Authentication
These operations create a player cabinet session through the sign-in methods enabled for the current project.
Login with credentials
login
Description
Authenticates a user by email or account login and password. When 2FA is enabled, the result contains a twoFactorChallenge instead of a session.
Input
| Input field | Type | Required | Description |
|---|---|---|---|
login | String! | ✓ | Account login. |
password | String! | ✓ | Password |
rememberMe | Boolean | - | Whether to create a long-lived session. |
utm | JSON | - | UTM tags |
launcher | Int | - | Launcher mode flag. |
Result
Response type - LoginResult.
Errors
METHOD_DISABLED- the selected sign-in method is disabled for the project.INVALID_CREDENTIALS- login or password is invalid.TOO_MANY_ATTEMPTS- the login attempt limit was exceeded.USER_BANNED- the account is blocked.
Project protection covers short request bursts by IP, an IP and login pair, one login across multiple IPs, and unknown-login enumeration. User-Agent is not treated as a trust boundary. For a throttled request, extensions.retryAfterSeconds contains the exact retry delay.
Exchange example
{
"documentId": "login",
"variables": {
"login": "GameLogin",
"password": "password123",
"rememberMe": true,
"utm": {
"source": "site",
"medium": "web",
"campaign": "launch"
},
"launcher": 1
}
}
{
"data": {
"login": {
"sessionId": "session-token",
"user": {
"id": "1001",
"selectedServerId": 1
}
}
}
}
Related types
loginGameAccount
Description
Authenticates a user by game account login and password.
Input
| Field | Type | Required | Description |
|---|---|---|---|
login | String! | ✓ | Game account login |
password | String! | ✓ | Game account password |
serverId | Int! | ✓ | Server ID |
utm | JSON | - | UTM tags |
Result
Response type - LoginResult.
Errors
INVALID_CREDENTIALS- login or password is invalid.USER_NOT_FOUND- the master account was not found.METHOD_DISABLED- game account login is disabled for the project.TOO_MANY_ATTEMPTS- the login attempt limit was exceeded.USER_BANNED- the account is blocked.
Exchange example
{
"documentId": "loginGameAccount",
"variables": {
"login": "GameLogin",
"password": "password123",
"serverId": 1,
"utm": {}
}
}
{
"data": {
"loginGameAccount": {
"sessionId": "session-token",
"user": {
"id": "1001",
}
}
}
}
Related types
loginPasskey
Description
Completes login with a passkey/WebAuthn assertion.
Input
| Field | Type | Required | Description |
|---|---|---|---|
assertion | JSON! | ✓ | WebAuthn assertion |
utm | JSON | - | UTM tags |
Result
Response type - LoginResult.
Errors
PASSKEY_INVALID_ASSERTION- the WebAuthn assertion is invalid.PASSKEY_NOT_FOUND- the matching passkey was not found.USER_NOT_FOUND- user was not found.TOO_MANY_ATTEMPTS- the login attempt limit was exceeded.
Exchange example
{
"documentId": "loginPasskey",
"variables": {
"assertion": {},
"utm": {}
}
}
{
"data": {
"loginPasskey": {
"sessionId": "session-token",
"user": {
"id": "1001"
}
}
}
}
Related types
Social login URL
socialAuthUrl
Description
Returns the OAuth redirect URL for a social provider configured by the current project.
Input
| Field | Type | Required | Description |
|---|---|---|---|
provider | String! | ✓ | External provider code. |
Result
Response type - SocialAuthUrl, containing the redirect URL and provider code.
Errors
SOCIAL_PROVIDER_DISABLED- the provider is not configured or is disabled for the project.
Exchange example
{
"documentId": "socialAuthUrl",
"variables": {
"provider": "google"
}
}
{
"data": {
"socialAuthUrl": {
"url": "https://project.example/auth/google",
"provider": "google"
}
}
}
Related types
Login by code
sendMagicCode
Description
Sends a one-time login code to the supplied email address. The same flow can create an account when the address is not registered yet.
Input
| Field | Type | Required | Description |
|---|---|---|---|
email | String! | ✓ | User email |
gameServerId | Int | - | Game server ID. |
Result
Response type - OperationResult.
Errors
METHOD_DISABLED- magic code login is disabled for the project.MAGIC_CODE_ALREADY_SENT- another code was requested before the resend interval elapsed.
Exchange example
{
"documentId": "sendMagicCode",
"variables": {
"gameServerId": 1
}
}
{
"data": {
"sendMagicCode": {
"message": "Login code sent"
}
}
}
Related types
loginMagicCode
Description
Verifies the one-time code and returns a session or a 2FA challenge. A new user is created when the code belongs to an unregistered address.
Input
| Field | Type | Required | Description |
|---|---|---|---|
email | String! | ✓ | User email |
code | String! | ✓ | Confirmation or authorization code. |
gameServerId | Int | - | Game server ID. |
utm | JSON | - | UTM tags |
Result
Response type - LoginResult.
Errors
METHOD_DISABLED- magic code login is disabled for the project.MAGIC_CODE_EXPIRED- the code is invalid or expired.TOO_MANY_ATTEMPTS- the verification attempt limit was exceeded.USER_BANNED- the account is blocked.
Exchange example
{
"documentId": "loginMagicCode",
"variables": {
"code": "123456",
"gameServerId": 1,
"utm": {
"source": "site",
"medium": "web",
"campaign": "launch"
}
}
}
{
"data": {
"loginMagicCode": {
"sessionId": "session-token",
"user": {
"id": "1001",
}
}
}
}
Related types
Login by link
sendMagicLink
Description
Sends a one-time passwordless login link. The same flow can create an account when the address is not registered yet.
Input
| Field | Type | Required | Description |
|---|---|---|---|
email | String! | ✓ | User email |
gameServerId | Int | - | Game server ID. |
Result
Response type - OperationResult.
Errors
METHOD_DISABLED- magic link login is disabled for the project.MAGIC_LINK_ALREADY_SENT- another link was requested before the resend interval elapsed.
Exchange example
{
"documentId": "sendMagicLink",
"variables": {
"gameServerId": 1
}
}
{
"data": {
"sendMagicLink": {
"message": "Login link sent"
}
}
}
Related types
loginMagicLink
Description
Verifies the one-time link token and returns a session or a 2FA challenge. A new user is created when the token belongs to an unregistered address.
Input
| Field | Type | Required | Description |
|---|---|---|---|
token | String! | ✓ | One-time authorization token. |
email | String! | ✓ | User email |
gameServerId | Int | - | Game server ID. |
utm | JSON | - | UTM tags |
Result
Response type - LoginResult.
Errors
METHOD_DISABLED- magic link login is disabled for the project.MAGIC_LINK_EXPIRED- the token is invalid or expired.TOO_MANY_ATTEMPTS- the verification attempt limit was exceeded.USER_BANNED- the account is blocked.
Exchange example
{
"documentId": "loginMagicLink",
"variables": {
"token": "magic-token",
"gameServerId": 1,
"utm": {
"source": "site",
"medium": "web",
"campaign": "launch"
}
}
}
{
"data": {
"loginMagicLink": {
"sessionId": "session-token",
"user": {
"id": "1001",
}
}
}
}
Related types
Logout
logout
Description
Ends the current user session.
Input
The operation does not accept variables.
Result
Response type - OperationResult.
When the session is missing or already closed, the operation also returns a completion message.
Exchange example
{
"documentId": "logout",
"variables": {}
}
{
"data": {
"logout": {
"message": "Session ended"
}
}
}