Set up a WebSocket listener with Foundry authentication

Use Foundry authentication to connect clients to a WebSocket server in a compute module. This listener uses your enrollment's primary domain; no dedicated subdomain is required.

Create and enable the listener

  1. In Data Connection > Listeners, select Create new listener and choose the Foundry WebSocket connector.
  2. Complete the configuration, turn on Enable listener, and copy the wss:// endpoint URL.
  3. Open the automatically created compute module from the listener's Configuration page, configure your container, and start the module.

If the connector is unavailable, contact Palantir Support. Your enrollment's ingress rules still apply.

Server address

Foundry forwards connections to ws://localhost:5000/ inside your compute module. Bind your server to 0.0.0.0 on port 5000 and accept WebSocket upgrades at /. This address is fixed; the listener's public endpoint path is not forwarded.

The client's token is not forwarded to your server. Configure the compute module's inputs and outputs for Foundry resource access. Exportable marking requirements still apply.

Connect a client

Connect to the copied wss:// endpoint with a Foundry token in the upgrade request:

Copied!
1 Authorization: Bearer <FOUNDRY_TOKEN>

For browser clients, pass the token as a WebSocket subprotocol:

Copied!
1 const socket = new WebSocket(listenerEndpointUrl, [`Bearer-${foundryToken}`]);

Set listenerEndpointUrl to the copied endpoint and foundryToken to your token. Text and binary messages flow in both directions.