Skip to content

Implement Steam login

To implement Steam login with the recipe code, complete the following procedure in order.

Before you begin, complete the common prerequisites.

Overall flow

What you configure and call in each step is as follows. Perform a step that names a specific method in the Applies to column only when you support that method.

Step Category What you do Applies to
1 External console Prepare credentials in Steamworks All
2 Hive Console Register credentials and enable Steam login All
3 Hive Axyl SDK Install the authentication module and Add-ons All
4 Hive Axyl SDK Initialize the SDK and register modules All
5 App code Initialize Steamworks Steam client method
6 Recipe code Copy the recipe folders All
7 App code Prepare ClientId and DeviceKey All
8 Recipe code Prepare the Steam credential source All
9 Recipe code Call Steam login All
10 Add-on Release the authentication ticket Steam client method
11 App code Handle login results All
12 App code Verify the behavior All
Login is blocked if you do not release authentication tickets

In the Steam client method, the recipe receives authentication tickets, and the app can hold only a fixed number of them at the same time. The recipe does not release tickets, so the app must implement step 10 itself.

1. Configure Steamworks

First, prepare in Steamworks the credentials that the Hive Axyl authentication server uses. The Hive Axyl authentication server uses these values to confirm with Steam that the Steam authentication result the app sent is genuine.

Check the Publisher Web API Key and copy it. You enter this value in the Hive Console in step 2.

The browser-based method does not register a redirect URL in Steamworks. Steam only displays the domain of the URL it sends the user back to as the site that requested login on the login screen. On Android and iOS, the domain of the Hive Axyl relay URL in 8.2 is displayed.

2. Configure the Hive Console

Register the prepared credentials in the Hive Console and enable Steam login. If the login method is disabled, the recipe call is rejected.

Setting Required Where to check
Register the Steam App ID and Web API Key Required Steam login credentials
Enable Steam login Required Login method types
Per-App ID login settings Optional Per-App ID login settings

The settings you register here apply to all App IDs in the project. To show different login methods only for a specific App ID, use per-App ID login settings.

The Steam App ID you enter here is the same value you registered as the Store App ID in the prerequisites. The two screens serve different purposes, so enter the same value in both. The input field appears when the project has a Windows or macOS App ID.

3. Install SDK modules and Add-ons

Install the authentication module and the Add-ons for the OSs your app supports in your Unity project. An Add-on is a Hive Axyl SDK extension package that performs Steam authentication on the app's behalf, and the credential source you prepare in step 8 calls this Add-on.

Package Needed Role
com.com2usplatform.hiveaxyl.core Required SDK initialization and login session management
com.com2usplatform.hiveaxyl.auth Required Login with Steam credentials and token issuance
com.com2usplatform.hiveaxyl.auth.addon.steam Required for the Steam client method Issuing authentication tickets from the Steam client
com.com2usplatform.hiveaxyl.auth.addon.webauth Required for the browser-based method Displaying the Steam login page in a browser
com.unity.nuget.newtonsoft-json Required for the browser-based method Referenced by the ProviderLogin.WebAuth/ assembly, so the code does not compile without it
com.com2usplatform.hiveaxyl.storage Recommended Encrypted storage of the DeviceKey and session tokens

When you install, also check the following.

  • Add-ons you do not install: The credential source for that method is excluded from compilation, so if you do not install the Steam Add-on, you cannot use SteamCredentialSource even in Windows and macOS builds.
  • Browser-based method on Android: You must register in the app the app callback scheme that receives the login result. For the scheme to register and how to register it, see 8.2.2. Register the Android app callback scheme.
  • Steamworks.NET bindings: The Steam login Add-on brings in the com.com2usplatform.hiveaxyl.steamworks package with it, so you do not need to install it separately.

4. Initialize the SDK

  • Hive Axyl SDK  Call the Hive Axyl SDK from the app.


    Detailed procedure: Initialize modules

Initialize the SDK once at the app's entry point, and register the authentication and token modules and the Add-on modules for the OSs you support. The recipe does not initialize the SDK, so calling it without initialization fails with a FailedPrecondition error.

