Console onboarding
The developer console is where you create projects, register applications and choose sign-in methods. This guide takes you from a new console account to a client ID you can paste into an SDK.
1. Sign in to the console
Open app.auth4.dev and sign in with your email address. The console sends a one-time code. Your console account is separate from the player accounts in your projects: players can never sign in to the console, and their tokens are never accepted by management APIs.
2. Create a project
On your first visit the console shows Welcome to auth4.dev and the New project form.
- Enter a Project name. Players see it on the hosted sign-in page, and you can change it later.
- Select Create project.
New projects allow sign-up, email codes and guest accounts. Discord stays off until you add its credentials. The console then opens the project's applications page.
3. Register an application
Under Register an application, fill in the fields below and select Register application.
| Field | What to enter |
|---|---|
| Application name | A name players recognise, such as your game's title. |
| Application type | Browser for web pages and single-page apps. Game (device sign-in) for Unity and other native builds. You can't change the type later. |
| Redirect URIs (browser only) | One per line. Each must exactly match the redirectUri your app passes to the SDK. Use HTTPS, or http://localhost during development. Wildcards and fragments are rejected. |
| Allowed origins (browser only) | The origin your page is served from, such as https://play.example.com, with no path. |
| Scopes | openid is required. Add email if your app reads the player's email address. Game applications that should stay signed in between token refreshes needoffline_access. The list is limited by the project's Allowed scopes. |
You never choose grant types or credentials. Browser applications use authorization code with PKCE. Game applications use device authorization. Both can refresh tokens when they haveoffline_access.
4. Copy the integration settings
Open the application to see Integration settings. These values are public, so you can commit them to client code.
| Console value | Used as |
|---|---|
| Issuer | issuer in the browser and server SDKs. It ends in/t/{projectId}. |
| Client ID | clientId in the browser SDK, ClientId in Unity. |
| Audience | audience in the server SDK. It is the client ID: tokens for this application use it as their aud claim. |
| Callback URL (browser) | The first registered redirect URI. |
| Device authorization endpoint (game) | Used by the Unity SDK automatically. You only need it for a custom client. |
The project ID that the server and Unity SDKs call tenantId is theProject ID under Project identifiers in project settings, next to theDiscovery URL.
5. Choose sign-in methods
The sign-in methods page has Allow new players to sign up, Guest accounts and Email verification codes. To add Discord, see Discord sign-in. Changes apply to the next sign-in attempt.
Project roles
| Role | Can do |
|---|---|
| Owner | Everything: project settings, sign-in methods, provider secrets, applications, and user and session actions. |
| Admin | Create, edit and disable applications. Everything else is read-only. |
| Viewer | Read-only access to the project, its applications, users, sessions and audit log. |
Inviting teammates isn't available in this release. See MVP limitations.
Disabling an application
Disabling an application stops new sign-ins and refreshes for it straight away. Access tokens already issued stay valid until they expire, up to five minutes. Servers that verify tokens offline keep accepting them until then. See revocation limits.