Setup Access Control

To configure access control for your channel:

Note: You should have a channel created before configuring access control. Access control applies only to subscribers. Publishers are authenticated through the Catalyst SDK or the REST API and do not require access control configuration.
  1. Select an access control type during channel creation or from the Access Control section.

Use this when subscribers are authenticated users in Catalyst Authentication with predefined roles.

  1. Select User Roles.

  2. Select one or more roles from the dropdown menu. Select user roles for channel access control

  3. Click Create or Update.

Only users belonging to the selected roles can subscribe to the channel. When a role is removed, subscribers with that role lose access immediately. When a role is granted, users with that role can subscribe immediately.

Note: To create new roles, refer to the Catalyst Authentication User Roles documentation.

Use this when you need custom authentication logic beyond role-based access (SSO, session-based connections, anonymous users, or custom criteria).

  1. Create an Advanced I/O function that handles subscriber authentication:
copy
module.exports = async (req, res) => {
    const { userId, connectionName } = req.body;
    
    // Your custom validation logic
    const isAuthorized = await yourCustomValidationLogic(userId);
    
    if (isAuthorized) {
        res.status(200).json({ approved: true });
    } else {
        res.status(403).json({ approved: false, reason: "Unauthorized" });
    }
};

The function must accept connection requests, perform validation logic, and return approval or rejection.

  1. Select Custom Logic.

  2. Select your Advanced I/O function from the dropdown. If the function doesn’t exist, click Create new Advanced I/O function to create one first. Select custom logic function for access control

  3. Click Create or Update.

Note: Only Advanced I/O functions are supported. Ensure the function is deployed and available in your project before configuring it.

Manage Subscriber Connections

After access control is configured, navigate to the Manage Connections section in the Access Control tab to view all subscribers.

List of subscriber connections in Manage Connections

Each connection displays:

Field Description
Connection Name Unique identifier for the subscriber connection (generated during token pair creation)
User Type Type of user (App User or Custom User) based on access control configuration
Status Current connection state: Active, Inactive, or Blocked

To block a subscriber:

  1. Locate the subscriber connection.
  2. Click the three-dot menu icon.
  3. Select Block. Block subscriber from three-dot menu

Blocking terminates the active connection immediately.

To delete a subscriber connection:

  1. Locate the subscriber connection.
  2. Click the three-dot menu icon.
  3. Select Delete.
  4. Confirm deletion in the dialog.

Last Updated 2026-10-08 12:04:32 +0530 IST