Laravel Echo 1,360 (https://github.com/laravel/echo 1,360 ) 2.5.0 wraps pusher-js 8.6.0 2,222 , adds channel helpers and makes the authorization request. In the browser, resources/js/echo.js reads VITE_REVERB_* values. The same API runs in Node 22, which makes a handy test client:
import Echo from 'laravel-echo';
import Pusher from 'pusher-js';
const echo = new Echo({
broadcaster: 'reverb',
Pusher,
key: process.env.REVERB_APP_KEY,
wsHost: '127.0.0.1',
wsPort: 8320,
forceTLS: false,
enabledTransports: ['ws'],
authEndpoint: 'http://127.0.0.1:8420/api/broadcasting/auth',
auth: { headers: { Authorization: `Bearer ${process.env.TOKEN}` } },
});
echo.private('orders.1')
.subscribed(() => console.log('subscribed to private-orders.1'))
.listen('.order.shipped', (payload) => {
console.log('order.shipped', JSON.stringify(payload));
echo.disconnect();
});Output
$ REVERB_APP_KEY=$KEY TOKEN=$ANN node listen.mjs &
subscribed to private-orders.1
$ curl -s -X POST -H "Authorization: Bearer $BEN" $B/api/v1/orders/1/ship
{"id":1,"status":"shipped"}
order.shipped {"id":1,"status":"shipped","shipped_at":"2026-09-23T09:06:57+00:00"}The payload is exactly broadcastWith(); the leading dot stops Echo from prefixing App\Events. Ben's token asked /api/broadcasting/auth for the same channel and got 403 Forbidden from the ownership rule. .notification() receives Database Notifications's broadcast notifications, and .join() handles presence channels.