http1. WebSockets don’t work with h2c.
Connect with wss
Connect to any hostname of the , automatic or custom, withwss://. Plain ws:// fails: it gets a 308 redirect to HTTPS, and WebSocket clients don’t follow redirects.
Policies check the handshake
The opening handshake is a normal HTTP request. Your gateway policies run on it, so a handshake that fails API key authentication, a rate limit, or a firewall rule is rejected before the connection opens. Your server gets the same headers as any other request, includingX-Unkey-Principal when a key was verified. See Request lifecycle and headers.
How long connections last
Once your server accepts the upgrade, the connection stays open as long as both ends keep it. The 15 minute request timeout doesn’t apply. We don’t limit connection length, frame size, or the number of connections. Your app sets those limits. The handshake shows up in the request log when the connection closes, with status101 and a latency covering the whole connection. A logging policy doesn’t save the messages.
Connections and instances
Each connection goes to a random instance, so two connections from the same client can land on different instances. Keep state on the connection or in a shared store, not in one instance’s memory. If no instance can take the connection, the client gets a503 right away. When a deployment is replaced or scaled down, the instance gets the shutdown signal and its connections close when the process exits. Make your clients reconnect when a connection closes. The new connection goes to a running instance of the current deployment.