Looks quite neat, might give it a test to see how it compares against Reverb.
One question, I see this mentioned in the docs; https://github.com/RustNSparks/sockudo?tab=readme-ov-file#publishing-events
Does that mean events can be sent without authentication? Reverb had this CVE, where the backend/api could just be consumed with public data