WEBRTC • DEFINITION
What Is WebRTC?
WebRTC (Web Real-Time Communication) is a collection of standardized browser APIs and real-time communication protocols that let web applications capture and exchange audio, video and data without a browser plug-in. The central API is RTCPeerConnection; applications commonly use getUserMedia() for cameras and microphones and RTCDataChannel for application data.
WebRTC provides the media and connectivity machinery, but it does not define how users find one another or exchange call-control messages. Every application still needs a signaling service—often WebSocket, HTTPS, SIP over WebSocket, or a vendor API—to exchange session descriptions and ICE candidates.
Audio and video
Capture microphone or camera streams, negotiate codecs and transport encrypted media with low latency.
Data channels
Exchange arbitrary application data such as chat messages, game state or file-transfer chunks.
Browser access
Build communication into a webpage without installing a traditional softphone or media plug-in.
OFFER • ANSWER • CONNECT
How Does WebRTC Work?
A WebRTC call is established in several coordinated stages. Signaling carries setup information; ICE discovers a viable network path; DTLS authenticates the endpoints and establishes keys; encrypted media then travels using SRTP. The media path may be direct between peers or relayed through TURN when direct connectivity fails.
- Capture mediaThe application requests permission to use the microphone, camera or screen with browser media APIs.
- Create a peer connectionThe application creates an RTCPeerConnection and supplies its STUN and TURN server configuration.
- Exchange SDPOne peer creates an SDP offer and the other returns an SDP answer through the application’s signaling channel.
- Exchange ICE candidatesEach side shares possible network routes as they are discovered, a technique commonly called trickle ICE.
- Select and secure a pathICE selects a working candidate pair, DTLS establishes cryptographic keys and media is protected with SRTP.
- Monitor the sessionThe application watches connection state and statistics such as packet loss, jitter, round-trip time and bitrate.
NAT • FIREWALL • CONNECTIVITY
What Do ICE, STUN and TURN Do?
ICE
Interactive Connectivity Establishment gathers and tests possible network routes, called candidates, then selects a working candidate pair.
STUN
A STUN server helps a device discover its public-facing address and produces a server-reflexive candidate for NAT traversal.
TURN
A TURN server relays traffic when firewalls, symmetric NAT or network policy prevents a usable direct connection. Production services need TURN for reliability.
STUN does not relay the call. TURN does. Because relayed audio and video consume server bandwidth, TURN capacity, authentication and regional placement must be planned as part of a production deployment.
JAVASCRIPT • EXAMPLE
Minimal WebRTC Peer-Connection Example
This simplified example creates a peer connection, adds microphone audio, creates an offer and sends the description and ICE candidates through an application-defined signaling channel:
const pc = new RTCPeerConnection({
iceServers: [{ urls: "turn:turn.example.com:3478",
username: "user", credential: "secret" }]
});
const stream = await navigator.mediaDevices.getUserMedia({ audio: true });
stream.getTracks().forEach(track => pc.addTrack(track, stream));
pc.onicecandidate = ({ candidate }) => {
if (candidate) signaling.send({ candidate });
};
await pc.setLocalDescription(await pc.createOffer());
signaling.send({ description: pc.localDescription });
The remote peer must set the received offer as its remote description, create and return an answer, and add received ICE candidates. A real application also handles permissions, reconnects, negotiation collisions, device changes and TURN credentials securely.
WEBRTC • SIP • VOIP
WebRTC vs SIP: What Is the Difference?
WebRTC and SIP solve different parts of a communication system. WebRTC gives browsers real-time media and peer-connectivity capabilities. SIP is a signaling protocol used to register endpoints and establish, modify and end communication sessions. They can be used together rather than treated as alternatives.
WebRTC
Browser APIs plus a secure real-time protocol stack for audio, video and data. Signaling is deliberately left to the application.
SIP
A call-control and signaling protocol widely used by IP-PBX systems, SIP trunks, phones and telecom services.
WebRTC with SIP
A browser phone can use SIP over secure WebSocket for signaling while WebRTC carries encrypted browser media. A gateway or media server may connect it to conventional SIP/RTP infrastructure.
