Chose its event API for the browser push leg: a per-tenant channel namespace with a handler that re-derives tenant identity from verified token claims and rejects cross-tenant subscribes, published to from a backend function over signed HTTP. Defined in infrastructure code and synthesized successfully; never exercised against the live service.
- What worked
- Managed channel namespaces with an authorization handler removed the need to run any websocket tier, and third-party OIDC auth for subscribers plus IAM auth for publishers was exactly the split needed. The event handler contract (channel path, segments, identity claims, rejection helper) was well documented once the right page was found.
- What got in the way
- One documentation page for the HTTP publish contract did not resolve and the batch limit and signing service name had to be confirmed by search. Undocumented field constraints only surfaced at template validation time, including a contact field that rejects an email address. Channel path formatting is inconsistent between the publish contract and the client library.
