Skip to content

Validate login tokens

Before the app server performs processing that must not allow forgery or tampering, such as granting items or saving play data, it must verify that the user who sent the request is really the owner of that account. The Player ID sent by the app client alone does not tell you whether it was forged, so the app server identifies the user by checking the access token issued during login with the Hive Axyl authentication server.

Access token validation takes place through Server-to-Server communication between the app server and the Hive Axyl authentication server. The app client only takes the access token from its session and passes it to the app server, and the Hive Axyl SDK does not provide a validation method.

Note

The Hive Axyl SDK handles getting a new access token issued when the current one expires, so the app server does not need to manage expiration itself. For details, see Automatic login.

Implementation order

The app client, the app server, and the Hive Axyl authentication server process access token validation in order.

  1. The app client reads the access token and Player ID from the current session. Both values are available after the session is registered through login.
  2. When the app client requests login or session establishment from the app server, it passes the access token along. The format in which the app server receives it follows the app server's authentication design.
  3. The app server calls Check access token validity with the access token it received. If data.active in the response is true, the token is valid, and data.playerId contains the Player ID of the token's owner.
  4. The app server acts on the result. If the token is valid, the app server creates its own session based on data.playerId. If it is not valid, the app server treats the request as abnormal access and rejects it.

Do not trust the Player ID sent by the app client as is. Process requests based on the Player ID that the Hive Axyl server confirmed in step 3.

Values the Hive Axyl SDK provides

The Hive Axyl SDK provides properties that read the credentials of the current session. You get both values from ISessionManager.

  • ISessionManager.AccessToken: The access token of the current session to pass to the app server. It is null when the user is not logged in.
  • ISessionManager.PlayerId: The Player ID of the current session. It is 0 when the user is not logged in.
using Hive.Axyl.Core;

ISessionManager session = HiveCore.Resolve<ISessionManager>();

if (session.IsLoggedIn)
{
    string accessToken = session.AccessToken;
    long playerId = session.PlayerId;
    // Pass accessToken along when you request login from the app server.
    await RequestAppServerLoginAsync(accessToken, playerId);
}

Access tokens are sensitive information. Do not write them to logs, and use encrypted communication such as HTTPS when you pass them to the app server.