Documentation

auth4.dev signs players in to your web app or game and gives your server short-lived tokens it can verify. This page explains the moving parts and where to start.

How it fits together

  1. Project. A project is an isolated tenant with its own users, applications, sign-in methods and token issuer, https://auth.auth4.dev/t/{projectId}. Use one project per game or product.
  2. Applications. Each place a player signs in from is an application with a public client ID. A browser application is a single-page or web app. Agame (device sign-in) application is a native game that cannot host a browser redirect. Neither type has a client secret.
  3. Sign-in methods. Players sign in on the hosted login page with an email code or Discord, or start as guests and upgrade later.
  4. Tokens. After sign-in your app holds an access token that expires after five minutes. Your game server verifies it with the server SDK before trusting the player's identity.

Where to start

You want to…Read
Create a project and register an applicationConsole onboarding
Turn on email codes or DiscordEmail sign-in, Discord sign-in
Add sign-in to a web pageBrowser quickstart
Protect a game API or backendServer quickstart
Sign players in from a Unity gameUnity quickstart
Understand token lifetimes and revocationTokens and revocation
Look up an endpointAPI reference

Environments

The hosted service uses three origins:

  • https://auth.auth4.dev: the token issuer, hosted login and device approval pages.
  • https://app.auth4.dev: the developer console.
  • https://auth4.dev: this site.

Copy the issuer from the console rather than building it yourself. Local and staging deployments use different origins, and the console always shows the one that issues your project's tokens.