Decline custom login
Tells Stash that the game will not approve this login code, and why. A declined code can no longer be approved. This is a server-side endpoint and should not be called from the client.
Versioned HMAC-SHA256 signature authenticating server-to-server SDK requests (your backend calling Stash), as opposed to client-side SDK operations. Recommended over the deprecated X-Stash-Api-Key for the best security. Header format: v1;{appId};{unixMillisTimestamp};{base64Signature} (semicolon-delimited). {base64Signature} is the base64-encoded HMAC-SHA256 of the string {unixMillisTimestamp}.{requestBody} using your app ingress secret (the ingress secret is shown base64-encoded in Studio; base64-decode it to the raw bytes used as the HMAC key), where {requestBody} is the compact canonical request JSON for POST requests and empty for GET requests. The timestamp must be within 5 minutes of Stash server time. Your appId is your immutable app identifier, shown in Stash Studio under Project Settings > App details; your ingress secret is under Project Settings > API Secrets.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
curl -X POST "https://example.com/sdk/custom_login/decline" \ -H "Content-Type: application/json" \ -d '{ "code": "string", "reason": "LOGIN_DECLINE_REASON_UNSPECIFIED" }'{}How is this guide?
Approve custom login POST
Approves a pending webshop login from your game server. Send the login code the webshop passed to your game, through the login deep link or a QR code, together with the signed-in player as user; Stash then completes the webshop login as that player. Authenticate the request with an HMAC signature of the request body, or with the deprecated API key. This is a server-side endpoint and must not be called from the game client.
Force Logout user POST
Logs out a user by invalidating their session. This endpoint is typically called when a user signs out of the game or switches to another account.