Skip to main content

Authentication

These operations create a player cabinet session through the sign-in methods enabled for the current project.

Login with credentials​

MutationdocumentId: loginauth: public

login​

Description​

Authenticates a user by email or account login and password. When 2FA is enabled, the result contains a twoFactorChallenge instead of a session.

Input​

Input fieldTypeRequiredDescription
loginString!✓Account login.
passwordString!✓Password
rememberMeBoolean-Whether to create a long-lived session.
utmJSON-UTM tags
launcherInt-Launcher mode flag.

Result​

Response type - LoginResult.

Errors​

  • METHOD_DISABLED - the selected sign-in method is disabled for the project.
  • INVALID_CREDENTIALS - login or password is invalid.
  • TOO_MANY_ATTEMPTS - the login attempt limit was exceeded.
  • USER_BANNED - the account is blocked.

Project protection covers short request bursts by IP, an IP and login pair, one login across multiple IPs, and unknown-login enumeration. User-Agent is not treated as a trust boundary. For a throttled request, extensions.retryAfterSeconds contains the exact retry delay.

Exchange example​

Request
documentId: login
{
"documentId": "login",
"variables": {
"login": "GameLogin",
"password": "password123",
"rememberMe": true,
"utm": {
"source": "site",
"medium": "web",
"campaign": "launch"
},
"launcher": 1
}
}
Response
200 OK
{
"data": {
"login": {
"sessionId": "session-token",
"user": {
"id": "1001",
"email": "[email protected]",
"selectedServerId": 1
}
}
}
}
MutationdocumentId: loginGameAccountauth: public

loginGameAccount​

Description​

Authenticates a user by game account login and password.

Input​

FieldTypeRequiredDescription
loginString!✓Game account login
passwordString!✓Game account password
serverIdInt!✓Server ID
utmJSON-UTM tags

Result​

Response type - LoginResult.

Errors​

  • INVALID_CREDENTIALS - login or password is invalid.
  • USER_NOT_FOUND - the master account was not found.
  • METHOD_DISABLED - game account login is disabled for the project.
  • TOO_MANY_ATTEMPTS - the login attempt limit was exceeded.
  • USER_BANNED - the account is blocked.

Exchange example​

Request
documentId: loginGameAccount
{
"documentId": "loginGameAccount",
"variables": {
"login": "GameLogin",
"password": "password123",
"serverId": 1,
"utm": {}
}
}
Response
200 OK
{
"data": {
"loginGameAccount": {
"sessionId": "session-token",
"user": {
"id": "1001",
"email": "[email protected]"
}
}
}
}
MutationdocumentId: loginPasskeyauth: public

loginPasskey​

Description​

Completes login with a passkey/WebAuthn assertion.

Input​

FieldTypeRequiredDescription
assertionJSON!✓WebAuthn assertion
utmJSON-UTM tags

Result​

Response type - LoginResult.

Errors​

  • PASSKEY_INVALID_ASSERTION - the WebAuthn assertion is invalid.
  • PASSKEY_NOT_FOUND - the matching passkey was not found.
  • USER_NOT_FOUND - user was not found.
  • TOO_MANY_ATTEMPTS - the login attempt limit was exceeded.

Exchange example​

Request
documentId: loginPasskey
{
"documentId": "loginPasskey",
"variables": {
"assertion": {},
"utm": {}
}
}
Response
200 OK
{
"data": {
"loginPasskey": {
"sessionId": "session-token",
"user": {
"id": "1001"
}
}
}
}

Social login URL​

QuerydocumentId: socialAuthUrlauth: public

socialAuthUrl​

Description​

Returns the OAuth redirect URL for a social provider configured by the current project.

Input​

FieldTypeRequiredDescription
providerString!✓External provider code.

Result​

Response type - SocialAuthUrl, containing the redirect URL and provider code.

Errors​

  • SOCIAL_PROVIDER_DISABLED - the provider is not configured or is disabled for the project.

Exchange example​

Request
documentId: socialAuthUrl
{
"documentId": "socialAuthUrl",
"variables": {
"provider": "google"
}
}
Response
200 OK
{
"data": {
"socialAuthUrl": {
"url": "https://project.example/auth/google",
"provider": "google"
}
}
}

Login by code​

MutationdocumentId: sendMagicCodeauth: public

sendMagicCode​

Description​

Sends a one-time login code to the supplied email address. The same flow can create an account when the address is not registered yet.