The following example code registers modules to support both methods and initializes the SDK.

using Hive.Axyl.Auth;
using Hive.Axyl.Auth.Addon.WebAuth;
using Hive.Axyl.Core;
using Hive.Axyl.Core.Unity;
using Hive.Axyl.Storage;
#if UNITY_STANDALONE_WIN || UNITY_STANDALONE_OSX
using Hive.Axyl.Auth.Addon.Steam;
#endif

var config = CoreConfig.CreateBuilder("{appId}").Build();

HiveBootstrap.Initialize(config, builder =>
{
    builder
        .AddAuth()
        .AddToken()
        .AddSecureStorage()
        .AddWebAuth();

#if UNITY_STANDALONE_WIN || UNITY_STANDALONE_OSX
    builder.AddSteamAuth();
#endif
});

For {appId}, enter the App ID that matches the runtime environment you build for.

AddSteamAuth() is wrapped in conditional compilation because the Steam Add-on assembly is included only in Windows, macOS, and Linux builds and in the Unity Editor. Android and iOS builds do not have this method at all, so a compile error occurs if you do not wrap it.

The assembly for AddWebAuth() is included in all builds, so you can call it without branching. The actual registration happens only in Android, iOS, macOS, and Windows builds, and for AddSteamAuth(), only in Windows and macOS builds. In the Unity Editor, both skip registration.

If your app already uses secure storage, you do not need to register AddSecureStorage(). Even in this case, the app must be able to read the DeviceKey and session tokens again after it restarts.

5. Initialize Steamworks

On Windows and macOS, the Add-on receives authentication tickets through Steamworks. The Hive Axyl SDK does not initialize Steamworks, so the app must initialize and maintain it directly.

Call SteamAPI.Init() once when the app starts, and call SteamAPI.RunCallbacks() every frame. If you run the app outside the Steam client for development, place a steam_appid.txt file in the same location as the executable and write the Steam App ID in it.

SteamAPI is provided by the Steamworks.NET bindings that the Steam login Add-on brings in. Add using Steamworks;, and in step 6, add com.rlabrecque.steamworks.net to your app assembly as a reference. Wrap this code in conditional compilation as well so that it compiles only in Windows and macOS builds.

If you call the recipe before initialization, it fails with a FailedPrecondition error.

If you support only the browser-based method, skip this step.

6. Install the recipe code

  • Recipe code  Copy the recipe code into your project.

A recipe is source code that you copy into your project instead of installing as a package. Copy the following items from the axyl-samples-unity repository to Assets/Recipes/ in your Unity project.

The items to copy and their roles are as follows.

  • Recipes.asmdef: Common assembly definition for recipes
  • AssemblyInfo.cs: Setting that exposes internal helpers to other recipe assemblies
  • Helper/: Common code shared by multiple recipes
  • ProviderLogin/: ProviderLoginRecipe, result types, and the credential source contract
  • ProviderLogin.Steam/: SteamCredentialSource
  • ProviderLogin.WebAuth/: SteamOpenIdCredentialSource, SteamRelayReturnTo, which builds the URL that Steam sends the user back to, and common browser login code

You do not need to copy the credential source for a method you do not support. If you support only the Steam client method, leave out ProviderLogin.WebAuth/, and if you support only the browser-based method, leave out ProviderLogin.Steam/.

To call recipes from your app code, add the following assembly to references in your app's assembly definition. Because autoReferenced in the original Recipes.asmdef is false, your app assemblies do not reference it automatically.

{
  "name": "MyApp",
  "references": [
    "Hive.Axyl.Core",
    "Hive.Axyl.Auth",
    "Hive.Axyl.Auth.Addon.Steam",
    "Hive.Axyl.Auth.Addon.WebAuth",
    "Hive.Axyl.Storage",
    "com.rlabrecque.steamworks.net",
    "Hive.Axyl.Samples.Recipes",
    "Hive.Axyl.Samples.Recipes.ProviderLogin",
    "Hive.Axyl.Samples.Recipes.ProviderLogin.Steam",
    "Hive.Axyl.Samples.Recipes.ProviderLogin.WebAuth"
  ]
}

Replace MyApp with the assembly name your app uses, and keep your existing settings and references. Unity assemblies do not pass references on transitively, so you must list here every assembly that your app code uses directly. Hive.Axyl.Core contains CoreConfig and HiveError, Hive.Axyl.Auth contains AddAuth() and AddToken(), Hive.Axyl.Auth.Addon.Steam contains AddSteamAuth() and the ticket release method, Hive.Axyl.Auth.Addon.WebAuth contains AddWebAuth(), Hive.Axyl.Storage contains AddSecureStorage(), and com.rlabrecque.steamworks.net contains SteamAPI and SteamUser, which are used in step 5.

