Relay & sharing

Transport selection and fallback

Choose compatible connection paths without assuming every transport supports every feature.

2 min read User guide

A transport carries a particular workload

A transport is the way session data travels. Terminal connections, file transfers, forwarding, interactive sharing and one-to-many output have different requirements. A transport available for a broadcast is not automatically a supported raw SSH tunnel.

Option What it means
Automatic Chooses among compatible paths allowed by the client, service and session policy. It is not a guarantee of a direct peer connection.
Direct connection Uses an eligible direct path when network reachability and permission allow it.
WebSocket Uses an available WebSocket route. Service and destination policy still apply.
WebRTC, direct or TURN Uses a compatible peer transport. TURN is a relayed network path for WebRTC, not a separate terminal protocol.
Cloudflare SFU A service-assisted sharing or media option where supported, not a general SSH, file-transfer or forwarding transport.

Set a preference

  1. Open the transport controls for the relevant session or sharing workflow.
  2. Review Available on this client and the use case being configured.
  3. Choose Transport for this use case, or inherit the saved default.
  4. Decide whether to enable Allow a compatible fallback.
  5. Review Allow managed relay resources before permitting use of managed infrastructure.
  6. Connect and check the actual selected path or reported failure.

A saved preference cannot create a missing capability. The provider, release and session policy must also support it. An unavailable strict selection should fail rather than be treated as proof that the requested transport was used.

Current limitations

MoQ is not available in the current app transport selector. Do not plan SSH, file transfers or sharing around it. A Cloudflare SFU sharing capability likewise does not imply a supported SSH, SFTP, forwarding or remote-desktop byte stream.

The native Device-owned relay settings are separate from the sharing transport panel. Their Automatic mode attempts direct WebRTC, optionally customer-owned TURN, then authenticated WebSocket. Strict modes do not allow that fallback. The current native TURN path uses UDP; on a UDP-blocked network, use an allowed WebSocket route rather than assuming TURN over TCP is available. Authentication failures are not permission to downgrade security.

Privacy and cost considerations

Direct and relayed paths can have different network visibility and infrastructure costs. Only permit fallback you are comfortable using. Customer-operated relay resources and managed resources have different operators and accounting.

Transport choice does not replace host verification, room permissions or the Gateway trust boundary. Confirm the actual workload and route instead of choosing a transport solely because its name sounds faster.

Features vary by release, platform and connection route. Check availability before planning your setup.

Search the guides

Search runs in your browser.

Your search stays here. No account or external search service.