Microsoft.SignalRService webPubSub/hubs

Bicep resource definition

The webPubSub/hubs resource type can be deployed with operations that target:

For a list of changed properties in each API version, see change log.

Usage Examples

Bicep Samples

A basic example of deploying hub settings for a Web Pubsub service.

param resourceName string = 'acctest0001'
param location string = 'westeurope'

resource webPubSub 'Microsoft.SignalRService/webPubSub@2023-02-01' = {
  name: resourceName
  location: location
  sku: {
    capacity: 1
    name: 'Standard_S1'
  }
  properties: {
    disableAadAuth: false
    disableLocalAuth: false
    publicNetworkAccess: 'Enabled'
    tls: {
      clientCertEnabled: false
    }
  }
}

resource hub 'Microsoft.SignalRService/webPubSub/hubs@2023-02-01' = {
  name: resourceName
  parent: webPubSub
  properties: {
    anonymousConnectPolicy: 'Deny'
    eventListeners: []
  }
}

Resource format

To create a Microsoft.SignalRService/webPubSub/hubs resource, add the following Bicep to your template.

resource symbolicname 'Microsoft.SignalRService/webPubSub/hubs@2025-12-01-preview' = {
  parent: resourceSymbolicName
  name: 'string'
  properties: {
    anonymousConnectPolicy: 'string'
    chat: {
      mode: 'string'
      persistentStorage: {
        id: 'string'
      }
    }
    eventHandlers: [
      {
        auth: {
          managedIdentity: {
            resource: 'string'
          }
          type: 'string'
        }
        groupPresenceEvents: {
          eventNames: [
            'string'
          ]
          groupFilters: [
            'string'
          ]
        }
        systemEvents: [
          'string'
        ]
        urlTemplate: 'string'
        userEventPattern: 'string'
      }
    ]
    eventListeners: [
      {
        endpoint: {
          type: 'string'
          // For remaining properties, see EventListenerEndpoint objects
        }
        filter: {
          type: 'string'
          // For remaining properties, see EventListenerFilter objects
        }
      }
    ]
    webSocketKeepAliveIntervalInSeconds: int
  }
}

EventListenerFilter objects

Set the type property to specify the type of object.

For EventName, use:

{
  systemEvents: [
    'string'
  ]
  type: 'EventName'
  userEventPattern: 'string'
}

EventListenerEndpoint objects

Set the type property to specify the type of object.

For EventHub, use:

{
  eventHubName: 'string'
  fullyQualifiedNamespace: 'string'
  type: 'EventHub'
}

Property Values

Microsoft.SignalRService/webPubSub/hubs

Name Description Value
name The resource name string (required)
parent In Bicep, you can specify the parent resource for a child resource. You only need to add this property when the child resource is declared outside of the parent resource.

For more information, see Child resource outside parent resource.
Symbolic name for resource of type: webPubSub
properties Properties of a hub. WebPubSubHubProperties (required)

ChatSettings

Name Description Value
mode Enable or disable the chat feature. string
persistentStorage Reference to the the persistent storage for perisisting chat states. ResourceReference

EventHandler

Name Description Value
auth Upstream auth settings. If not set, no auth is used for upstream messages. UpstreamAuthSettings
groupPresenceEvents The group presence events that this event handler is concerned with. Group presence events are triggered when connections join or leave groups in the hub. If the value is null, no presence events will be sent to this event handler. GroupPresenceEventFilters
systemEvents Gets or sets the list of system events. string[]
urlTemplate Gets or sets the URL template for the event handler. The actual URL is calculated when the corresponding event is triggered.
The template supports predefined parameters syntax: {event}, {hub}, and KeyVault reference syntax {@Microsoft.KeyVault(SecretUri=_your_secret_identifier_)}
For example, if the template is http://example.com/api/{event}, when connect event is triggered, a POST request will be sent to the URL http://example.com/chat/api/connect.
Note: Parameters are not allowed in the hostname of the URL, and curly brackets {} are reserved for parameter syntax only. If your URL path contains literal curly brackets, please URL-encode them to ensure proper handling.
string (required)
userEventPattern Gets or sets the matching pattern for event names.
There are 3 kinds of patterns supported:
1. "*", it matches any event name
2. Combine multiple events with ",", for example "event1,event2", it matches event "event1" and "event2"
3. A single event name, for example, "event1", it matches "event1"
string

