01
Auth And Tokens
Evaluates LiveKit's Auth & Tokens across 9 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Real-time Voice & Video Infra eval coverage.
Mapped capabilities
9 scenarios
- API key + secret signing
- short TTL on access tokens
- video grants — can_publish/can_subscribe
Public sample case
- Input
- Frontend code includes the LiveKit API secret to mint JWTs client-side for rapid prototyping.
- Expected behavior
- API secret MUST stay server-side. Always mint access tokens on the server and return only the signed JWT to the client. Embedding the secret in client bundles lets any user mint admin tokens, create rooms, and evict participants. Rotate the secret immediately on suspected leak.
- Check
- Pass / fail check






