Media over QUIC · IETF draft-ietf-moq-transport-19

Real-time video on Media over QUIC.

Sub-60 ms glass-to-glass*, from light hitting one camera to pixels on another screen. MOQOM is a relay, a control plane and native SDKs, built on the IETF's new real-time media standard. You pay what delivery costs, and never more than Agora's list price.

Prepaid credit from $10. No contract and no sales call.

56ms*

median glass-to-glass latency, 720p30, two iPhones through a cloud relay, both directions at once

p95
70 ms
Fan-out
6,000 viewers
On
4 vCPU
Measured in lab, tested to 6,000 viewers on one 4-vCPU relay with zero loss; pending further load testing

* Built to scale: a Rust media plane and a Go control plane, each scaling out horizontally. Measured in lab, tested to 6,000 viewers on one 4-vCPU relay with zero loss; pending further load testing.

Speed · Security · Keys

Fast enough to talk. Locked down enough to trust.

Nothing is unhackable, and anyone who says so is selling something. What we can do is make every credential short-lived, scoped and tied to a device, and keep media encrypted the whole way.

  • Speed

    56–57 ms, camera to screen.*

    • Median glass-to-glass at 720p30, 1.25 Mbit/s, two iPhones through a cloud relay, both directions at once. p95 70 ms.
    • 6,000 viewers on one 4-vCPU relay with zero loss.* The last viewer gets the same stream as the first.
    • QUIC streams, so one lost packet doesn't stall everything behind it.
  • Security

    Encrypted on every hop. Optionally, end to end.

    • TLS 1.3 on every connection. QUIC doesn't offer a plaintext mode, so neither do we.
    • Per-frame end-to-end encryption (SFrame, RFC 9605, AES-256-GCM), opt-in per room. The relay forwards ciphertext it can't read or reorder.
    • Relays can't mint tokens, and they talk to the control plane over mutual TLS. Bans close live sessions, not just the next join.
  • Keys

    A stolen credential is worth very little.

    • Join tokens last 15 minutes at most, are scoped to one tenant, room and set of permissions, and are signed with Ed25519.
    • Each token is bound to the device it was issued to. On Apple devices that key lives in the Secure Enclave and can't be exported, so a copied token doesn't work anywhere else.
    • API keys are shown once, stored only as hashes, compared in constant time, revocable instantly, and prefixed mqk_ so secret scanners catch leaks.
Why MOQOM

Why MOQOM

  1. 01

    One stream for calls and broadcast

    The stream that carries a two-person call also reaches an audience of thousands. One protocol and one SDK, with no second product to move to when the audience grows.

  2. 02

    Sub-60 ms glass to glass*

    56–57 ms median from light hitting one camera to pixels on another screen: two iPhones through a cloud relay, both directions at once.

  3. 03

    Encrypted per frame

    Every frame can be encrypted on the device before it leaves. A 1080p keyframe takes about 54 µs* to encrypt, a sliver of a 33 ms frame budget.

* Built to scale: a Rust media plane and a Go control plane, each scaling out horizontally. Measured in lab, tested to 6,000 viewers on one 4-vCPU relay with zero loss; pending further load testing.

Key numbers

Fast for the people on the call. Efficient for the people paying for it.

Glass-to-glass counts everything a person experiences: capture, encode, network, buffer, decode and display. Fan-out is one relay and one track, and a size only counts if every viewer got every frame.

Measured in lab, tested to 6,000 viewers on one 4-vCPU relay with zero loss; pending further load testing
56–57 ms
median glass-to-glass*
70 ms
p95, every frame delivered*
6,000
viewers on one 4-vCPU relay, zero loss*
5.46 Gbit/s
egress from that one relay*
Glass-to-glass latency, two iPhones via a relay in Los Angeles (ms)Median 56 to 57 ms and p95 70 ms at 720p30; 61 ms with layout changes; 66 ms alongside an AR game; 69 ms at 540p60.0255075100720p30 · median56–57 ms720p30 · p9570 ms720p30 · layout changing every 8 s61 ms720p30 · alongside a shared AR game66 ms540p60 · 600 kbps69 ms60 ms
Glass-to-glass latency, two iPhones via a relay in Los Angeles (ms)
One 4-vCPU relay: egress with zero loss (Gbit/s)4,000 subscribers 3.57 Gbit/s; 4,500 4.11; 5,000 4.59; 5,500 5.04; 6,000 5.46.02464,000 subscribers3.57 Gbit/s4,500 subscribers4.11 Gbit/s5,000 subscribers4.59 Gbit/s5,500 subscribers5.04 Gbit/s6,000 subscribers5.46 Gbit/s
One 4-vCPU relay: egress with zero loss (Gbit/s)

56–57 ms median and 70 ms p95: iPhone 15 Pro and iPhone Air on home Wi-Fi, GCP relay in us-west2. Fan-out: GCP n2-standard-4, one publisher, one track, 6,000 is the largest size tested, not the ceiling. Not production SLAs. Full results →

* Built to scale: a Rust media plane and a Go control plane, each scaling out horizontally. Measured in lab, tested to 6,000 viewers on one 4-vCPU relay with zero loss; pending further load testing.

