Account Security
All operations require X-Project-Context. Configuration operations require a user session; completing a login challenge happens before a session exists.
PIN protection
documentId | Authorization | Variables | Result |
|---|---|---|---|
togglePinShield | Bearer session | enable: Boolean!, pin: String! | OperationResult! |
recoverPin | Bearer session | method: String! | OperationResult! |
togglePinShield enables or disables an additional PIN check for financial and other protected actions. recoverPin sends recovery through a confirmed user channel.
Selected server
changeServer accepts serverId: Int! and selects a game server in the current project.
2FA methods
| Value | Purpose |
|---|---|
totp | Six-digit RFC 6238 code from an authenticator app |
email | One-time code sent to a confirmed email address |
recovery_code | One-time recovery code available only during login |
recovery_code cannot be enrolled as a standalone method. A recovery-code set is created after the first 2FA method is enabled.
Enroll a method
Enrollment requires two operations: submit the current password, then confirm the selected method's code.
{
"documentId": "beginTwoFactorEnrollment",
"variables": {
"method": "totp",
"currentPassword": "account-password"
}
}
{
"data": {
"beginTwoFactorEnrollment": {
"token": "opaque-challenge-token",
"availableMethods": [
"totp"
],
"expiresAt": "2026-07-19 12:10:00",
"provisioningUri": "otpauth://totp/...",
"manualKey": "BASE32SECRET"
}
}
}
Verify the code through confirmTwoFactorEnrollment:
{
"documentId": "confirmTwoFactorEnrollment",
"variables": {
"challengeToken": "opaque-challenge-token",
"code": "123456"
}
}
The response contains a new recovery-code set only when the first method is enabled. Codes are shown once: prompt the user to store them.
For email, beginTwoFactorEnrollment immediately sends a code to the confirmed address. requestTwoFactorChallengeCode resends an email code for an existing challenge under a rate limit.
Remove a method
| Step | documentId | Variables |
|---|---|---|
| 1 | beginTwoFactorRemoval | method, currentPassword |
| 2 | confirmTwoFactorRemoval | challengeToken, code |
After removing the final method, recovery codes and incomplete confirmation requests are no longer valid.
Recovery codes
documentId | Purpose |
|---|---|
twoFactorRecoveryCodesCount | Count unused codes |
beginTwoFactorRecoveryCodeReplacement | Verify the password and begin replacement |
confirmTwoFactorRecoveryCodeReplacement | Verify an active factor and return the new set |
Replacement immediately invalidates every old code. Each recovery code can be used to sign in only once.
Finish sign-in
login, loginGameAccount, magic link, and magic code return twoFactorChallenge when 2FA is enabled. Send its token to verifyTwoFactorChallenge:
{
"documentId": "verifyTwoFactorChallenge",
"variables": {
"challengeToken": "opaque-challenge-token",
"method": "recovery_code",
"code": "ABCD-EFGH-IJKL"
}
}
Successful confirmation returns a session. If the challenge expires or reaches its attempt limit, start sign-in again.
Passkeys
Manage credentials
documentId | Authorization | Purpose |
|---|---|---|
passkeyCredentials | Bearer session | List the current user's Passkeys |
passkeyRegOptions | Bearer session | Get WebAuthn creation options |
passkeyRegister | Bearer session | Verify attestation and store the credential |
deletePasskey | Bearer session | Delete a credential by credentialId |
passkeyRegister accepts attestation: JSON! and optional name: String. Its result is PasskeyCredential, not OperationResult.
{
"documentId": "passkeyRegister",
"variables": {
"attestation": {},
"name": "Windows Hello"
}
}
Options are single-use within one WebAuthn procedure. Request new options for another attempt.
Passkey sign-in
| Step | documentId | Authorization |
|---|---|---|
| 1 | passkeyAuthOptions | public |
| 2 | loginPasskey | public |
loginPasskey accepts assertion: JSON! and optional utm: JSON. Successful cryptographic verification creates the user session.
Common errors
| Error | Cause |
|---|---|
UNAUTHENTICATED | A configuration operation has no valid session |
INVALID_CREDENTIALS | The current password is incorrect |
TWO_FACTOR_INVALID_CODE | The code is invalid or was already used |
TWO_FACTOR_TOKEN_EXPIRED | The challenge expired, exhausted attempts, or was consumed |
TWO_FACTOR_METHOD_UNAVAILABLE | The method is not enabled or not allowed by the challenge |
PASSKEY_INVALID_ASSERTION | WebAuthn assertion/attestation verification failed |
PASSKEY_NOT_FOUND | The credential was not found |