If you do not register AddSecureStorage(), you do not need to list Hive.Axyl.Storage. If you support only one method, also leave out the Add-on and recipe assemblies for the other method.

The code does not compile if you copy only the credential source folders

SteamCredentialSource and SteamOpenIdCredentialSource implement the credential source contract in ProviderLogin/, and ProviderLoginRecipe uses the PKCE generation code and the session preparation code in Helper/. Copy Helper/, Recipes.asmdef, AssemblyInfo.cs, and ProviderLogin/ together.

7. Prepare ClientId and DeviceKey

The constructor of ProviderLoginRecipe takes ClientId and DeviceKey. ClientId is the value you checked in the common prerequisites, which the Hive Console issues for each project. DeviceKey is the value the Hive Axyl authentication server uses to distinguish login sessions by device, and the app creates and keeps it itself.

The recipe does not create or save DeviceKey, so create and manage it according to the following conditions.

  • A different value for each device. A random value such as a UUID is recommended
  • A value created and saved once on first launch and reused for every later login
  • A length of 22 to 64 characters
  • A value made up only of ASCII characters, excluding spaces and control characters
Do not overwrite it with a new DeviceKey just because the storage could not be read

The value may not be gone; only the read may have failed. First fix the storage access problem or try reading again.

You do not need to prepare PKCE values. Each time it is called, the recipe creates a pair itself and passes them separately to the login call and the token issuance call.

Passing an empty value throws an exception

If ClientId or DeviceKey is empty, the recipe throws an ArgumentException instead of returning a result. It also throws an ArgumentNullException when you pass the credential source as null. Before you pass a value read from storage as is, first check whether it is empty.

8. Prepare the Steam credential source

To tell the recipe which external authentication provider to log in with, you must create a credential source and pass it. Steam uses a different authentication method on each OS, so select the source that matches the OS the app is running on.

8.1. Steam client method

SteamCredentialSource receives an authentication ticket from the Steam client. The constructor arguments are as follows.

Argument Required How to prepare
identity Required The identification string that Steamworks uses when it creates the ticket. It must be the same as the value the Hive Axyl authentication server uses for verification. The server hashes the Steam ID64 with SHA-256, converts the hash to lowercase hexadecimal, and uses the first 30 characters.
steamId Required The Steam ID64 read from Steamworks. You also need it to create identity, so read it first.

The Steam login Add-on does not provide these two values, so the app reads and creates them directly from Steamworks. The following example code prepares the two values.

using System;
using System.Security.Cryptography;
using System.Text;
using Steamworks;

string steamId = SteamUser.GetSteamID().m_SteamID.ToString();

string identity;
using (var sha = SHA256.Create())
{
    byte[] hash = sha.ComputeHash(Encoding.UTF8.GetBytes(steamId));
    identity = BitConverter.ToString(hash)
        .Replace("-", string.Empty)
        .ToLowerInvariant()
        .Substring(0, 30);
}

Only the first 30 characters are used because Steam limits the length of the identification string. If your app server is set up to verify with a different identification string, put that value in as is.

If identity is empty or contains only white space, the constructor throws an ArgumentException. Unlike when you call the Hive Axyl SDK methods directly, the recipe does not allow an empty string.

The ticket value to release in step 10 is not included in the login result. Create a class in your app that wraps the credential source, and keep the ticket separately. IProviderCredentialSource is a public contract, so you can wrap it without modifying the recipe.

using System.Threading;
using System.Threading.Tasks;
using Hive.Axyl.Samples.Recipes;

public sealed class SteamTicketKeepingSource : IProviderCredentialSource
{
    private readonly SteamCredentialSource m_inner;

    public SteamTicketKeepingSource(string identity, string steamId = null)
    {
        m_inner = new SteamCredentialSource(identity, steamId);
    }

    public string TicketHex { get; private set; }

    public LoginProvider Provider => m_inner.Provider;

    public async Task<ProviderCredentialOutcome> AcquireAsync(
        CancellationToken cancellationToken = default)
    {
        ProviderCredentialOutcome outcome = await m_inner.AcquireAsync(cancellationToken);
        TicketHex = outcome.Credential?.ProviderToken;
        return outcome;
    }
}

This class and the identity preparation code above must compile only in Windows and macOS builds. Wrap them in conditional compilation as in step 8.3, or create a separate assembly definition with includePlatforms limited to Windows and macOS and put them in it.

