Authentication for web apps and games
Sign players in without running your own auth server.
auth4.dev handles sign-in for your web app, game client and game API. Use email codes, Discord, guest accounts and device sign-in, then verify short-lived tokens on your own server.
What you get
Email codes
Players sign in with a six-digit code sent to their inbox. There are no passwords to store or reset.
Discord sign-in
Connect your Discord application and let players use the account they already have for gaming.
Guests that upgrade safely
Players start without an account and add an email or Discord identity later. Their user ID stays the same, and accounts are never merged silently.
Device sign-in for games
Show a short code in your game and let the player approve it on a phone or PC. No browser runs inside the game.
Isolated projects
Each project is its own tenant with its own issuer, users, applications and sign-in settings. Tokens issued for one project are rejected by another.
Developer console
Create projects, register applications, turn on sign-in methods, and manage users, sessions and audit events.
SDKs for where your players are
Three SDKs, each with a runnable example in the repository. The snippets below are taken from those examples.
Browser (TypeScript)
Hosted login with authorization code and PKCE. Access tokens stay in memory. Browser quickstart
examples/browser/src/main.tsconst auth4 = new Auth4BrowserClient({
issuer: "https://auth.auth4.dev/t/ten_replace_with_your_tenant",
clientId: "cli_replace_with_your_browser_client",
redirectUri: `${window.location.origin}${window.location.pathname}`,
});Server (TypeScript)
Verify access tokens in Node.js, Cloudflare Workers or Hono. Server quickstart
examples/server/shared/protected-endpoint.tsexport async function handleProtectedRequest(
request: Request,
client: Auth4ServerClient,
): Promise<Response> {
const claims = await authenticateRequest(request, client);
if (!claims) return unauthorizedResponse();
return Response.json({ subject: claims.sub, tenant: claims.tenant_id });
}Unity (C#)
Device sign-in, guest play and rotating refresh tokens for native games. Unity quickstart
packages/sdk-unity/Samples~/DeviceLogin/DeviceLoginSample.cs_client = new Auth4Client(new Auth4ClientOptions
{
TenantId = tenantId,
ClientId = clientId,
AuthOrigin = authOrigin,
Transport = new UnityWebRequestTransport(),
});Built on open standards
- OAuth 2.0 authorization code with S256 PKCE. Implicit and password grants are refused.
- A documented subset of OpenID Connect, with a separate issuer for each project.
- Device authorization (RFC 8628) for consoles, desktops and other native games.
- RS256 tokens that expire after five minutes, plus rotating refresh tokens with reuse detection.
Clear about what it doesn't do yet
This is a focused first release. It has no passwords, passkeys, enterprise single sign-on, custom domains, team invitations or billing yet.