WebSockets
Authorization: Bearer or ?api_key= (browsers can’t set
headers). The protocol:
Architecture
Workers forbid cross-request socket I/O, so sockets live in the RealtimeHub Durable Object (apps/api/src/realtime/hub.ts). Fetch
handlers publish through hub.fetch(/publish); the hub broadcasts in its own
context. Without the REALTIME_HUB binding the route serves inline
(same-context only). Shard hubs per org when one gets hot.