8.2. Browser-based method

SteamOpenIdCredentialSource opens the Steam login page in a browser and extracts the Steam identifier and the authentication response from the callback that comes back. Steam cannot send the user back to the app's own scheme URL, so on Android and iOS, the login result returns to the app callback URL through the relay URL that Hive Axyl operates.

The constructor arguments are as follows.

Argument Required How to prepare
returnTo Required The absolute http or https URL that Steam sends the user back to. On Android and iOS, put in the Hive Axyl relay URL created with SteamRelayReturnTo.Build(). If the format is invalid, the constructor throws an ArgumentException.
redirectUri Optional Put this in when the URL where the app waits for the callback differs from returnTo. On Android and iOS, put in the app callback URL {appId}://oauth-callback. If omitted, returnTo is used as is.

8.2.1. Build the URL that Steam sends the user back to

SteamRelayReturnTo.Build() creates returnTo by appending the app callback URL and a random value for each login attempt to the Hive Axyl relay URL as query parameters. The Hive Axyl relay URL forwards the callback parameters that Steam sent to this app callback URL without changing them. Pass the following values as arguments.

  • relayBase: The Hive Axyl relay URL https://core-api.hiveaxyl.com/auth/v1/provider/callback
  • appCallback: The app callback URL {appId}://oauth-callback. {appId} is the App ID you created in the Hive Console, not the Android package name
  • nonce: A random value newly created for each login attempt
using System;
using Hive.Axyl.Samples.Recipes;

string appCallback = "{appId}://oauth-callback";
string returnTo = SteamRelayReturnTo.Build(
    "https://core-api.hiveaxyl.com/auth/v1/provider/callback",
    appCallback,
    Guid.NewGuid().ToString("N"));

IProviderCredentialSource source = new SteamOpenIdCredentialSource(returnTo, appCallback);

returnTo contains a random value for each login attempt, so create returnTo and the source anew every time the user logs in. You do not need to prepare the authorization URL or the state value. The credential source builds a URL that conforms to the Steam OpenID specification by itself, and it also checks by itself whether openid.return_to in the returned callback matches the returnTo created for this login.

8.2.2. Register the Android app callback scheme

On Android, register the App ID, which is the scheme of the app callback URL, in your app so that the callback screen of the WebAuth Add-on receives it. If you do not register it, the result that the Hive Axyl relay URL sends does not reach the app, and login does not finish. For how to register it, see Prepare the redirect URI for Android. If another login method already uses a different scheme, register both schemes as described in Register multiple schemes. On iOS, the OS authentication session checks the scheme directly, so you do not need to register it.

8.3. Select the source by method

If you support both methods, separate them with conditional compilation. The recipe assembly that contains SteamCredentialSource is included only in Windows, macOS, and Linux builds and in the Unity Editor, so a compile error occurs in Android and iOS builds if you do not wrap it. identity and steamId are the values you created in 8.1, and returnTo and appCallback are the values you created in 8.2.

using Hive.Axyl.Samples.Recipes;

IProviderCredentialSource source;

#if UNITY_STANDALONE_WIN || UNITY_STANDALONE_OSX
var steamSource = new SteamTicketKeepingSource(identity, steamId);
source = steamSource;
#else
source = new SteamOpenIdCredentialSource(returnTo, appCallback);
#endif

If you support only one method, create only the source for that method.

9. Call Steam login

  • Recipe code  Call the recipe code from the app.

Pass the prepared credential source to LoginWithProviderAsync(). The recipe receives credentials from Steam, logs in, and also activates the session.

