Authentication Methods
The three ways players sign in to your Stash webshop: pre-authenticated links your game server generates, Direct Sign-in (SSO) with providers like Google, Apple, or Facebook, and Account Linking through deep links and QR codes.
Stash provides three ways for players to sign in to your webshop. You can implement any combination of them.
Pre-authenticated links
Use a pre-authenticated link when the player starts in your game, for example by tapping a webshop button. The player opens the link and arrives in the webshop already signed in, with no sign-in step.
Your game server calls Generate authenticated URL (POST /sdk/server/generate_url) with the player's user.id and a target, and receives a url. Sign the request with your ingress secret, as described in HMAC signing. Pass the url to your game client, which opens it in the browser.
targetsets the webshop page the player lands on, for exampleSTOREorLOYALTY.- Each link signs a player in once and expires 30 minutes after it is generated. Generate a new link each time the player opens the webshop, and open it right away.
user.regionCodeis optional. When you send it, it must be a valid country code; an invalid value rejects the request.
Call generate_url from your game server only. Anyone who opens the link before the player can sign in as that player, so do not log, cache, or share it.
Direct Sign in (SSO)
Players authenticate directly in the webshop using SSO providers such as Google, Apple, or Facebook.
You configure the providers in Stash Studio by adding their credentials. Players click Sign in, select a provider, and complete authentication in the browser.
Account Linking
With account linking, players authenticate by launching your game through a deep link on mobile or by scanning a QR code on desktop.
The deep link passes a session code to the game client. The client attaches the player's authentication data to the session code and sends both to Stash.
This method enables passwordless login by reusing the player's existing game session.
How is this guide?
Real-time Catalog
Learn how to expose REST API endpoints on your game backend to power personalized web shops with real-time offers. This guide covers the Catalog, Player, and Purchase APIs with protobuf-based type-safe integration.
Authentication Providers
Learn about the authentication providers supported by Stash including Apple, Google, Facebook, Game Center, Play Games, Amazon Cognito, and custom JWT/OIDC. Understand the credentials needed for each provider and how to configure them in Stash Studio.