Skip to main content

Social Networks

Social sign-in lets players use Google, Steam, Discord, VK, or Telegram. If 2FA is enabled for the account, the second factor remains mandatory.

Adding a Provider​

  1. Create an OAuth application in the selected provider dashboard.
  2. Open Settings -> Social Providers.
  3. Click Add Social Provider.
  4. Select the project and provider type.
  5. Enter Client ID, Client Secret, and Callback URL.
  6. Enable and save the provider.

For Google in the main MMO-DEV WEB environment, use this callback:

https://api.mmo-web.dev/auth/social/google/callback
Provider credentials and callback

Telegram​

Use a separate project bot for players.

  1. Open your bot in the @BotFather -> Login Widget mini app.
  2. Add the Callback URL to Allowed URLs. For the main environment, use https://api.mmo-web.dev/auth/social/telegram/callback.
  3. Copy the displayed Client ID and Client Secret into the selected project's Telegram provider settings. A Bot API token is not a Client Secret.
  4. Keep RS256 selected under Login Widget -> Advanced.
  5. Enable and save the provider.

See the Telegram setup guide for the BotFather fields.

Where the Player Returns​

The provider first returns the browser to api.mmo-web.dev. The player is then redirected with a one-time sign-in code to the project website:

https://site-project.tld/auth/social-callback?code=...

This is why the OAuth application uses the MMO-DEV WEB API domain, not the admin panel or a direct client callback.

Enabling It for a Project​

Open the project, select the Cabinet tab, and enable social sign-in. Save the project and upload the updated settings to the client website.

Verification​

  1. Sign in to an existing player account and open Settings.
  2. For Telegram, find the Telegram section on the Settings tab, select Bind, then Continue in Telegram. Other social accounts are linked on the Security tab. Enter your PIN when requested.
  3. Approve the connection with the provider and wait to return to settings with a successful linking message.
  4. In a private window, test sign-in with the linked profile and the 2FA prompt when enabled.

If you cancel or confirmation expires, start linking again. Unlink the previous Telegram account before replacing it. Disabled providers are not offered for new connections.