Also prepare a CancellationTokenSource in case the app needs to stop waiting for login by itself.

using System.Threading;
using Hive.Axyl.Samples.Recipes;

var recipe = new ProviderLoginRecipe(clientId, deviceKey);

var cancellation = new CancellationTokenSource();
CancellationToken token = cancellation.Token;

LoginWithProviderOutcome outcome = await recipe.LoginWithProviderAsync(source, token);

Call cancellation.Cancel() when the app needs to end the wait first, such as when it leaves the scene where login started, and clean up with cancellation.Dispose() when the call finishes. Do not call it when the user closes the Steam login page. The recipe reports that case as UserCanceled.

The recipe performs the following tasks internally.

Category Call Where to check
Recipe code Checks that the authentication, token, and session modules are registered None
Add-on In the Steam client method, gets an authentication ticket with GetAuthTicketForWebApiAsync() Windows and macOS
Add-on In the browser-based method, opens the Steam login page with OpenAsync() and receives the callback that the Hive Axyl relay URL forwarded to the app callback URL Open a web login session
Recipe code In the browser-based method, checks openid.mode and openid.return_to in the callback, and gets the Steam ID64 in openid.claimed_id and the callback query string as credentials OSs other than Windows and macOS
Recipe code Creates a pair of PKCE values and passes them separately to the login call and the token issuance call Prepare the call parameter values
Hive Axyl SDK Passes the Steam credentials with LoginProviderAsync() and receives an authorization code Log in with an external authentication provider
Hive Axyl SDK Exchanges the authorization code for an access token and a refresh token with IssueTokenAsync() Issue tokens and activate the session
Hive Axyl SDK Activates the login session with SetSession() Issue tokens and activate the session

The detailed procedures in the table above are written for calling the Hive Axyl SDK methods directly. Do not reimplement in the app the steps that the recipe handles for you, such as creating PKCE values or the authorization URL. Refer to them only to check what each call sends and receives.

If the modules are not registered, the recipe stops at the module check step with a FailedPrecondition error. When Success is returned, the session is already ready, so do not call the token issuance or session activation code separately. The session is activated only after usable tokens are received, so a failed attempt does not affect a session that was already open.

10. Release the authentication ticket

In the Steam client method, release the authentication ticket after you receive the login result. Steam limits the number of tickets that an app can hold at the same time, so if you keep issuing tickets without releasing them, later logins fail. The recipe does not release tickets.

The credential source you created in step 8.1 keeps the ticket value to release. The login result does not include the ticket, so use that value. Put this code in the same scope where you created the credential source in step 8.3 so that it can read steamSource.

Release the ticket after you receive the result, whether login succeeded or failed. If you release it before verification finishes, Steam considers the ticket invalid and login fails.

#if UNITY_STANDALONE_WIN || UNITY_STANDALONE_OSX
using Hive.Axyl.Auth.Addon.Steam;
using Hive.Axyl.Core;

// Call this after you receive the result of LoginWithProviderAsync.
if (steamSource.TicketHex != null
    && HiveCore.TryResolve<ISteamPlugin>(out var steam))
{
    steam.ReleaseTicket(steamSource.TicketHex);
}
#endif

Call ReleaseTicket() on the Unity main thread. Passing a ticket that was already released or is unknown does nothing.

This code is wrapped in conditional compilation because the assembly that contains ISteamPlugin is not included in Android and iOS builds. The browser-based method has no ticket to release, so this code does not need to run.

11. Handle login results

LoginWithProviderOutcome reports the login result through Status. FailedStep is a diagnostic value, so do not use it as the basis for branching the app's normal flow.

Status Value to check App handling
Success PlayerId, IsBlocked If the account is not under a usage restriction, move to the post-login screen.
BusinessOutcome BusinessOutcome, UnknownOutcomeCode Branch according to the rejection reason, and handle and record unknown values as failures.
UserCanceled None The user closed the Steam login page or declined login, so return to the previous screen.
Failure Error.Code, Error.TraceId Record the technical problem and provide a retry flow.

UserCanceled occurs only in the browser-based method, because the Steam client method has no login screen for the user to close.

If IsBlocked is true, login succeeded, but the account is under a usage restriction. For restriction types and how to notify users, see Usage restriction.

PlayerId is the unique identifier that Hive Axyl assigns to each user. If the user logs in again with the same Steam account, the same value is returned, so the app uses this value to distinguish the user's play data.

When you record errors, also record FailedStep. It has five values, None, Resolve, AcquireCredential, LoginProvider, and SessionSetup, and it tells you at which step the process stopped.

