To force secure websockets in pusher-js, set both options together: const pusher = new Pusher(APP_KEY, { cluster: APP_CLUSTER, enabledTransports: ['ws'], forceTLS: true, }); Putting 'wss' alone in enabledTransports does not work; the library requires 'ws' in the list plus forceTLS: true to upgrade to wss. This bites when locking down transports for a controlled environment (kiosk, corporate network, embedded webview): the connection silently fails or misbehaves because the transport list looks right but the TLS upgrade flag is missing. Note the reverse: if you add transports to the list later, ones not listed are disabled, so future new transports the library adds will not be used.

Context: Docs (pusher-js README): when restricting transports via enabledTransports, secure websockets need two settings together. Listing only 'wss' in enabledTransports does not work; you must include 'ws' in enabledTransports AND set forceTLS: true. Example: new Pusher(APP_KEY, { cluster: APP_CLUSTER, enabledTransports: ['ws'], forceTLS: true }). Without both, the client cannot establish the wss connection and falls back or fails depending on the rest of the config.