For a ready-made integration path, the VaxVoIP WebPhone SDK connects browser-based WebRTC calling with SIP servers and IP-PBX systems.
MEDIA • TRANSPORT
WebRTC vs RTP: What Is the Difference?
RTP is a protocol for transporting real-time media; WebRTC is the larger browser communication system that performs capture, negotiation, connectivity, security and media handling. WebRTC audio and video are carried using Secure RTP (SRTP), with keys negotiated through DTLS. In contrast, many traditional VoIP systems may use plain RTP unless secure media is configured.
PERMISSIONS • ENCRYPTION • DEPLOYMENT
Is WebRTC Secure?
WebRTC media is encrypted in transit, and browsers require user permission before a site can access the microphone or camera. Secure deployment still depends on the surrounding application.
- Use HTTPS and secure signalingProtect pages, authentication and signaling with HTTPS and WSS.
- Authenticate TURN accessUse short-lived credentials and prevent unauthorized users from consuming relay bandwidth.
- Validate signaling messagesAuthorize call actions and treat SDP, candidates and user identifiers as untrusted input.
- Minimize permissionsRequest microphone, camera or screen access only when the user starts the corresponding feature.
- Monitor abuseRate-limit call attempts, protect accounts and log suspicious registration or signaling behavior.
PRACTICAL • APPLICATIONS
Common WebRTC Use Cases
Browser phones
Place and receive calls from a website, CRM, help desk or agent desktop without a separate softphone.
Video meetings
Deliver one-to-one or multiparty video using peer connections and, for groups, an SFU or other media server.
Contact centers
Connect customers and agents through click-to-call, in-browser agent controls and SIP infrastructure.
Telehealth and support
Provide permission-based audio, video and screen sharing inside secured web applications.
Live collaboration
Combine media with data channels for chat, whiteboards, remote assistance or shared application state.
IoT and monitoring
Stream low-latency media or data between browsers, devices and application services where supported.
QUALITY • CONNECTIVITY • DEBUGGING
Why Do WebRTC Calls Fail?
Most failures fall into one of three groups: signaling did not complete, ICE could not find a working path, or media quality degraded after connection. Inspect browser permission errors, signaling logs, ICE states and getStats() results together.
- No microphone or cameraCheck HTTPS, browser permission state, device availability and whether another application holds the device.
- ICE failedVerify TURN reachability, credentials, DNS, firewall policy and support for networks that block UDP.
- One-way or no audioCheck selected candidates, media direction in SDP, track handling, gateway routing and codec compatibility.
- Poor qualityMeasure packet loss, jitter, round-trip time and available bitrate; then examine Wi-Fi, congestion and relay location.
STANDARDS • REFERENCES
WebRTC Technical References
This guide follows the current WebRTC standard and official implementation guidance:
WEBRTC • FAQ
Frequently Asked Questions
Is WebRTC a protocol or an API?
WebRTC is a technology stack that includes standardized browser APIs and supporting real-time protocols. It is not one signaling protocol, and applications must provide their own signaling mechanism.
Does WebRTC require a server?
Usually yes. Applications need a web server and signaling service, and production deployments normally need STUN and TURN. Multiparty conferences commonly use a media server such as an SFU.
Does WebRTC use SIP?
WebRTC does not require SIP, but browser phones often use SIP over WebSocket to connect with IP-PBX systems and SIP services.
Does WebRTC always connect peer to peer?
No. ICE prefers a usable path, which may be direct or relayed through TURN. Multiparty and recording deployments may deliberately route media through a server.
What is the difference between STUN and TURN?
STUN helps discover a public-facing network address. TURN relays the actual traffic when a direct connection cannot be established.
Is WebRTC media encrypted?
Yes. WebRTC protects real-time media with SRTP and negotiates keys using DTLS; application signaling should also be protected with HTTPS or WSS.
NEXT • STEP
Add WebRTC Calling to a SIP Application
WebRTC makes secure, low-latency browser communication possible, while signaling, TURN reliability, SIP interoperability and application security still require careful implementation. If your goal is a browser phone connected to an existing SIP server or IP-PBX, explore the VaxVoIP WebPhone SDK or contact VaxVoIP to discuss your integration.