Input​

FieldTypeRequiredDescription
emailString!✓User email
gameServerIdInt-Game server ID.

Result​

Response type - OperationResult.

Errors​

  • METHOD_DISABLED - magic code login is disabled for the project.
  • MAGIC_CODE_ALREADY_SENT - another code was requested before the resend interval elapsed.

Exchange example​

Request
documentId: sendMagicCode
{
"documentId": "sendMagicCode",
"variables": {
"email": "[email protected]",
"gameServerId": 1
}
}
Response
200 OK
{
"data": {
"sendMagicCode": {
"message": "Login code sent"
}
}
}
MutationdocumentId: loginMagicCodeauth: public

loginMagicCode​

Description​

Verifies the one-time code and returns a session or a 2FA challenge. A new user is created when the code belongs to an unregistered address.

Input​

FieldTypeRequiredDescription
emailString!✓User email
codeString!✓Confirmation or authorization code.
gameServerIdInt-Game server ID.
utmJSON-UTM tags

Result​

Response type - LoginResult.

Errors​

  • METHOD_DISABLED - magic code login is disabled for the project.
  • MAGIC_CODE_EXPIRED - the code is invalid or expired.
  • TOO_MANY_ATTEMPTS - the verification attempt limit was exceeded.
  • USER_BANNED - the account is blocked.

Exchange example​

Request
documentId: loginMagicCode
{
"documentId": "loginMagicCode",
"variables": {
"code": "123456",
"email": "[email protected]",
"gameServerId": 1,
"utm": {
"source": "site",
"medium": "web",
"campaign": "launch"
}
}
}
Response
200 OK
{
"data": {
"loginMagicCode": {
"sessionId": "session-token",
"user": {
"id": "1001",
"email": "[email protected]"
}
}
}
}
MutationdocumentId: sendMagicLinkauth: public

Description​

Sends a one-time passwordless login link. The same flow can create an account when the address is not registered yet.

Input​

FieldTypeRequiredDescription
emailString!✓User email
gameServerIdInt-Game server ID.

Result​

Response type - OperationResult.

Errors​

  • METHOD_DISABLED - magic link login is disabled for the project.
  • MAGIC_LINK_ALREADY_SENT - another link was requested before the resend interval elapsed.

Exchange example​

Request
documentId: sendMagicLink
{
"documentId": "sendMagicLink",
"variables": {
"email": "[email protected]",
"gameServerId": 1
}
}
Response
200 OK
{
"data": {
"sendMagicLink": {
"message": "Login link sent"
}
}
}
MutationdocumentId: loginMagicLinkauth: public

Description​

Verifies the one-time link token and returns a session or a 2FA challenge. A new user is created when the token belongs to an unregistered address.

Input​

FieldTypeRequiredDescription
tokenString!✓One-time authorization token.
emailString!✓User email
gameServerIdInt-Game server ID.
utmJSON-UTM tags

Result​

Response type - LoginResult.

Errors​

  • METHOD_DISABLED - magic link login is disabled for the project.
  • MAGIC_LINK_EXPIRED - the token is invalid or expired.
  • TOO_MANY_ATTEMPTS - the verification attempt limit was exceeded.
  • USER_BANNED - the account is blocked.

Exchange example​

Request
documentId: loginMagicLink
{
"documentId": "loginMagicLink",
"variables": {
"token": "magic-token",
"email": "[email protected]",
"gameServerId": 1,
"utm": {
"source": "site",
"medium": "web",
"campaign": "launch"
}
}
}
Response
200 OK
{
"data": {
"loginMagicLink": {
"sessionId": "session-token",
"user": {
"id": "1001",
"email": "[email protected]"
}
}
}
}

Logout​

MutationdocumentId: logoutauth: Bearer session

logout​

Description​

Ends the current user session.

Input​

The operation does not accept variables.

Result​

Response type - OperationResult.

When the session is missing or already closed, the operation also returns a completion message.

Exchange example​

Request
documentId: logout
{
"documentId": "logout",
"variables": {}
}
Response
200 OK
{
"data": {
"logout": {
"message": "Session ended"
}
}
}