A route returns 404 when its provider is not configured.
Apple and Google
Pylon checks the token’s signature against the provider’s keys. It also checks the issuer, the expiry, and the audience.
Apple gives your app the user’s name only on the first sign-in, and never puts it in the token. Send it as
name on that first request.
An account links to an existing user with the same email address. A Google account with an unverified email is refused.
Steam
The game gets a ticket from Steam withISteamUser::GetAuthTicketForWebApi(identity). Pylon checks the ticket with Steam’s ISteamUserAuth/AuthenticateUserTicket Web API.
Steam refuses a ticket made for another app id or another identity. This means a ticket that a player gave another service cannot sign in to your app.
- The account is the player’s SteamID64. With Family Sharing, the player signs in as themselves, not as the account that owns the game.
- Email: Steam gives no email address. A Steam account never links to an existing user by email.
- The user row: the first sign-in creates a user with a placeholder address,
steam-<steamid>-<random>@steam.invalid. This address is not verified and never receives mail. Replace it if you collect a real address. - Errors:
- 401
INVALID_TICKET: Steam refused the ticket. - 403
ACCOUNT_BANNED: the player is banned andPYLON_STEAM_REFUSE_BANNEDis on. - 502
PROVIDER_UNAVAILABLE: Pylon could not reach Steam. The route fails closed.
- 401
Get the ticket
Steamworks.NET:SignInWithAppleAsync, SignInWithGoogleAsync, and SignInWithSteamAsync. See the C# and Unity SDK.