I did mean separate bounties for each app of course.
Yes, the spec is an absolute nightmare and totally unclear. It should also have an option to be in a header and not force us to open the websocket connection first.
We are simply providing an AUTH challenge in connect and will not respond to any REQs or EVENTs until you answer the auth. You have 10 minutes to respond or we drop your connection. It is trivial to modify this to do whatever it is clients prefer provided they have an implementation for us to test.