EventHubEndpoint

Name Description Value
eventHubName The name of the Event Hub. string (required)
fullyQualifiedNamespace The fully qualified namespace name of the Event Hub resource. string (required)
type 'EventHub' (required)

EventListener

Name Description Value
endpoint An endpoint specifying where Web PubSub should send events to. EventListenerEndpoint (required)
filter A base class for event filter which determines whether an event should be sent to an event listener. EventListenerFilter (required)

EventListenerEndpoint

Name Description Value
type Set to 'EventHub' for type EventHubEndpoint. 'EventHub' (required)

EventListenerFilter

Name Description Value
type Set to 'EventName' for type EventNameFilter. 'EventName' (required)

EventNameFilter

Name Description Value
systemEvents Gets or sets a list of system events. Supported events: "connected" and "disconnected". Blocking event "connect" is not supported because it requires a response. string[]
type 'EventName' (required)
userEventPattern Gets or sets a matching pattern for event names.
There are 3 kinds of patterns supported:
1. "*", it matches any event name
2. Combine multiple events with ",", for example "event1,event2", it matches events "event1" and "event2"
3. A single event name, for example, "event1", it matches "event1"
string

GroupPresenceEventFilters

Name Description Value
eventNames The concerning event names. Valid values are "joined", "left". If the value is null or empty, no presence events will be sent to the event handler. String array containing any of:
'joined'
'left' (required)
groupFilters The group filters. Only events from these groups will be sent to the event handler. Each element is a pattern that may match multiple groups. If null or empty, events from all groups will be sent (subject to eventNames). string[]

ManagedIdentitySettings

Name Description Value
resource The Resource indicating the App ID URI of the target resource.
It also appears in the aud (audience) claim of the issued token.
string

ResourceReference

Name Description Value
id Resource ID. string

UpstreamAuthSettings

Name Description Value
managedIdentity Managed identity settings for upstream. ManagedIdentitySettings
type Upstream auth type enum. 'ManagedIdentity'
'None'

WebPubSubHubProperties

Name Description Value
anonymousConnectPolicy The settings for configuring if anonymous connections are allowed for this hub: "allow" or "deny". Default to "deny". string
chat The chat settings for the hub. ChatSettings
eventHandlers Event handler of a hub. EventHandler[]
eventListeners Event listener settings for forwarding your client events to listeners.
Event listener is transparent to Web PubSub clients, and it doesn't return any result to clients nor interrupt the lifetime of clients.
One event can be sent to multiple listeners, as long as it matches the filters in those listeners. The order of the array elements doesn't matter.
Maximum count of event listeners among all hubs is 10.
EventListener[]
webSocketKeepAliveIntervalInSeconds The settings for configuring the WebSocket ping-pong interval in seconds for all clients in the hub. Valid range: 1 to 120. Default to 20 seconds. int

Constraints:
Min value = 1
Max value = 120

ARM template resource definition

The webPubSub/hubs resource type can be deployed with operations that target:

Usage Examples

Resource format

To create a Microsoft.SignalRService/webPubSub/hubs resource, add the following JSON to your template.

{
  "type": "Microsoft.SignalRService/webPubSub/hubs",
  "apiVersion": "2025-12-01-preview",
  "name": "string",
  "properties": {
    "anonymousConnectPolicy": "string",
    "chat": {
      "mode": "string",
      "persistentStorage": {
        "id": "string"
      }
    },
    "eventHandlers": [
      {
        "auth": {
          "managedIdentity": {
            "resource": "string"
          },
          "type": "string"
        },
        "groupPresenceEvents": {
          "eventNames": [ "string" ],
          "groupFilters": [ "string" ]
        },
        "systemEvents": [ "string" ],
        "urlTemplate": "string",
        "userEventPattern": "string"
      }
    ],
    "eventListeners": [
      {
        "endpoint": {
          "type": "string"
          // For remaining properties, see EventListenerEndpoint objects
        },
        "filter": {
          "type": "string"
          // For remaining properties, see EventListenerFilter objects
        }
      }
    ],
    "webSocketKeepAliveIntervalInSeconds": "int"
  }
}

EventListenerFilter objects

Set the type property to specify the type of object.

For EventName, use:

{
  "systemEvents": [ "string" ],
  "type": "EventName",
  "userEventPattern": "string"
}

EventListenerEndpoint objects

Set the type property to specify the type of object.

For EventHub, use:

{
  "eventHubName": "string",
  "fullyQualifiedNamespace": "string",
  "type": "EventHub"
}

Property Values

Microsoft.SignalRService/webPubSub/hubs

Name Description Value
apiVersion The api version '2025-12-01-preview'
name The resource name string (required)
properties Properties of a hub. WebPubSubHubProperties (required)
type The resource type 'Microsoft.SignalRService/webPubSub/hubs'

ChatSettings

Name Description Value
mode Enable or disable the chat feature. string
persistentStorage Reference to the the persistent storage for perisisting chat states. ResourceReference

EventHandler

Name Description Value
auth Upstream auth settings. If not set, no auth is used for upstream messages. UpstreamAuthSettings
groupPresenceEvents The group presence events that this event handler is concerned with. Group presence events are triggered when connections join or leave groups in the hub. If the value is null, no presence events will be sent to this event handler. GroupPresenceEventFilters
systemEvents Gets or sets the list of system events. string[]
urlTemplate Gets or sets the URL template for the event handler. The actual URL is calculated when the corresponding event is triggered.
The template supports predefined parameters syntax: {event}, {hub}, and KeyVault reference syntax {@Microsoft.KeyVault(SecretUri=_your_secret_identifier_)}
For example, if the template is http://example.com/api/{event}, when connect event is triggered, a POST request will be sent to the URL http://example.com/chat/api/connect.
Note: Parameters are not allowed in the hostname of the URL, and curly brackets {} are reserved for parameter syntax only. If your URL path contains literal curly brackets, please URL-encode them to ensure proper handling.
string (required)
userEventPattern Gets or sets the matching pattern for event names.
There are 3 kinds of patterns supported:
1. "*", it matches any event name
2. Combine multiple events with ",", for example "event1,event2", it matches event "event1" and "event2"
3. A single event name, for example, "event1", it matches "event1"
string

EventHubEndpoint

Name Description Value
eventHubName The name of the Event Hub. string (required)
fullyQualifiedNamespace The fully qualified namespace name of the Event Hub resource. string (required)
type 'EventHub' (required)

EventListener

Name Description Value
endpoint An endpoint specifying where Web PubSub should send events to. EventListenerEndpoint (required)
filter A base class for event filter which determines whether an event should be sent to an event listener. EventListenerFilter (required)

EventListenerEndpoint

Name Description Value
type Set to 'EventHub' for type EventHubEndpoint. 'EventHub' (required)

EventListenerFilter

Name Description Value
type Set to 'EventName' for type EventNameFilter. 'EventName' (required)

EventNameFilter

Name Description Value
systemEvents Gets or sets a list of system events. Supported events: "connected" and "disconnected". Blocking event "connect" is not supported because it requires a response. string[]
type 'EventName' (required)
userEventPattern Gets or sets a matching pattern for event names.
There are 3 kinds of patterns supported:
1. "*", it matches any event name
2. Combine multiple events with ",", for example "event1,event2", it matches events "event1" and "event2"
3. A single event name, for example, "event1", it matches "event1"
string

GroupPresenceEventFilters

Name Description Value
eventNames The concerning event names. Valid values are "joined", "left". If the value is null or empty, no presence events will be sent to the event handler. String array containing any of:
'joined'
'left' (required)
groupFilters The group filters. Only events from these groups will be sent to the event handler. Each element is a pattern that may match multiple groups. If null or empty, events from all groups will be sent (subject to eventNames). string[]

ManagedIdentitySettings

Name Description Value
resource The Resource indicating the App ID URI of the target resource.
It also appears in the aud (audience) claim of the issued token.
string

ResourceReference

Name Description Value
id Resource ID. string

UpstreamAuthSettings

Name Description Value
managedIdentity Managed identity settings for upstream. ManagedIdentitySettings
type Upstream auth type enum. 'ManagedIdentity'
'None'

WebPubSubHubProperties

Name Description Value
anonymousConnectPolicy The settings for configuring if anonymous connections are allowed for this hub: "allow" or "deny". Default to "deny". string
chat The chat settings for the hub. ChatSettings
eventHandlers Event handler of a hub. EventHandler[]
eventListeners Event listener settings for forwarding your client events to listeners.
Event listener is transparent to Web PubSub clients, and it doesn't return any result to clients nor interrupt the lifetime of clients.
One event can be sent to multiple listeners, as long as it matches the filters in those listeners. The order of the array elements doesn't matter.
Maximum count of event listeners among all hubs is 10.
EventListener[]
webSocketKeepAliveIntervalInSeconds The settings for configuring the WebSocket ping-pong interval in seconds for all clients in the hub. Valid range: 1 to 120. Default to 20 seconds. int

Constraints:
Min value = 1
Max value = 120

Terraform (AzAPI provider) resource definition

The webPubSub/hubs resource type can be deployed with operations that target:

  • Resource groups For a list of changed properties in each API version, see change log.

Usage Examples

Terraform Samples

A basic example of deploying hub settings for a Web Pubsub service.

terraform {
  required_providers {
    azapi = {
      source = "Azure/azapi"
    }
  }
}

provider "azapi" {
  skip_provider_registration = false
}

variable "resource_name" {
  type    = string
  default = "acctest0001"
}

variable "location" {
  type    = string
  default = "westeurope"
}

resource "azapi_resource" "resourceGroup" {
  type     = "Microsoft.Resources/resourceGroups@2020-06-01"
  name     = var.resource_name
  location = var.location
}

resource "azapi_resource" "webPubSub" {
  type      = "Microsoft.SignalRService/webPubSub@2023-02-01"
  parent_id = azapi_resource.resourceGroup.id
  name      = var.resource_name
  location  = var.location
  identity {
    type         = "SystemAssigned"
    identity_ids = []
  }
  body = {
    properties = {
      disableAadAuth      = false
      disableLocalAuth    = false
      publicNetworkAccess = "Enabled"
      tls = {
        clientCertEnabled = false
      }
    }
    sku = {
      capacity = 1
      name     = "Standard_S1"
    }
  }
  schema_validation_enabled = false
  response_export_values    = ["*"]
}

resource "azapi_resource" "hub" {
  type      = "Microsoft.SignalRService/webPubSub/hubs@2023-02-01"
  parent_id = azapi_resource.webPubSub.id
  name      = var.resource_name
  body = {
    properties = {
      anonymousConnectPolicy = "Deny"
      eventListeners = [
      ]
    }
  }
  schema_validation_enabled = false
  response_export_values    = ["*"]
}

Resource format

To create a Microsoft.SignalRService/webPubSub/hubs resource, add the following Terraform to your template.

resource "azapi_resource" "symbolicname" {
  type = "Microsoft.SignalRService/webPubSub/hubs@2025-12-01-preview"
  name = "string"
  parent_id = "string"
  body = {
    properties = {
      anonymousConnectPolicy = "string"
      chat = {
        mode = "string"
        persistentStorage = {
          id = "string"
        }
      }
      eventHandlers = [
        {
          auth = {
            managedIdentity = {
              resource = "string"
            }
            type = "string"
          }
          groupPresenceEvents = {
            eventNames = [
              "string"
            ]
            groupFilters = [
              "string"
            ]
          }
          systemEvents = [
            "string"
          ]
          urlTemplate = "string"
          userEventPattern = "string"
        }
      ]
      eventListeners = [
        {
          endpoint = {
            type = "string"
            // For remaining properties, see EventListenerEndpoint objects
          }
          filter = {
            type = "string"
            // For remaining properties, see EventListenerFilter objects
          }
        }
      ]
      webSocketKeepAliveIntervalInSeconds = int
    }
  }
}

EventListenerFilter objects

Set the type property to specify the type of object.

For EventName, use:

{
  systemEvents = [
    "string"
  ]
  type = "EventName"
  userEventPattern = "string"
}

EventListenerEndpoint objects

Set the type property to specify the type of object.

For EventHub, use:

{
  eventHubName = "string"
  fullyQualifiedNamespace = "string"
  type = "EventHub"
}

Property Values

Microsoft.SignalRService/webPubSub/hubs

Name Description Value
name The resource name string (required)
parent_id The ID of the resource that is the parent for this resource. ID for resource of type: webPubSub
properties Properties of a hub. WebPubSubHubProperties (required)
type The resource type "Microsoft.SignalRService/webPubSub/hubs@2025-12-01-preview"

ChatSettings

Name Description Value
mode Enable or disable the chat feature. string
persistentStorage Reference to the the persistent storage for perisisting chat states. ResourceReference

EventHandler

Name Description Value
auth Upstream auth settings. If not set, no auth is used for upstream messages. UpstreamAuthSettings
groupPresenceEvents The group presence events that this event handler is concerned with. Group presence events are triggered when connections join or leave groups in the hub. If the value is null, no presence events will be sent to this event handler. GroupPresenceEventFilters
systemEvents Gets or sets the list of system events. string[]
urlTemplate Gets or sets the URL template for the event handler. The actual URL is calculated when the corresponding event is triggered.
The template supports predefined parameters syntax: {event}, {hub}, and KeyVault reference syntax {@Microsoft.KeyVault(SecretUri=_your_secret_identifier_)}
For example, if the template is http://example.com/api/{event}, when connect event is triggered, a POST request will be sent to the URL http://example.com/chat/api/connect.
Note: Parameters are not allowed in the hostname of the URL, and curly brackets {} are reserved for parameter syntax only. If your URL path contains literal curly brackets, please URL-encode them to ensure proper handling.
string (required)
userEventPattern Gets or sets the matching pattern for event names.
There are 3 kinds of patterns supported:
1. "*", it matches any event name
2. Combine multiple events with ",", for example "event1,event2", it matches event "event1" and "event2"
3. A single event name, for example, "event1", it matches "event1"
string

EventHubEndpoint

Name Description Value
eventHubName The name of the Event Hub. string (required)
fullyQualifiedNamespace The fully qualified namespace name of the Event Hub resource. string (required)
type 'EventHub' (required)

EventListener

Name Description Value
endpoint An endpoint specifying where Web PubSub should send events to. EventListenerEndpoint (required)
filter A base class for event filter which determines whether an event should be sent to an event listener. EventListenerFilter (required)

EventListenerEndpoint

Name Description Value
type Set to 'EventHub' for type EventHubEndpoint. 'EventHub' (required)

EventListenerFilter

Name Description Value
type Set to 'EventName' for type EventNameFilter. 'EventName' (required)

EventNameFilter

Name Description Value
systemEvents Gets or sets a list of system events. Supported events: "connected" and "disconnected". Blocking event "connect" is not supported because it requires a response. string[]
type 'EventName' (required)
userEventPattern Gets or sets a matching pattern for event names.
There are 3 kinds of patterns supported:
1. "*", it matches any event name
2. Combine multiple events with ",", for example "event1,event2", it matches events "event1" and "event2"
3. A single event name, for example, "event1", it matches "event1"
string

GroupPresenceEventFilters

Name Description Value
eventNames The concerning event names. Valid values are "joined", "left". If the value is null or empty, no presence events will be sent to the event handler. String array containing any of:
'joined'
'left' (required)
groupFilters The group filters. Only events from these groups will be sent to the event handler. Each element is a pattern that may match multiple groups. If null or empty, events from all groups will be sent (subject to eventNames). string[]

ManagedIdentitySettings

Name Description Value
resource The Resource indicating the App ID URI of the target resource.
It also appears in the aud (audience) claim of the issued token.
string

ResourceReference

Name Description Value
id Resource ID. string

UpstreamAuthSettings

Name Description Value
managedIdentity Managed identity settings for upstream. ManagedIdentitySettings
type Upstream auth type enum. 'ManagedIdentity'
'None'

WebPubSubHubProperties

Name Description Value
anonymousConnectPolicy The settings for configuring if anonymous connections are allowed for this hub: "allow" or "deny". Default to "deny". string
chat The chat settings for the hub. ChatSettings
eventHandlers Event handler of a hub. EventHandler[]
eventListeners Event listener settings for forwarding your client events to listeners.
Event listener is transparent to Web PubSub clients, and it doesn't return any result to clients nor interrupt the lifetime of clients.
One event can be sent to multiple listeners, as long as it matches the filters in those listeners. The order of the array elements doesn't matter.
Maximum count of event listeners among all hubs is 10.
EventListener[]
webSocketKeepAliveIntervalInSeconds The settings for configuring the WebSocket ping-pong interval in seconds for all clients in the hub. Valid range: 1 to 120. Default to 20 seconds. int

Constraints:
Min value = 1
Max value = 120