This doesn't seem like something I'd market as secure. Couldn't someone randomly join your session through entering a random 6 digits? Seems like it would need to expire, have owners approve new connections, etc.
Hope you figure it out though!
Unless you have some sort of throttling implemented, that's not really a lot and could probably be brute forced.