Skip to main content

Integration Security

These rules apply to websites, the launcher, player cabinets, and external integrations that use the MMO-DEV WEB API.

Client Requests​

  • Send only documentId and variables; do not send a query field from browsers.
  • Send only the fields listed in the operation reference.
  • Pass the selected server only through variables.gameServerId.
  • Use Authorization: Bearer <sessionId> only after successful authorization.
  • Do not store passwords, PIN codes, 2FA codes, or tokens in URLs, localStorage, or logs.

Web Analytics​

  • Use the built-in analytics code from the cabinet or the template function when it is available in the theme.
  • Do not send IP address, User-Agent, or private keys from the browser.
  • Site events should contain only safe event context: page, event type, screen size, language, UTM, and safe technical metrics.

Keys and Access​

  • Use only the access keys shown in the control panel for the specific integration.
  • Do not pass access keys through public JavaScript, URLs, page templates, or client logs.
  • Keep payment provider keys, mail provider keys, social application secrets, and other integration credentials only in project settings. Do not place these values in templates, JavaScript, URLs, or client logs.

Logging and Debugging​

Log documentId, HTTP status, error category, and technical request id when available. Mask email, tokens, keys, wallets, PIN codes, and payment details.

Before Release​

Review the integration checklist, API errors, and access rules for every operation that is available without a session.