Agent skill

Relay Transport

by openchamber in openchamber/openchamber

A skill your agent uses when adding or changing OpenChamber WebSocket, SSE, streaming, realtime endpoints, shared UI sockets, runtime transport internals, private relay behavior, or files under the…

MITAuto-check passedBackend & APIs

Install Relay Transport

skills CLI
$ npx skills add openchamber/openchamber --skill relay-transport -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openchamber/openchamber relay-transport --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openchamber/openchamber.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/relay-transport .claude/skills/relay-transport && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
relay-transport
GitHub stars
11k
Token cost
~1.8k tokens
SKILL.md length
923 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when adding or changing OpenChamber WebSocket, SSE, streaming, realtime endpoints, shared UI sockets, runtime transport internals, private relay behavior, or files under the…

  • Works in 5 steps: Open it via openRuntimeWebSocket… → Add the path to BOTH allowlists (they… → Mint the URL token before connecting.… → …
  • Changing OpenChamber WebSocket
  • SKILL.md covers Overview, The core mental model, WebSocket Endpoint Branch and Wire Format And Codec Branch, plus 3 more sections
  • Calls bun and node

What it does

Relay Transport is an agent skill from openchamber/openchamber. Use when adding or changing OpenChamber WebSocket, SSE, streaming, realtime endpoints, shared UI sockets, runtime transport internals, private relay behavior, or files under the UI/server relay modules.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: opencode

It sits in Backend & APIs, covering Realtime and WebSockets. The repository describes itself as: Agentic Development Environment based on OpenCode AI agent. The licence is MIT.

When your agent uses it

  • Changing OpenChamber WebSocket
  • Realtime endpoints
  • Shared UI sockets
  • Runtime transport internals

Example prompts

  • “/relay-transport”

Requirements

  • Compatibility (from SKILL.md): opencode

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Open it via openRuntimeWebSocket (packages/ui/src/lib/relay/runtime-socket.ts), never new WebSocket(...) directly. A raw new WebSocket…
  2. Add the path to BOTH allowlists (they are separate and both required)
  3. Mint the URL token before connecting. Call refreshRuntimeUrlAuthToken() and build the URL through the resolver's websocket(...) so…
  4. Do not touch origin handling. The server rejects WS upgrades whose Origin it does not trust. Over the tunnel the host dials loopback and…
  5. Test over the relay, not just direct/desktop. A new WS may be the first WebSocket the mobile client runs through the tunnel (events are…

What it can do on your machine

Read from SKILL.md and the folder at commit ea1182c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    opencode

    From compatibility in the SKILL.md frontmatter.

Context cost

Relay Transport loads about 1.8k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 923 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openchamber/openchamber at commit ea1182c, republished under its MIT licence (© openchamber). 923 words, ~1,826 tokens.

Download SKILL.mdSave it as .claude/skills/relay-transport/SKILL.md (or your agent's skills folder).
name
relay-transport
description
Use when adding or changing OpenChamber WebSocket, SSE, streaming, realtime endpoints, shared UI sockets, runtime transport internals, private relay behavior, or files under the UI/server relay modules.
compatibility
opencode
license
MIT

Overview

OpenChamber has a private relay: a client (mobile app, browser, another desktop) reaches a user's instance through an OpenChamber-hosted relay over an end-to-end encrypted tunnel. All of the app's traffic — many HTTP requests, the event stream (SSE), and WebSockets (terminal, dictation) — is multiplexed and encrypted through one connection per client.

Architecture overview: packages/web/server/lib/relay/DOCUMENTATION.md. Code: packages/ui/src/lib/relay/ (client + shared, TS) and packages/web/server/lib/relay/ (host, JS).

Load ui-api-decoupling when the change adds or alters a shared runtime API, URL/auth contract, bridge, proxy, or runtime-switch behavior. This skill owns relay mechanics; ui-api-decoupling owns the shared UI/runtime boundary.

Why this skill exists: relay bugs do not show up in normal testing. The event stream is SSE (which behaves differently from WebSockets), so a new WebSocket feature is often the first real WebSocket to cross the tunnel on mobile — and it fails there while working everywhere else. We have fixed the same class of bug across several iterations. The rules below are those lessons.

The core mental model

  • The tunnel is transparent. A feature should reach the server through the shared runtime transport (runtimeFetch, openRuntimeWebSocket) and never know whether it is direct or relayed. If a feature constructs its own fetch/WebSocket against a runtime URL, it bypasses the tunnel and breaks in relay mode.
  • Three transports behave differently over the tunnel:
    • HTTP and SSE authenticate with the client's bearer token (a header). They "just work" through the tunnel for any allowlisted /api/*, /auth/*, /health path.
    • WebSockets cannot send headers. They authenticate with a short-lived URL-scoped token (oc_url_token) that must be minted first and passed as a query parameter. This is the source of most relay WS bugs.

