
# WebSocket Streams

WebSocket is a new protocol in HTML5 that enables full-duplex communication between clients and servers, allowing rapid bidirectional data transmission. Through a simple handshake, a connection can be established between client and server, enabling the server to actively push information to the client based on business rules. Its advantages include:

- Small header size (~2 bytes) during data transmission between client and server
- Both client and server can actively send data
- Eliminates the need for repeated TCP connection setup/teardown, conserving bandwidth and server resources
- Strongly recommended for developers to obtain market data, order book depth, and other information

| Domain          | WebSocket API                        | Recommended Use                  |
|-----------------|--------------------------------------|----------------------------------|
| Public Channel  | wss://ws-spot.weex.com/v3/ws/public  | Production public channel  |
| Private Channel | wss://ws-spot.weex.com/v3/ws/private | Production private channel |

## Connection

Connection Specifications:

- Connection limit: 300 connection requests/IP/5 minutes, maximum 20 concurrent connections per IP

- Subscription limit: 240 operations/hour/connection, maximum 100 channels per connection

- Public channel requirement: Public channel connections require header authentication(User-Agent)

- Private channel requirement: Private channel connections require header authentication

- To maintain stable and effective connections, we recommend:

- After successful WebSocket connection establishment, the server will periodically send Ping messages to the client. Public channels use the format: `{"event":"ping","time":"1693208170000"}`, while private channels use the format: `{"type":"ping","time":"1693208170000"}`. In both formats, "time" represents the server's timestamp. Upon receiving either message, the client should respond with the same Pong message: `{"method":"PONG","id":1}`. The server will actively terminate connections that fail to respond more than 10 times.

## Header Authentication for Private Channels

**User-Agent**:Client identification

**ACCESS-KEY**: Unique identifier for API user authentication (requires application)

**ACCESS-PASSPHRASE**: Password for the API Key

**ACCESS-TIMESTAMP**: Unix Epoch timestamp in milliseconds (expires after 30 seconds, must match signature timestamp)

**ACCESS-SIGN**: Signature string generated as follows:

The message (string to be signed) consists of: timestamp + requestPath

Example timestamp (in milliseconds):
`const timestamp = '' + Date.now()`

Where requestPath is `/v3/ws/private`

<strong>Signature Generation Process</strong>

1. Encrypt the message string using HMAC SHA256 with the secret key:
   - Signature = hmac_sha256(secretkey, Message)
2. Encode the Signature using Base64:
   - Signature = base64.encode(Signature)

## Subscription

Subscription Specification:
```json
{
  "method": "SUBSCRIBE",
  "params": ["BTCUSDT@ticker", "BTCUSDT@depth15"],
  "id": 1
}
```

## Unsubscription

Unsubscription Specification:
```json
{
  "result": true,
  "id": 1
}
```
