Guest accounts
Guests let players start without signing up. A guest is a real account with a stable user ID, and you can upgrade it to email or Discord later without losing progress.
Turn guests on
Guests are on for new projects. Change it with Guest accounts on the project's sign-in methods page. Guest creation is limited to ten per application and IP address per hour.
How a guest becomes a full account
- The game creates a guest session. The response includes a stable
user_id, which is also the access token'ssub. Store game progress against it. - When the player wants to keep their progress, the game creates a linking intent with the guest's access token. It is valid for about five minutes.
- The player proves an email address with a six-digit code, or signs in with Discord.
- The game completes the upgrade. auth4.dev attaches the new identity to the sameuser, returns new tokens and a new session ID, and revokes the guest session.
Your server sees the same sub before and after the upgrade, so no data migration is needed.
When the identity is already in use
If the email address or Discord account already belongs to a different player, the upgrade fails with 409 identity_in_use.
- The guest session is unchanged and the player can keep playing.
- Nothing is merged. auth4.dev never combines two users or their game data, and a matching email address never links accounts.
Give the player a clear choice:
| Choice | What your game does |
|---|---|
| Use a different email or Discord account | Start a new upgrade with the other identity. |
| Keep playing as a guest | Do nothing. Remind the player that guest progress can be lost. |
| Switch to the existing account | Warn that guest progress stays with the guest, then sign out and sign in to the other account. If you want to move progress, do it in your own backend after the player is signed in to both. auth4.dev doesn't do this for you. |
Upgrade safety rules
- Only an active guest session can be upgraded, and only by the session that started the linking intent.
- Proofs and linking intents are single-use, short-lived and tied to the same project, application and browser flow. Replayed, expired or mismatched proofs fail.
- A new email or Discord identity proven during the upgrade moves to the guest only if it was created for this upgrade and was never used to sign in.
- Upgrades are limited to ten per player per hour.
SDK support
| Client | Guest sign-in | Upgrade by email | Upgrade by Discord |
|---|---|---|---|
| Unity (native platforms) | Yes | Yes, in-game code entry | Not yet |
| Unity WebGL | Yes | No | No |
| Browser SDK | Not in the SDK | Not in the SDK | Not in the SDK |
Web games can call the guest endpoints directly and use the hosted/login/upgrade window for the upgrade step. See the guest API reference and the hosted login reference.