WebSocket Endpoint Branch

Adding a new WS endpoint (or porting one, e.g. the planned terminal port) requires ALL of these, or it breaks over the relay:

  1. Open it via openRuntimeWebSocket (packages/ui/src/lib/relay/runtime-socket.ts), never new WebSocket(...) directly. A raw new WebSocket against a runtime URL fails in relay mode (the resolver yields a tunnel-virtual/custom-scheme URL the platform rejects — surfaced as "The string did not match the expected pattern").
  2. Add the path to BOTH allowlists (they are separate and both required):
    • Host tunnel dispatcher: ALLOWED_WS_PATHS in packages/web/server/lib/relay/tunnel-host.js.
    • URL-token auth gate: isUrlAuthWebSocketPath in packages/web/server/lib/ui-auth/ui-auth.js (otherwise the oc_url_token is refused for that path → 401).
  3. Mint the URL token before connecting. Call refreshRuntimeUrlAuthToken() and build the URL through the resolver's websocket(...) so oc_url_token is appended. SSE/HTTP do not need this; WS does.
  4. Do not touch origin handling. The server rejects WS upgrades whose Origin it does not trust. Over the tunnel the host dials loopback and presents the loopback origin (http://127.0.0.1:<port>), which the server trusts as same-origin — this already covers every allowlisted WS path. Never reintroduce reliance on window.location.origin: in the iOS WKWebView it is "null"/empty for the custom scheme, so forwarding it produces a 403.
  5. Test over the relay, not just direct/desktop. A new WS may be the first WebSocket the mobile client runs through the tunnel (events are SSE-locked on Capacitor). Passing on desktop or a direct connection proves nothing about the relay path.
Show full SKILL.md (417 more words)Show less

Wire Format And Codec Branch

  • Two implementations must stay byte-compatible. The E2EE and framing exist as TS (packages/ui/src/lib/relay/{crypto,handshake,tunnel-codec}.ts, normative) and a JS host mirror (packages/web/server/lib/relay/{e2ee,tunnel-codec}.js). Any wire-format, frame-type, handshake, or batching change must update both and keep packages/web/server/lib/relay/cross-compat.test.js green.
  • Frame types live in protocol.ts and must match across protocol.ts, tunnel-codec.ts, and tunnel-codec.js. Adding a frame type without mirroring it corrupts the stream on one side.
  • Frame batching is capability-negotiated in the handshake with a legacy fallback, so mixed client/host app versions still interoperate. Preserve the negotiation and the single-frame fallback; do not make batching unconditional.
  • The encrypted-frame counter/IV is per-direction and strictly increasing. One encrypted WS message = one encrypt call = one counter tick. Keep encrypt+send serialized per direction; do not reorder or parallelize it.

Runtime Transport Branch

  • Relay mode routes through runtime-switch (activates the tunnel singleton), runtime-fetch (routes runtime requests through it), runtime-url/runtime-socket (tunnel-backed URLs/sockets), and runtime-auth (mints the URL token through the tunnel). When refactoring any of these, preserve the relay branch and the direct-URL/Electron-realtime-proxy branches — they must remain byte-identical in behavior for non-relay runtimes.
  • The host dispatcher never injects credentials. Tunneled requests carry the client's own token; the server authenticates them. Do not add host-side auth shortcuts, and do not trust loopback source address as authentication (relay traffic arrives at loopback but represents remote clients).

Reconnect Branch

For indefinite SSE/WebSocket reconnect loops:

  • Use exponential backoff based on consecutive failures, not a constant short delay.
  • Use the long backoff cap while navigator.onLine is false or document.visibilityState is hidden.
  • Treat permanent 4xx responses as long-backoff failures; keep 408 and 429 retryable.
  • Make waits interruptible by online, visibility becoming visible, and the pipeline abort signal.
  • Reset failure state only after a genuinely healthy connection.

Blind short retries on hidden, offline, unauthorized, or stale-path clients waste battery and flood server logs.

Verification

  • Exercise the real auth and origin gates. An end-to-end test whose stub server accepts any WS upgrade will pass while the real server rejects it — this is precisely how the origin-check bug shipped. When writing a relay integration test, mirror the real gates (ensureSessionToken via oc_url_token, isRequestOriginAllowed) or run against the real server pieces.
  • Run relay tests per file (bun test <file>); the suite has order sensitivity.
  • Validate both sides: packages/ui type-check/lint, and node --check on changed JS host files.

Completion requires every applicable branch above: WS path allowlists/auth/origin and real relay exercise; mirrored TS/JS wire changes with cross-compat coverage; preserved direct and relay runtime branches; or reconnect pacing under offline, hidden, permanent-failure, recovery, and abort conditions.

