| IBroadcaster | Publishes notifications through the configured backplane. Recipients share an immutable envelope with id @. |
| IDarkWsAuthenticator | Resolves a session for a request or replacement token. Return null on rejection; expiry remains application policy. |
| IDarkWsBackplane | Transport for broadcast delivery across application instances. |
| IDarkWsContextAccessor | Current message context. Uninitialized access throws InvalidOperationException; lifecycle hooks receive context explicitly. |
| IDarkWsScopeInitializer | Initializes scoped application services before each handler invocation. |
| IDarkWsSession | Application session identity, principal, and groups. Membership is snapshotted on add or re-authentication. |
| IWebSocketConnection | Public connection contract implementable by consumers and test doubles. Send buffers must not be mutated. |