Player Authentication

Account Linking

Learn how to connect a player's webshop session with their game client through account linking. Understand deep link setup, integration steps for different engines, and Unity-specific implementation using the Stash SDK.

Account linking connects a player's webshop session with their game client.

The webshop launches the game through a deep link (on mobile) or a QR code (on desktop). The deep link carries a session code. The game client attaches the player's authentication data to this code and sends both to the Stash API to complete login.

Set up the login deep link on the App Login page in Stash Studio. Use a URL scheme that clearly represents your game, and register it in your game client on each platform. For example, the demo app uses howlingwoods://.

Open App Login

Open your game in Stash Studio. In the main menu, click Webshop, then App Login.

Turn on App Login

Turn on Enable App Login and enter a Button label. Players see a "Sign in with" button with that label.

In Login deep link, enter your app's deep link with %s where the login code goes, for example yourscheme://stash/login?code=%s. Use %s exactly once. This is not the Account Linking URL scheme.

Set a minimum app version (optional)

In Minimum app version (optional), enter the oldest app version that can sign in, as numbers separated by dots, for example 2.37.0. Players with an older version are asked to update first. Leave it empty for no minimum.

To require a different version on one platform, also fill in Minimum iOS app version (optional) or Minimum Android app version (optional). A platform's own minimum applies to players on that platform instead of Minimum app version. Leave a platform field empty to use Minimum app version there.

Stash picks the minimum for the platform your game server sends with the login. When no platform is sent, Minimum app version applies.

Save

Click Save. Changes are live on your web shop right away. On desktop, players scan a QR code that opens the QR landing page shown on the same page, which then opens your app.

Integrate account linking

The example below uses Unity, but you can follow the same flow in other engines such as Unreal Engine, Godot, or custom web/native clients.

Obtain the Player's Authentication Token

Use the platform's authentication system (Google, Apple, or other providers) to retrieve a valid token or credential for the player.

Extract the Code

Parse the deep link or callback URL to extract the code parameter.

Call the Stash Linking Endpoint

Send the code and the player's authentication data to your game server. From there, call ApproveCustomLogin (POST /sdk/custom_login/approve) to complete the link.

ApproveCustomLogin is a server-side endpoint. Call it from your game server, not from the game client directly.

Refer to your engine's documentation for handling deep links. The game client extracts the code and forwards it to your game server. The server completes the link by calling ApproveCustomLogin.

Login code rules

  • Lifetime. A code is valid for 10 minutes from when the webshop creates it. Approve it inside that window.
  • Single use. A code can be approved once.
  • Format. The code is URL-safe base64 and can end in =. Pass it to ApproveCustomLogin exactly as it appears after code= in the link.

ApproveCustomLogin answers:

HTTP statusMessageMeaning
200Approved. The webshop that showed the code can now sign the player in.
400already approvedThe code was approved before. Have the player start sign-in again from the webshop.
403invalid codeThe code has expired, is malformed, or was issued for another shop.
401invalid authThe request signature or API key was rejected. See API Keys.

Set up account linking in Unity

Use the Stash SDK to integrate account linking in Unity.

The SDK is optional. It provides convenient wrappers around the API endpoints, but you can also implement account linking with direct API calls.

Import the Stash SDK

Follow these steps to add the Stash SDK to your Unity project:

Import the package

Import the .unitypackage file into your game with the Unity asset package import process.

Import demo scenes (Optional)

Select the Scenes folder to import demo scenes.

See the Unity deep linking overview for platform-specific instructions.

Let's take a look at the structure of the Stash's deep links.

Deep Link Structure
stashggsample://login?code=<code>

The key element in the link is the code. Configure deep links correctly and add logic to extract the code when your game launches through a deep link.

Extract the code

With deep linking configured, you can extract the code.

Use Unity's Application.deepLinkActivated event to handle deep link activations. This event triggers whenever the game launches or resumes from a Stash deep link.

In the onDeepLinkActivated handler, split the link to extract the code.

Extract Code from Deep Link
public void onDeepLinkActivated(string url) {
  // Extract the code parameter from the link.
  var code = url.Split("login?code=")[1];
  if (!string.IsNullOrEmpty(code)) {
    // Work with code...
  }
}

How is this guide?

On this page