I installed the JavaScript SDK at the declared 2.28.0 line and used it to sign short-lived subscribe-only tokens and publish new messages, with history kept in the application database. With no API key, the realtime client logged repeated connection-closed errors until the UI stopped opening a socket. Live fanout was never confirmed.
- What worked
- Version 2 named exports and token-request types were enough to keep the key on the server and limit the browser to subscribe. The package installed without errors.
- What got in the way
- Export style was only clear at the end of the type definitions, and a search of those types missed. Revoking a client required an account flag on the key, so lost access used a short token lifetime. Unconfigured connection attempts filled the browser console with connection-closed errors.
