Integration Checklist
Use this list before launching a website, launcher, or external integration.
Requests
- All calls go to
POST /graphql. - The request body contains
documentIdandvariables. - The
queryfield is not sent from browsers or public clients. Content-Typeis alwaysapplication/json.
Project Context
X-Project-Contextcomes fromidentity.contextTokenin the latest downloaded project configuration.- Use
changeServerto switch the selected server. - Public catalogs and operations targeting a specific server pass
variables.gameServerId. - Use
variables.gameServerIdonly for operations with an explicit target server. - Clients do not send the platform or login server; the API derives both values.
Accept-Languageis sent for localized messages.
Authorization
- After sign-in,
sessionIdis stored safely and sent asAuthorization: Bearer <sessionId>. - Public operations without a session are limited to registration, sign-in, settings, and public catalog flows.
- 2FA, passkey, and social sign-in are handled as separate user states.
Security
- Passwords, PIN codes, tokens, and payment details do not appear in URLs or client logs.
- Errors are shown to users safely, without unnecessary technical details.
- Web analytics does not send IP, User-Agent, or access keys from the browser.
Verification
- Every used
documentIdexists in the operations reference. data: null, theerrorsarray, and partial GraphQL responses are handled.- Expired sessions, wrong platform, and unavailable server scenarios are tested.