Skip to main content

Account Security

All operations require X-Project-Context. Configuration operations require a user session; completing a login challenge happens before a session exists.

PIN protection​

documentIdAuthorizationVariablesResult
togglePinShieldBearer sessionenable: Boolean!, pin: String!OperationResult!
recoverPinBearer sessionmethod: String!OperationResult!

togglePinShield enables or disables an additional PIN check for financial and other protected actions. recoverPin sends recovery through a confirmed user channel.

Selected server​

changeServer accepts serverId: Int! and selects a game server in the current project.

2FA methods​

ValuePurpose
totpSix-digit RFC 6238 code from an authenticator app
emailOne-time code sent to a confirmed email address
recovery_codeOne-time recovery code available only during login

recovery_code cannot be enrolled as a standalone method. A recovery-code set is created after the first 2FA method is enabled.

Enroll a method​

Enrollment requires two operations: submit the current password, then confirm the selected method's code.

Request
documentId: beginTwoFactorEnrollment
{
"documentId": "beginTwoFactorEnrollment",
"variables": {
"method": "totp",
"currentPassword": "account-password"
}
}
Response
200 OK
{
"data": {
"beginTwoFactorEnrollment": {
"token": "opaque-challenge-token",
"availableMethods": [
"totp"
],
"expiresAt": "2026-07-19 12:10:00",
"provisioningUri": "otpauth://totp/...",
"manualKey": "BASE32SECRET"
}
}
}

Verify the code through confirmTwoFactorEnrollment:

documentId: confirmTwoFactorEnrollment
{
"documentId": "confirmTwoFactorEnrollment",
"variables": {
"challengeToken": "opaque-challenge-token",
"code": "123456"
}
}

The response contains a new recovery-code set only when the first method is enabled. Codes are shown once: prompt the user to store them.

For email, beginTwoFactorEnrollment immediately sends a code to the confirmed address. requestTwoFactorChallengeCode resends an email code for an existing challenge under a rate limit.

Remove a method​

StepdocumentIdVariables
1beginTwoFactorRemovalmethod, currentPassword
2confirmTwoFactorRemovalchallengeToken, code

After removing the final method, recovery codes and incomplete confirmation requests are no longer valid.

Recovery codes​

documentIdPurpose
twoFactorRecoveryCodesCountCount unused codes
beginTwoFactorRecoveryCodeReplacementVerify the password and begin replacement
confirmTwoFactorRecoveryCodeReplacementVerify an active factor and return the new set

Replacement immediately invalidates every old code. Each recovery code can be used to sign in only once.

Finish sign-in​

login, loginGameAccount, magic link, and magic code return twoFactorChallenge when 2FA is enabled. Send its token to verifyTwoFactorChallenge:

documentId: verifyTwoFactorChallenge
{
"documentId": "verifyTwoFactorChallenge",
"variables": {
"challengeToken": "opaque-challenge-token",
"method": "recovery_code",
"code": "ABCD-EFGH-IJKL"
}
}

Successful confirmation returns a session. If the challenge expires or reaches its attempt limit, start sign-in again.

Passkeys​

Manage credentials​

documentIdAuthorizationPurpose
passkeyCredentialsBearer sessionList the current user's Passkeys
passkeyRegOptionsBearer sessionGet WebAuthn creation options
passkeyRegisterBearer sessionVerify attestation and store the credential
deletePasskeyBearer sessionDelete a credential by credentialId

passkeyRegister accepts attestation: JSON! and optional name: String. Its result is PasskeyCredential, not OperationResult.

documentId: passkeyRegister
{
"documentId": "passkeyRegister",
"variables": {
"attestation": {},
"name": "Windows Hello"
}
}

Options are single-use within one WebAuthn procedure. Request new options for another attempt.

Passkey sign-in​

StepdocumentIdAuthorization
1passkeyAuthOptionspublic
2loginPasskeypublic

loginPasskey accepts assertion: JSON! and optional utm: JSON. Successful cryptographic verification creates the user session.

Common errors​

ErrorCause
UNAUTHENTICATEDA configuration operation has no valid session
INVALID_CREDENTIALSThe current password is incorrect
TWO_FACTOR_INVALID_CODEThe code is invalid or was already used
TWO_FACTOR_TOKEN_EXPIREDThe challenge expired, exhausted attempts, or was consumed
TWO_FACTOR_METHOD_UNAVAILABLEThe method is not enabled or not allowed by the challenge
PASSKEY_INVALID_ASSERTIONWebAuthn assertion/attestation verification failed
PASSKEY_NOT_FOUNDThe credential was not found