Authentication for web apps and games

Sign players in without running your own auth server.

auth4.dev handles sign-in for your web app, game client and game API. Use email codes, Discord, guest accounts and device sign-in, then verify short-lived tokens on your own server.

What you get

SDKs for where your players are

Three SDKs, each with a runnable example in the repository. The snippets below are taken from those examples.

Browser (TypeScript)

Hosted login with authorization code and PKCE. Access tokens stay in memory. Browser quickstart

Excerpt from examples/browser/src/main.ts
const auth4 = new Auth4BrowserClient({
  issuer: "https://auth.auth4.dev/t/ten_replace_with_your_tenant",
  clientId: "cli_replace_with_your_browser_client",
  redirectUri: `${window.location.origin}${window.location.pathname}`,
});

Server (TypeScript)

Verify access tokens in Node.js, Cloudflare Workers or Hono. Server quickstart

Excerpt from examples/server/shared/protected-endpoint.ts
export async function handleProtectedRequest(
  request: Request,
  client: Auth4ServerClient,
): Promise<Response> {
  const claims = await authenticateRequest(request, client);
  if (!claims) return unauthorizedResponse();
  return Response.json({ subject: claims.sub, tenant: claims.tenant_id });
}

Unity (C#)

Device sign-in, guest play and rotating refresh tokens for native games. Unity quickstart

Excerpt from packages/sdk-unity/Samples~/DeviceLogin/DeviceLoginSample.cs
_client = new Auth4Client(new Auth4ClientOptions
{
    TenantId = tenantId,
    ClientId = clientId,
    AuthOrigin = authOrigin,
    Transport = new UnityWebRequestTransport(),
});

Built on open standards

  • OAuth 2.0 authorization code with S256 PKCE. Implicit and password grants are refused.
  • A documented subset of OpenID Connect, with a separate issuer for each project.
  • Device authorization (RFC 8628) for consoles, desktops and other native games.
  • RS256 tokens that expire after five minutes, plus rotating refresh tokens with reuse detection.

How tokens work

Clear about what it doesn't do yet

This is a focused first release. It has no passwords, passkeys, enterprise single sign-on, custom domains, team invitations or billing yet.

Read the MVP limitations