11.1. Handle rejection reasons

A BusinessOutcome value is the reason login did not succeed, so the message to show the user differs for each value. The recipe combines the rejection reasons from two server calls into a single value and returns it, so check both places.

Some rejection reasons are not in either of those two places. TemporarilyUnavailable means that the Hive Axyl authentication server could not make a decision and returned the request, so send the same request again. Do not repeat it immediately; retry at increasing intervals, such as 1 second, 3 seconds, and 6 seconds.

If the recipe receives a result that this SDK version does not know, BusinessOutcome becomes Unrecognized. In this case, use UnknownOutcomeCode to distinguish two cases. If it has a value, this SDK version does not know the result code the server sent. If it is empty, the SDK knows the result, but the recipe has not given it a name. In either case, do not look it up in the two places above; record UnknownOutcomeCode and RawJson, and then handle it as a failure. Do not show these two values to users; use them only for recording app errors.

The recipe renames the names written in the detailed procedures as follows before returning them.

  • TerminateService: ServiceTerminated
  • InvalidClientId: InvalidClient
  • InvalidGrant: InvalidAuthorizationCode
  • InvalidGrantExpired: ExpiredAuthorizationCode
  • InvalidGrantCodeChallenge: CodeChallengeMismatch
  • InvalidGrantRefreshToken: InvalidRefreshToken

InvalidRefreshToken occurs only when tokens are reissued with a refresh token, so it does not occur in this recipe. The other five also appear as they are in this recipe.

ProviderTokenError means that the authentication result was not valid when the Hive Axyl authentication server checked it with Steam. Have the user authenticate again.

11.2. Handle cancellation and unsupported environments

Not every result whose Status is Failure should be reported to the user as a failure. Cases where the app stopped waiting and environments where Steam login cannot run also end up here, so distinguish them with Error.Code.

Error.Code Meaning App handling
Cancelled The app canceled login with a CancellationToken. A different result from UserCanceled, in which the user closed the Steam login page Show a message different from the one for UserCanceled.
Unavailable The call could not run to completion Follow the handling by cause below.
FailedPrecondition The preparation required for the call is not complete. If FailedStep is Resolve, the authentication and token modules were not registered in step 4 or the SDK was not initialized. If it is AcquireCredential, the Steam client is not running, Steamworks was not initialized in step 5, or a ticket request started earlier has not finished yet Check the preparation state that corresponds to FailedStep. To keep ticket requests from overlapping, keep the login button locked until the response returns.
Internal A value needed for the next step could not be obtained during the call. In the Steam client method, the Steamworks call itself failed or returned an invalid ticket. In the browser-based method, the callback is not Steam's approval response or does not contain a Steam identifier Retrying does not solve it, so record Error.TraceId and FailedStep.
PermissionDenied openid.return_to in the callback returned from the browser differs from the returnTo created for this login. The callback did not start from this login, so the recipe does not request login Keep the login screen, and let the user try again after you create returnTo and the source anew as in step 8.2.
Unknown Steamworks returned an unexpected result Error.ExternalCode contains the original value that Steamworks returned, so record it as well.

There are four causes for which Error.Code is HiveErrorCode.Unavailable, and the handling for each cause is as follows.

  • Steam Add-on not registered: The app ran in the Unity Editor, or the AddSteamAuth() registration in step 4 was left out. Check the registration, and then try again in an actual build.
  • No user logged in to the Steam client: Guide the user to log in to the Steam client.
  • Web login session Add-on not registered: Check the Add-on installation in step 3 and the AddWebAuth() registration in step 4.
  • Network disconnection or temporary service outage: Guide the user to try again after a while.

12. Verify the behavior

  • App code  Verify the behavior in the app.

Verify each method you support on a real device. In the Unity Editor, neither Add-on is registered and an Unavailable error is returned, so you cannot verify the flow from credential acquisition onward.

Verify the Steam client method in the following order.

  1. Run the Steam client, log in, and then run the app.
  2. Run Steam login, and check for Success and PlayerId.
  3. Check that the ticket release in step 10 is called.
  4. Run login several times in a row, and check that ticket issuance keeps succeeding. If you left out the release, this step fails.
  5. Quit the app completely, run it again, log in with the same Steam account, and check that PlayerId is the same.
  6. