connectWebChannel({ baseUrl, policy, core, transport: 'websocket' }). The SDK first verifies attestation and completes the HTTP Noise handshake/confirmation, then upgrades /v1/ws at the same origin. Only the opaque confirmed handle travels before encrypted binary frames.
All client.request commands retain the same signatures, authorization, stable IDs and journal. Text messages, subprotocols, compression, private URL fields and bearer/cookie headers are unsupported.