© openchamber, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/relay-transport of openchamber/openchamber.

Open the folder on GitHubat commit ea1182c

Compare with similar skills

Relay Transport next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Relay Transport compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Relay Transport this skillopenchamber/openchamber11k—~1.8kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
Gemini Live API Devgoogle-gemini/gemini-skills4.3k—~4.6kAutomated safety check: PassApache-2.0
Broker Integrationmarketcalls/openalgo2.8k—~4.7kAutomated safety check: NotesAGPL-3.0
Trigger.dev Realtimepapermark/papermark9.2k—~1.7kAutomated safety check: PassCustom licence

Similar skills

  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Broker Integration

    marketcalls/openalgo

    Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.

    2.8k GitHub stars~4.7k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Trigger.dev Realtime

    papermark/papermark

    Shows how to subscribe to Trigger.dev task runs from the backend and from React for progress indicators, live dashboards, AI response streams and approval waits.

    9.2k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Spider King

    aoyunyang/spider-king-skill

    Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.

    509 GitHub stars~7.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from openchamber/openchamber

All 21 skills in this repo
  • Theme System

    openchamber/openchamber

    A skill your agent uses when creating or modifying OpenChamber UI components, styling, colors, buttons, visual states, themes, or icons.

    11k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • UI API Decoupling

    openchamber/openchamber

    A skill your agent uses when creating or modifying OpenChamber shared UI data access, OpenCode SDK calls, RuntimeAPIs, runtime fetch/auth/URLs, authenticated browser assets, bridges/proxies, runtime…

    11k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Drag To Reorder

    openchamber/openchamber

    A skill your agent uses when implementing or modifying OpenChamber sortable or drag-to-reorder behavior, especially @dnd-kit, touch/mobile interactions, variable-width items, or wrapping layouts.

    11k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Locale UI Patterns

    openchamber/openchamber

    A skill your agent uses when creating or modifying OpenChamber UI text, labels, buttons, placeholders, aria labels, empty states, toasts, dialogs, settings copy, navigation labels, or any…

    11k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Performance Engineering

    openchamber/openchamber

    A skill your agent uses when implementing or reviewing code on interaction, render, event, polling, synchronization, list-processing, store-selector, cache, indexing, or high-volume data paths; when…

    11k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Serve Sim

    openchamber/openchamber

    A skill your agent uses when working with the OpenChamber iOS Simulator app without opening Xcode - boot/install/launch the Capacitor iOS app, start a browser stream, tap/type/gesture/rotate…

    11k GitHub stars~619 tokensUpdated today
    Auto-check passed

Categories

Questions about Relay Transport

What does Relay Transport do?

A skill your agent uses when adding or changing OpenChamber WebSocket, SSE, streaming, realtime endpoints, shared UI sockets, runtime transport internals, private relay behavior, or files under the…. Relay Transport is an agent skill from openchamber/openchamber. Use when adding or changing OpenChamber WebSocket, SSE, streaming, realtime endpoints, shared UI sockets, runtime transport internals, private relay behavior, or files under the UI/server relay modules.

When should I use Relay Transport?

Relay Transport fits situations like: changing OpenChamber WebSocket; realtime endpoints; shared UI sockets; runtime transport internals.

How do I install Relay Transport in Claude Code?

Run `npx skills add openchamber/openchamber --skill relay-transport -a claude-code`. Or copy the skill folder (.agents/skills/relay-transport in openchamber/openchamber) into .claude/skills/relay-transport in your project. Claude Code loads it when a task matches its description.

How do I install Relay Transport in Codex?

Run `npx skills add openchamber/openchamber --skill relay-transport -a codex`. Or copy the skill folder (.agents/skills/relay-transport in openchamber/openchamber) into .agents/skills/relay-transport in your project. Codex loads it when a task matches its description.

Can I use Relay Transport in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openchamber/openchamber --skill relay-transport -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/relay-transport, .gemini/skills/relay-transport, .github/skills/relay-transport and .opencode/skills/relay-transport in your project.

What does Relay Transport need to run?

Going by SKILL.md and its folder, Relay Transport needs the command-line tools its instructions call (bun and node). Compatibility (from SKILL.md): opencode.

Does Relay Transport access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Relay Transport safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Relay Transport use?

Relay Transport is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Relay Transport use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Relay Transport?

Skills that share tags, products or a category with Relay Transport: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Use Yaak (mountain-loop/yaak, 19k stars), Gemini Live API Dev (google-gemini/gemini-skills, 4.3k stars) and Broker Integration (marketcalls/openalgo, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Relay Transport?

openchamber (a GitHub organization) maintains it in openchamber/openchamber, which has 11,359 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 10, 2026.

Source: openchamber/openchamber on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.