Validate login tokens
Before the app server performs processing that must not allow forgery or tampering, such as granting items or saving play data, it must verify that the user who sent the request is really the owner of that account. The Player ID sent by the app client alone does not tell you whether it was forged, so the app server identifies the user by checking the access token issued during login with the Hive Axyl authentication server.
Access token validation takes place through Server-to-Server communication between the app server and the Hive Axyl authentication server. The app client only takes the access token from its session and passes it to the app server, and the Hive Axyl SDK does not provide a validation method.
Note
The Hive Axyl SDK handles getting a new access token issued when the current one expires, so the app server does not need to manage expiration itself. For details, see Automatic login.
Implementation order
The app client, the app server, and the Hive Axyl authentication server process access token validation in order.
- The app client reads the access token and Player ID from the current session. Both values are available after the session is registered through login.
- When the app client requests login or session establishment from the app server, it passes the access token along. The format in which the app server receives it follows the app server's authentication design.
- The app server calls Check access token validity with the access token it received. If
data.activein the response istrue, the token is valid, anddata.playerIdcontains the Player ID of the token's owner. - The app server acts on the result. If the token is valid, the app server creates its own session based on
data.playerId. If it is not valid, the app server treats the request as abnormal access and rejects it.
Do not trust the Player ID sent by the app client as is. Process requests based on the Player ID that the Hive Axyl server confirmed in step 3.
Values the Hive Axyl SDK provides
The Hive Axyl SDK provides properties that read the credentials of the current session. You get both values from ISessionManager.
ISessionManager.AccessToken: The access token of the current session to pass to the app server. It isnullwhen the user is not logged in.ISessionManager.PlayerId: The Player ID of the current session. It is0when the user is not logged in.
using Hive.Axyl.Core;
ISessionManager session = HiveCore.Resolve<ISessionManager>();
if (session.IsLoggedIn)
{
string accessToken = session.AccessToken;
long playerId = session.PlayerId;
// Pass accessToken along when you request login from the app server.
await RequestAppServerLoginAsync(accessToken, playerId);
}
Access tokens are sensitive information. Do not write them to logs, and use encrypted communication such as HTTPS when you pass them to the app server.
Related documents
- Check access token validity: Request and response of the Hive Axyl Server API that the app server calls
- Get started - Log in: The process of registering the access token in the session
- Hive Axyl Server API error handling: The order for checking error responses that the app server receives