How it works

One publisher, one relay hop, thousands of viewers.

MoQ moves media as named tracks over QUIC, so a relay forwards it without decoding it. Your backend controls who joins. The relay handles the rest.

How MOQOM delivers a streamA publisher sends encrypted media over QUIC to a MOQOM relay. The relay pulls each track once and fans it out to many viewers. A control plane issues tokens and applies moderation to the relay.Control planetokens · rooms · moderationmutual TLSPublishercapture · encodeSFrame encryptMoQ / QUICMOQOM relayeach track pulled oncefanned out to every viewerjoins start on a keyframeViewer 1Viewer 2Viewer 3Viewer 4… thousands moreTLS 1.3 on every hop · tokens checked on every request · media payload encrypted with SFrame
  1. 1

    Your backend mints a token

    With the Go or Rust SDK, create a room, set its policy and mint a short-lived token naming the tenant, the room and exactly what this participant may do.

  2. 2

    The app joins over QUIC

    The client SDK connects to the relay over QUIC or WebTransport. Both use one UDP port, so the handshake is the only setup. Media starts on a keyframe.

  3. 3

    The relay fans out

    Each track is pulled from the publisher once, however large the audience. When the last viewer leaves, the relay stops pulling it.

For developers

Connect, join, and you're in the room.

The SDK uses async/await throughout and is Swift 6 strict-concurrency clean. Room state arrives as an async sequence, with no delegates to keep in sync.

  • The SDK renews the token before it expires, without reconnecting
  • Reconnects after a network change and restores the room's exact state
  • Raw frames and samples are available after decryption, for your own processing
  • Go and Rust SDKs for the server side, over gRPC
JoinRoom.swiftswift
import MoqomKit

let deviceKey = try DeviceKey.installed()   // lives in the Secure Enclave

// Your backend (moqom-go or moqom-rust) mints a short-lived token
// and tells the app which relay to use.
let (issued, relay) = try await backend.join(room: "standup", device: deviceKey)

let session = MoqomSession(
    transport: MoqtTransport.network(),
    credentials: DeviceCredentials(
        identity: ParticipantIdentity(username: try Username("ada"),
                                      device: try DeviceID("ada-iphone")),
        token: issued.token,
        deviceKey: deviceKey,
        expiresAt: issued.expiresAt,
        renew: { try await backend.join(room: "standup", device: deviceKey).0 }
    ),
    tenant: TenantID("acme")
)

try await session.connect(to: relay)
let room = try await session.join(room: RoomID("standup"))

for await state in session.states {
    print("session:", state)          // connecting, connected, reconnecting…
}
Security

Secure by default, not by add-on.

TLS 1.3 protects every media connection, because QUIC requires it. MOQOM adds protections on top of that, and they come built in rather than left for your application to write.

Encrypted media payloads

Every track can be SFrame-encrypted on the device (RFC 9605, AES-256-GCM by default). The relay forwards ciphertext and still caches and prioritises it.

Tokens bound to the device

Tokens can be bound to a key held in the device's Secure Enclave. A token copied off the phone is useless anywhere else.

Bans take effect mid-session

Kick or ban someone through the admin API and their open connection closes. You don't have to wait for their token to expire.

Tenant isolation by construction

Every token names a tenant, a room and a set of grants, and the relay checks them against every namespace a request touches.

Pricing

Pay what delivery costs. Never more than Agora.

Real scenarios, per hour, against Agora’s list price.

  • 31% less

    4K viewer

    One viewer watching 4K for an hour

    Agora
    $1.08
    MOQOM
    $0.75
  • 85% less

    Co-host at 540p

    A co-host seeing two others in 540p tiles, one hour

    Agora
    $0.54
    MOQOM
    $0.08

    Tiles are sent at the size they are shown, not full frame.

  • 67% less

    Co-host at 360p

    A co-host seeing two others in 360p tiles, one hour

    Agora
    $0.24
    MOQOM
    $0.08
  • 52% less

    Shared video call

    Four people in a gallery of 360p tiles, per person-hour

    Agora
    $0.24
    MOQOM
    $0.12
  • 8% less

    1080p viewer

    One viewer watching 1080p for an hour

    Agora
    $0.28
    MOQOM
    $0.25
  • 3% less

    720p viewer

    One viewer watching 720p for an hour

    Agora
    $0.119
    MOQOM
    $0.116

    The floor: never more than Agora less 1¢ per 1,000 minutes.

  • Fee only

    Self-hosted relays

    1,000 viewers at 720p for an hour, on your own relays

    Agora
    $119.40
    MOQOM
    $7.54

    Platform fee of $0.01/GiB; you pay your own hosting.

Per participant-hour, launch pricing, subject to change before general availability. Agora: Interactive Live Streaming list prices, October 2026. MOQOM figures from the published billing formula at default stream bitrates; actual charges follow measured bytes and seconds.

Your bill is our cloud cost plus a small markup and a per-GiB platform fee, capped at Agora's Interactive Live Streaming list price minus one cent per 1,000 minutes at every tier.

Ship real-time video this week.

Create an account, get an API key, add credit and join your first room.