CubiCube Platform
Real-time sync for local-first applications
Kraken provides WebSocket-based real-time sync for Yjs documents. Each app gets isolated namespaces for data separation.
Before connecting, your app must be registered with Kraken (contact admin or use the API):
POST /api/apps
Authorization: Bearer YOUR_ADMIN_TOKEN
Content-Type: application/json
{
"app_id": "my-app",
"name": "My Application",
"allowed_origins": ["https://my-app.example.com"],
"owner_email": "dev@example.com"
}
const ws = new WebSocket(
'wss://kraken.helixpods.ai/doc/my-document?token=YOUR_ROOM_JWT'
);
Kraken uses a three-layer security model:
Each registered app gets a krk_โฆ API key (the platform master token is admin-only).
Your backend uses it to mint short-lived room JWTs via POST /api/tokens
(Authorization: Bearer krk_โฆ). A per-app key can only mint tokens for its own app.
Never send this key to a browser or use it on a WebSocket.
Short-lived HS256 JWTs minted from POST /api/tokens. Pass the JWT as:
?token=YOUR_ROOM_JWTAuthorization: Bearer YOUR_ROOM_JWTYour app's origin (domain) determines which namespace your rooms belong to.
This is automatic - Kraken reads the Origin header from WebSocket connections.
app claims. Per-app API keys and the master token are server-side
credentials โ only room JWTs reach the client.
Each registered app gets isolated data:
| Your Request | Internal Room ID |
|---|---|
/doc/readme from app-a.example.com |
app-a:readme |
/doc/readme from app-b.example.com |
app-b:readme |
Health check endpoint. No authentication required.
curl https://kraken.helixpods.ai/health
WebSocket endpoint for Yjs sync. Requires authentication.
wss://kraken.helixpods.ai/doc/my-room?token=TOKEN
List registered apps. Admin authentication required.
Register a new app. Master-token auth. Returns a one-time krk_ API key.
{
"app_id": "string (required)",
"name": "string (required)",
"allowed_origins": ["array of strings (required)"],
"description": "string (optional)",
"owner_email": "string (optional)"
}
Update an app. Master token, or the app's own key for its own record
({ "rotate_api_key": true } returns a fresh key).
Issue a room/app-scoped JWT for WebSocket sync. Auth: master token
(any app) or the app's own krk_ key (own app only).
{
"app_id": "string (required)",
"scope": "read | write (optional, default write)",
"room": "string (optional room constraint)",
"ttl_seconds": "number (optional, max 30 days)"
}
Server statistics. Master-token auth only.
List rooms. Master-token auth only.
import * as Y from 'yjs';
import { WebsocketProvider } from 'y-websocket';
const doc = new Y.Doc();
// Kraken routes document sync under /doc/{room}
const provider = new WebsocketProvider(
'wss://kraken.helixpods.ai/doc',
'my-document',
doc,
{ params: { token: 'YOUR_ROOM_JWT' } } // room JWT from your backend, never a server credential
);
provider.on('status', ({ status }) => {
console.log('Connection status:', status);
});
// Use your Yjs document
const text = doc.getText('content');
text.insert(0, 'Hello, collaborative world!');
import * as Y from 'yjs';
import * as syncProtocol from 'y-protocols/sync';
import * as encoding from 'lib0/encoding';
import * as decoding from 'lib0/decoding';
const doc = new Y.Doc();
const ws = new WebSocket('wss://kraken.helixpods.ai/doc/my-room?token=YOUR_TOKEN');
ws.binaryType = 'arraybuffer';
ws.onopen = () => {
// Send sync step 1
const encoder = encoding.createEncoder();
encoding.writeVarUint(encoder, 0); // message type: sync
syncProtocol.writeSyncStep1(encoder, doc);
ws.send(encoding.toUint8Array(encoder));
};
ws.onmessage = (event) => {
const decoder = decoding.createDecoder(new Uint8Array(event.data));
const messageType = decoding.readVarUint(decoder);
// Handle sync messages...
};
import { useEffect, useState } from 'react';
import * as Y from 'yjs';
import { WebsocketProvider } from 'y-websocket';
function useYjsDocument(roomName: string, roomJwtFromYourBackend: string) {
const [doc] = useState(() => new Y.Doc());
const [connected, setConnected] = useState(false);
useEffect(() => {
const provider = new WebsocketProvider(
'wss://kraken.helixpods.ai/doc',
roomName,
doc,
// Room JWT minted by YOUR backend via POST /api/tokens.
// Server credentials (per-app API key / master token) never reach the browser.
{ params: { token: roomJwtFromYourBackend } }
);
provider.on('status', ({ status }) => {
setConnected(status === 'connected');
});
return () => provider.destroy();
}, [roomName, doc]);
return { doc, connected };
}
Use @nexartis/kraken-sdk (repo: Nexartis/kraken-sdk) for SvelteKit and Svelte 5 applications requiring real-time document sync.
| Code | Meaning | Solution |
|---|---|---|
| 400 | Bad Request | Invalid room path |
| 401 | Unauthorized | Missing/invalid JWT or admin credential |
| 403 | Forbidden | Origin not registered |
| 426 | Upgrade Required | Use WebSocket, not HTTP |