Self-hosted Mosquitto
Run your own MQTT broker instead of a cloud service. Mosquitto is a small and popular MQTT broker for Linux.
pi-webrtc and the browser connect to the broker in different ways:
| Who connects | Protocol | Port in this guide |
|---|---|---|
| pi-webrtc on the device | MQTT | 1883 |
| The browser | MQTT over WebSocket | 8083, or 443 through a reverse proxy |
1. Install Mosquitto
On the server:
sudo apt update
sudo apt install mosquitto mosquitto-clients2. Create a user
sudo mosquitto_passwd -c /etc/mosquitto/passwd <username>
sudo chown mosquitto:mosquitto /etc/mosquitto/passwdThe first command asks for a password.
3. Add the listeners
Create /etc/mosquitto/conf.d/pi-webrtc.conf:
# For pi-webrtc
listener 1883
# For browsers
listener 8083
protocol websockets
allow_anonymous false
password_file /etc/mosquitto/passwdRestart Mosquitto:
sudo systemctl restart mosquitto4. Test the broker
In one terminal, subscribe:
mosquitto_sub -h localhost -p 1883 -u <username> -P <password> -t 'test/#' -vIn a second terminal, publish:
mosquitto_pub -h localhost -p 1883 -u <username> -P <password> -t test/hello -m hiThe first terminal should print test/hello hi.
5. Add TLS for browsers
The web app uses HTTPS, so the browser can only use a secure WebSocket (wss://). Put the broker behind a reverse proxy that has a TLS certificate. For example, with nginx:
location /mqtt {
proxy_pass http://127.0.0.1:8083;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "Upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}The browser then connects to port 443 with the path /mqtt.
6. Connect pi-webrtc
./pi-webrtc ... \
--use-mqtt \
--mqtt-host=<broker-host> \
--mqtt-port=1883 \
--mqtt-username=<username> \
--mqtt-password=<password>If the device connects to the broker over the internet, use TLS on port 8883 instead of 1883. See the Mosquitto TLS guide.
The client library
pi-webrtc uses the Mosquitto client library from your OS. The release needs libmosquitto1, and building from source needs libmosquitto-dev. Both come from apt, so you do not need to build Mosquitto yourself.
TURN
Use a TURN server when a peer-to-peer connection fails, for example over 4G or 5G. A TURN server relays the video between the device and the browser.
Recording
pi-webrtc can save MP4 video files and JPEG snapshots on the device, all the time or only when a viewer asks. Recording uses the full camera resolution, even...

