Technical Questions
Answers about client installation, GraphQL API, project settings, security, payments, and diagnostics.
Client Installation and Configuration
1. Where is the client connection configured?
Local parameters are stored in src/config.php: database connection, public API URL, cookie domain, globalSalt, and system paths. Project settings are managed in the panel.
2. Should I edit project settings on the client manually?
No. Game servers, menus, payments, modules, visual theme, and other project parameters are changed in the SaaS panel and delivered to the client through the standard settings update flow.
3. What is globalSalt?
It is a unique salt for one installation, used to protect CSRF/cookie values. The installer generates it locally; do not copy it between sites.
4. What should I do if the error says globalSalt is required?
Check that $config['globalSalt'] is filled in src/config.php. For a new site, return to the installer. Do not replace it on a running site unless necessary, because active sessions will be invalidated.
5. Which PHP and MySQL versions should I use?
Use current PHP and MySQL versions supported by the current client release and hosting. Local development in OpenServer uses MySQL 8.4.
6. Can I run the client behind Nginx?
Yes. Configure rewrite to the public entry point and block direct access to non-public directories, logs, and temporary files.
GraphQL API
7. How is an API request made?
All public calls use POST /graphql and contain only documentId and variables.
{
"documentId": "me",
"variables": {}
}
8. Can I send the query field?
No. Public clients do not send arbitrary GraphQL documents. Use documented IDs only.
9. Which headers are required?
At minimum, send Content-Type: application/json and X-Project-Context with identity.contextToken from the current project configuration. For authorized operations, also send Authorization: Bearer <sessionId>.
10. How do I pass the selected server?
Pass the selected server ID in variables.gameServerId. The server must belong to the project from X-Project-Context.
11. Do I need to pass the platform?
No. The API derives the platform and login server from the selected server and project configuration.
12. How do I get a session?
Call login. The response contains sessionId, which is then sent in Authorization.
13. How does password recovery work?
Call sendPasswordRecoveryEmail, then confirmPasswordRecoveryCode. The recovery code is one-time and valid only for the current project.
14. Why can getGameCredentials require a PIN?
Viewing a game password is a sensitive operation. If PIN protection is enabled for the project or user, send pin together with accountLogin.
Security
15. Can I pass secret keys to the browser?
No. Browser requests use only the public GraphQL API, the user session, and public project context. Integration, payment, and provider secrets must not appear in client-side code.
16. Where should payment and provider keys be stored?
In project settings or protected storage when enabled. Do not store them in templates, JavaScript, URLs, logs, or public files.
17. How should I log errors safely?
Log documentId, HTTP status, error category, and X-Request-Id. Mask email, tokens, PINs, passwords, wallets, and payment details.
18. What should I do if a key may be leaked?
Rotate the key in the panel, update the client release or integration settings, clean public logs, and review recent activity in the audit log.
Payments
19. A payment was created but not credited. What should I check?
Check invoice status, callback/webhook URL in the aggregator, currency, amount, selected project, and public availability of the site.
20. What does a payment signature error mean?
Usually it means a wrong secret key, wrong merchant id, wrong currency, or callback from another payment profile.
21. Can payment settings differ between servers?
Yes. A project can have shared payment settings and server-level overrides when the selected scenario supports them.
Game Accounts and Servers
22. Why are characters not displayed?
Check variables.gameServerId, game account binding, connection to the game data source, and whether characters exist on the server.
23. Why can't I bind a game account?
Possible reasons: wrong password, account already bound, wrong server selected, account limit reached, or PIN required.
24. Why is a module menu item missing?
Check whether the module is purchased, enabled for the project/server, and allowed in menu settings.
Analytics and Launcher
25. How does web analytics work?
Open Journal -> Web Analytics for visits, audience, page speed, forms, clicks and website errors. The guide covers the fields and examples for every section.
26. Why doesn't the launcher or website write analytics?
For the website, check the main API address, project connection and report dates. A separate website-analytics address is not required. Browser blocking and a lack of matching visits also affect results. Check launcher settings and reports separately.
Diagnostics
27. What should I include in a support request?
Include domain, project ID, team ID, server, error time, reproduction steps, screenshot, documentId, and X-Request-Id if the issue is API-related.
28. How do I verify that docs match the API?
Compare the used documentId with the API reference and check the request example in the specific operation section.
29. What should I do if updates stop working after moving the site?
Check whether internal_data was transferred. If the installation identity was lost, revoke the old installation in the project card, generate a new one-time code, and enroll the site again through the local client admin. User data and the currently installed version are not removed.