Skip to content

The latest @livekit/protocol breaks token validation #893

Description

@KazimirPodolski

Describe the bug

After I bumped versions of my server stuff, livekit-server-sdk's dependency @livekit/protocol went from 1.44.0 to 1.45.3. Now I'm getting an error trying to connect to OpenVidu with a generated (custom) token:

Uncaught (in promise) ConnectionError: could not establish signal connection: invalid token: eyJhbGciOiJIUzI1NiJ9.eyJuYW1lIjoiTXIuIEZpcnN0IFR1dG9yIEREUyIsInZpZGVvIjp7InJvb20iOiIwMTlkYWY3My1kN2MxLTczNzEtYTU2YS0xODczNGZkOGZiNzUiLCJyb29tSm9pbiI6dHJ1ZSwicm9vbUFkbWluIjp0cnVlLCJyb29tUmVjb3JkIjp0cnVlLCJjYW5QdWJsaXNoIjp0cnVlLCJjYW5QdWJsaXNoRGF0YSI6dHJ1ZSwiY2FuU3Vic2NyaWJlIjp0cnVlLCJjYW5VcGRhdGVPd25NZXRhZGF0YSI6dHJ1ZX0sInJvb21Db25maWciOnsibmFtZSI6IjAxOWRhZjczLWQ3YzEtNzM3MS1hNTZhLTE4NzM0ZmQ4ZmI3NSIsImVtcHR5VGltZW91dCI6NjAwLCJkZXBhcnR1cmVUaW1lb3V0Ijo2MDAsIm1heFBhcnRpY2lwYW50cyI6MCwibWluUGxheW91dERlbGF5IjowLCJtYXhQbGF5b3V0RGVsYXkiOjAsInN5bmNTdHJlYW1zIjpmYWxzZSwiYWdlbnRzIjpbXSwibWV0YWRhdGEiOiJ7XCJ0YXJnZXRJZFwiOlwiMDE5ZGFmNzMtZDdjMS03MzcxLWE1NmEtMTg3MzRmZDhmYjc1XCIsXCJ0YXJnZXRUeXBlXCI6XCJsZXNzb25cIixcInVzZXJQcm9maWxlSWRcIjpcIjAxOWRhYzFhLTZmYjgtNzliYy1hOGY0LWQ5MzA2N2ZmMWE2MFwiLFwiZW52XCI6XCJsb2NhbGRldlwifSIsInRhZ3MiOnt9fSwiaXNzIjoiRzhaZjNRSlhkeVl1c2dvZklxWmtocWw0ZnZPajFwbG8iLCJleHAiOjE3NzY3OTM3MzcsIm5iZiI6MTc3Njc3MjEzNywic3ViIjoiMDE5ZGFjMWEtNmZiOC03OWJjLWE4ZjQtZDkzMDY3ZmYxYTYwIn0.CKT6bxxIWMhCGKeoywomXB3Ag1JaMx9khXIzciJ-kSU, error: proto: (line 1:357): unknown field "tags"

Corresponding OpenVidu log entry:

2026-04-21T11:48:58.376Z    WARN    livekit service/utils.go:54     error handling request  {"status": 401, "method": "GET", "path": "/rtc/v1/validate", "error": "invalid token: eyJhbGciOiJIUzI1NiJ9.eyJuYW1lIjoiTXIuIEZpcnN0IFR1dG9yIEREUyIsInZpZGVvIjp7InJvb20iOiIwMTlkYWY3My1kN2MxLTczNzEtYTU2YS0xODczNGZkOGZiNzUiLCJyb29tSm9pbiI6dHJ1ZSwicm9vbUFkbWluIjp0cnVlLCJyb29tUmVjb3JkIjp0cnVlLCJjYW5QdWJsaXNoIjp0cnVlLCJjYW5QdWJsaXNoRGF0YSI6dHJ1ZSwiY2FuU3Vic2NyaWJlIjp0cnVlLCJjYW5VcGRhdGVPd25NZXRhZGF0YSI6dHJ1ZX0sInJvb21Db25maWciOnsibmFtZSI6IjAxOWRhZjczLWQ3YzEtNzM3MS1hNTZhLTE4NzM0ZmQ4ZmI3NSIsImVtcHR5VGltZW91dCI6NjAwLCJkZXBhcnR1cmVUaW1lb3V0Ijo2MDAsIm1heFBhcnRpY2lwYW50cyI6MCwibWluUGxheW91dERlbGF5IjowLCJtYXhQbGF5b3V0RGVsYXkiOjAsInN5bmNTdHJlYW1zIjpmYWxzZSwiYWdlbnRzIjpbXSwibWV0YWRhdGEiOiJ7XCJ0YXJnZXRJZFwiOlwiMDE5ZGFmNzMtZDdjMS03MzcxLWE1NmEtMTg3MzRmZDhmYjc1XCIsXCJ0YXJnZXRUeXBlXCI6XCJsZXNzb25cIixcInVzZXJQcm9maWxlSWRcIjpcIjAxOWRhYzFhLTZmYjgtNzliYy1hOGY0LWQ5MzA2N2ZmMWE2MFwiLFwiZW52XCI6XCJsb2NhbGRldlwifSIsInRhZ3MiOnt9fSwiaXNzIjoiRzhaZjNRSlhkeVl1c2dvZklxWmtocWw0ZnZPajFwbG8iLCJleHAiOjE3NzY3OTM3MzcsIm5iZiI6MTc3Njc3MjEzNywic3ViIjoiMDE5ZGFjMWEtNmZiOC03OWJjLWE4ZjQtZDkzMDY3ZmYxYTYwIn0.CKT6bxxIWMhCGKeoywomXB3Ag1JaMx9khXIzciJ-kSU, error: proto: (line 1:357): unknown field \"tags\""}

You can check out the JWT (no secrets there), apparently there is a new field in RoomConfiguration:

{
  ...
  "roomConfig": {
    ...
    "tags": {}
  }
}

Expected behavior
OpenVidu should accept and ignore unknown fields in the auth token.

Wrong current behavior
OpenVidu invalidates the token.

OpenVidu tutorial where to replicate the error
I think this test should fail if you update versions to the latest ones because it does new RoomConfiguration. I'll make a repro if that simpler path won't do.

OpenVidu deployment info
Commynity Single node on premises as explained in the docs.

Using https://demos.openvidu.io:4443 does NOT reproduce the issue.

Client device info (if applicable)

  • Brave 1.88.136 (Official Build) (64-bit) Chromium: 146.0.7680.164

Additional context
I see how this can be upstream problem with Livekit server not accepting tokens from slighly different version of it's protocol, but currently I don't know for sure. But for now it looks to me self-hosting OpenVidu via the installer and using Livekit Node SDK with it will always fail.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions