You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Node.js中实现加密交易所WebSocket客户端并转发至前端?

Best Practices for Using Crypto Exchange WebSocket APIs in Frontend

Great question—this is a super common scenario when building crypto-related frontend apps, and the answer depends entirely on whether you need public or private WebSocket data. Let’s break it down clearly:

1. For Public Data (No API Keys Required)

Most crypto exchanges offer unauthenticated WebSocket endpoints for public market data like real-time prices, K-line charts, order book depth, and trade history. These don’t require API keys at all, so you can connect directly from the frontend without any middleman.

  • Why avoid official Node.js libraries here? Official SDKs are built for server-side use (they include logic for private endpoints and key management) and are overkill for public data. Instead, use the browser’s native WebSocket API or a lightweight frontend library to connect directly to the exchange’s public stream.
  • Example frontend code (connecting to a public K-line stream):
// Frontend: Connect to a public BTC/USDT 1-minute K-line stream
const ws = new WebSocket('wss://stream.binance.com:9443/ws/btcusdt@kline_1m');

ws.onopen = () => {
  console.log('Connected to public K-line stream');
};

ws.onmessage = (event) => {
  const klineData = JSON.parse(event.data).k;
  console.log('Updated K-line:', {
    timestamp: klineData.t,
    open: klineData.o,
    high: klineData.h,
    low: klineData.l,
    close: klineData.c
  });
};

ws.onerror = (err) => {
  console.error('WebSocket connection error:', err);
};

2. For Private Data (Requires API Keys)

If you need access to user-specific data (like open orders, balance updates, or trade confirmations), you must not handle API keys in the frontend. Exposing your secret key in client-side code is a critical security risk—anyone can steal it and take control of the associated account.

The Solution: Build a Proxy WebSocket Server

You’ll need a backend service that acts as a middleman between your frontend and the exchange’s WebSocket API:

  • The backend securely stores the API keys (use environment variables or encrypted secret managers—never hardcode them).
  • Your frontend connects to your backend’s WebSocket endpoint (using wss:// for encryption).
  • The backend handles all authentication/signing with the exchange’s API, forwards public/private data to the frontend, and relays frontend requests (like placing orders) to the exchange.

Key Security & Implementation Tips:

  • Authenticate frontend connections: Use JWT tokens or session cookies to verify that only authorized users can connect to your proxy server. Reject unauthenticated connections immediately.
  • Use encrypted connections: Ensure both the frontend ↔ backend and backend ↔ exchange connections use wss:// (WebSocket Secure) to prevent data interception.
  • Rate limiting: Implement rate limits on your proxy server to avoid hitting the exchange’s API rate limits and getting your IP banned.
  • Clean up connections: When a frontend disconnects, make sure your backend closes the corresponding exchange WebSocket connection to avoid unnecessary resource usage.

Example Proxy Server Code (Node.js):

// Backend proxy server using Node.js, ws library, and Binance SDK
const WebSocket = require('ws');
const binanceAPI = require('node-binance-api');
const jwt = require('jsonwebtoken');

// Initialize Binance API with secure key storage
const binance = new binanceAPI().options({
  APIKEY: process.env.BINANCE_API_KEY,
  APISECRET: process.env.BINANCE_API_SECRET,
  useServerTime: true
});

// Create proxy WebSocket server
const wss = new WebSocket.Server({ port: 8080 });

wss.on('connection', (clientWs, req) => {
  // Validate frontend JWT token
  const authHeader = req.headers.authorization;
  if (!authHeader || !authHeader.startsWith('Bearer ')) {
    clientWs.close(401, 'Unauthorized: No token provided');
    return;
  }

  const token = authHeader.split(' ')[1];
  try {
    jwt.verify(token, process.env.JWT_SECRET);
  } catch (err) {
    clientWs.close(401, 'Unauthorized: Invalid token');
    return;
  }

  // Connect to Binance's private user data stream
  binance.websockets.userData((data) => {
    // Forward private data to frontend
    clientWs.send(JSON.stringify(data));
  });

  // Handle frontend requests (e.g., place order)
  clientWs.on('message', (message) => {
    const payload = JSON.parse(message);
    if (payload.type === 'placeOrder') {
      binance.order(
        payload.symbol,
        payload.side,
        payload.type,
        payload.quantity,
        payload.price
      )
      .then(orderResult => {
        clientWs.send(JSON.stringify({ type: 'orderSuccess', data: orderResult }));
      })
      .catch(err => {
        clientWs.send(JSON.stringify({ type: 'orderError', data: err.message }));
      });
    }
  });

  // Clean up on frontend disconnect
  clientWs.on('close', () => {
    binance.websockets.closeAll();
  });
});

Final Takeaways

  • Public data only: Skip the proxy—connect directly to the exchange’s public WebSocket endpoints from the frontend.
  • Private data needed: Build a secure proxy server to handle API key management and data forwarding. This is the only safe way to access user-specific WebSocket data without exposing sensitive credentials.

内容的提问来源于stack exchange,提问作者LawrenceH

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:59:15