Skip to main content

Integration Checklist

Use this list before launching a website, launcher, or external integration.

Requests​

  • All calls go to POST /graphql.
  • The request body contains documentId and variables.
  • The query field is not sent from browsers or public clients.
  • Content-Type is always application/json.

Project Context​

  • X-Project-Context comes from identity.contextToken in the latest downloaded project configuration.
  • Use changeServer to switch the selected server.
  • Public catalogs and operations targeting a specific server pass variables.gameServerId.
  • Use variables.gameServerId only for operations with an explicit target server.
  • Clients do not send the platform or login server; the API derives both values.
  • Accept-Language is sent for localized messages.

Authorization​

  • After sign-in, sessionId is stored safely and sent as Authorization: Bearer <sessionId>.
  • Public operations without a session are limited to registration, sign-in, settings, and public catalog flows.
  • 2FA, passkey, and social sign-in are handled as separate user states.

Security​

  • Passwords, PIN codes, tokens, and payment details do not appear in URLs or client logs.
  • Errors are shown to users safely, without unnecessary technical details.
  • Web analytics does not send IP, User-Agent, or access keys from the browser.

Verification​

  • Every used documentId exists in the operations reference.
  • data: null, the errors array, and partial GraphQL responses are handled.
  • Expired sessions, wrong platform, and unavailable server scenarios are tested.