I never worked with WebSockets, so I can't really help you with that. Could it be that the base64-encoded part is actually encoded because its signature bytes, and not a key? I suggest you check out the specification of this WebSocket security and see what they say.