Skip to main content
A native app gets proof of the player’s platform account from the platform SDK. The app sends that proof to Pylon, and Pylon checks it with the platform. Each route then links the account and returns a session, the same as OAuth:
A guest session sent with the request merges into the signed-in user, as with the other sign-in routes. A route returns 404 when its provider is not configured.

Apple and Google

Pylon checks the token’s signature against the provider’s keys. It also checks the issuer, the expiry, and the audience. Apple gives your app the user’s name only on the first sign-in, and never puts it in the token. Send it as name on that first request. An account links to an existing user with the same email address. A Google account with an unverified email is refused.

Steam

The game gets a ticket from Steam with ISteamUser::GetAuthTicketForWebApi(identity). Pylon checks the ticket with Steam’s ISteamUserAuth/AuthenticateUserTicket Web API. Steam refuses a ticket made for another app id or another identity. This means a ticket that a player gave another service cannot sign in to your app.
  • The account is the player’s SteamID64. With Family Sharing, the player signs in as themselves, not as the account that owns the game.
  • Email: Steam gives no email address. A Steam account never links to an existing user by email.
  • The user row: the first sign-in creates a user with a placeholder address, steam-<steamid>-<random>@steam.invalid. This address is not verified and never receives mail. Replace it if you collect a real address.
  • Errors:
    • 401 INVALID_TICKET: Steam refused the ticket.
    • 403 ACCOUNT_BANNED: the player is banned and PYLON_STEAM_REFUSE_BANNED is on.
    • 502 PROVIDER_UNAVAILABLE: Pylon could not reach Steam. The route fails closed.

Get the ticket

Steamworks.NET:
Facepunch.Steamworks:
The C# client has SignInWithAppleAsync, SignInWithGoogleAsync, and SignInWithSteamAsync. See the C# and Unity SDK.