol and transport”| Protocol | IETF draft-ietf-moq-transport-19, own implementation in Rust and in Swift, written independently |
| Control messages | All 18 in draft-19 |
| Proposed extension | Relay hop limit (draft-elliottwave-moq-relay-hops-00) |
| Data plane | Object datagrams, subgroup streams, fetch streams with gap markers |
| Carriers | Raw QUIC and WebTransport (HTTP/3) on one UDP port |
| QUIC stack (relay) | quinn, vendored unmodified |
| QUIC stack (Apple) | Network.framework |
| Relay forwarding | Subgroup streams. Datagram forwarding not yet carried |
| Scale-out | Multiple SO_REUSEPORT sockets per relay |
Relay behaviour
Section titled “Relay behaviour”| Upstream deduplication | Each track pulled from the publisher once, whatever the audience |
| Slow viewers | Never allowed to stall the room or the publisher |
| Retention | Bounded by groups, bytes and seconds, evicting whole groups; can be disabled |
| Join | New subscribers fetch the group in progress, so playback starts on a keyframe |
| Publisher stop | Every viewer is told explicitly |
| Quotas | Per device and per user: sessions, subscriptions, announcements, watches and fetches |
| Observability | Separate admin port (off by default): Prometheus metrics, JSON snapshots of sessions, rooms and tracks, liveness and readiness, QUIC RTT / cwnd / loss, track-silence detection |
Security
Section titled “Security”| Transport | TLS 1.3, inherent in QUIC, on every media connection |
| Tokens | Ed25519-signed; tenant, room, grants and expiry checked against every namespace a request names |
| Token lifetime | 10 minutes default, 15 minutes maximum; renewed during a session without reconnecting |
| Device binding | Tokens are bound to a key generated on the device |
| Revocation | A ban ends the live session, not only the next join |
| Media encryption | SFrame (RFC 9605) over MOQT, AES-256-GCM by default, AES-128-GCM supported; payload-only, so relay caching and priority survive |
| E2EE key management | Shared-key rooms today; MLS for small rooms and sender keys for large ones designed, not built |
See Security.
Limits
Section titled “Limits”| Limit | Value |
|---|---|
| Client token lifetime | ≤ 15 minutes |
| Usage records per report | ≤ 5,000 |
| Usage record interval | ≤ 86,400 seconds |
| Billing request body | ≤ 1 MiB |
| Join request body | ≤ 4 KiB |
| Join rate | 30 / minute / credential |
| Signups | 5 / hour / client address |
| Top-up amount | $10.00 – $10,000.00 |
| Username | ≤ 4,096 UTF-8 bytes, NFC-normalised |
| Default stage slots / watchdog limit | 8 / 8 per room |
Platforms
Section titled “Platforms”| SDK | Floor | Status |
|---|---|---|
MoqomKit (Swift) |
iOS, iPadOS, macOS, visionOS, tvOS 26; Swift 6 strict concurrency | Available (binary core) |
moqom-go |
Go 1.23+ | Available |
moqom-rust |
Toolchain pinned in repo | Available |
| Web | Evergreen browsers with WebTransport | In progress, coming Q4 2026, possibly October |
| Android | — | In progress, coming Q4 2026, possibly October |
| Desktop | Windows, macOS, Linux | In progress, coming Q4 2026, possibly October |
| OBS plugin | OBS Studio | Scoped, work ongoing, release planned October 2026 |
Not yet, stated so nobody quotes it
Section titled “Not yet, stated so nobody quotes it”- Datagram forwarding at the relay
- Authentication on the relay admin port (which is why it is off by default)
- Global steering and a multi-replica control plane
- MLS / sender-key E2EE key management