MVP limitations

auth4.dev is a focused first release. This page lists what isn't included yet, so you can plan around it.

Sign-in methods

  • No passwords, passkeys, magic links or one-time codes by SMS.
  • Discord is the only social provider. There's no enterprise single sign-on (SAML or OIDC federation).
  • Verification emails use fixed wording and a fixed sender.
  • The device approval page doesn't offer its own sign-in form. The player needs an existing auth4.dev browser session.

SDKs

  • The SDKs aren't published to npm or the Unity Asset Store yet. Use them from the auth4.dev repository. The Unity package's licence terms aren't final.
  • The browser SDK has no refresh tokens or silent renewal. Players sign in again after the five-minute access token expires or the page reloads.
  • The browser SDK has no guest sign-in or upgrade methods.
  • Unity can't link Discord to a guest, and Unity WebGL builds can't upgrade guests.
  • There are no SDKs for other engines or languages. Use the HTTP endpoints directly.

Tokens

  • Tokens carry a fixed set of claims. Custom claims and player roles aren't supported.
  • Access tokens don't indicate whether the player is a guest.
  • Offline verification has up to five minutes of revocation delay. See Tokens and revocation.
  • The discovery document doesn't list the device authorization endpoint.

Console and accounts

  • No team invitations. Projects can't be shared from the console yet.
  • No custom domains: hosted login always runs on the auth4.dev auth origin.
  • No billing or plans. This site doesn't publish pricing or service-level commitments.
  • Device sign-in settings, such as code length and lifetime, aren't configurable.
  • No webhooks or event streaming. The audit log is viewable in the console for 30 days.

What this documentation doesn't claim

auth4.dev doesn't claim any security certification, compliance attestation or regulatory approval. The security boundaries and retention pages describe how the system is built, not an audit result.