Skip to main content
Choose this option when your server must mint the participant token instead of giving Egma a LiveKit project key pair. The endpoint must return access to the requested room and arrange the named worker’s dispatch. The example below does both through LiveKit’s room configuration. For this authentication path, your endpoint owns the room lifecycle. It prepares the room, dispatches the requested worker, and cleans the room up after Egma leaves.

Create the endpoint

This example uses Python and FastAPI. Install its dependencies in a server project:
Set these environment variables on that server: Create token_server.py:
Start the server and expose this route through your HTTPS reverse proxy:
The endpoint preserves the requested worker and its test metadata in the token’s room configuration. Do not pre-create the room: LiveKit applies that configuration when the first participant creates it by joining. This follows LiveKit’s token endpoint contract. The endpoint and returned LiveKit address must resolve to public addresses. Use HTTPS for the endpoint and WSS or HTTPS for LIVEKIT_URL. These rules also apply to self-hosted Egma. For a private-network LiveKit server, use project credentials instead.

Connect Egma to the endpoint

In your agent repository, set LIVEKIT_TOKEN_ENDPOINT to the full public URL ending in /egma/livekit-token. Load the same EGMA_TOKEN_SECRET from your secret store. This command passes the authorization header through standard input:
For a text connection, use --modality chat after adding the worker’s text configuration. Use the returned connection ID to start a run. Check that the worker joins the egma-sim- room and receives any test metadata. Egma makes one token request per simulation. It allows 20 seconds for the response, does not follow redirects, and accepts a response body up to 64 KiB. It joins the room once with the participant token. A voice simulation publishes and subscribes to audio. A chat simulation joins as one text-only client: it publishes no media tracks, subscribes to no audio, and performs no audio decoding, speech-to-text, text-to-speech, recording, or voice processing. Egma waits 30 seconds for your worker to join and answer, then ends the simulation as agent_never_joined. Egma leaves when the conversation ends. It never deletes the room and never uses the token again, so your token endpoint owns cleanup for this room. Configure your worker to shut down when the caller leaves. A short empty-room timeout on your LiveKit project is one way to clean the room up.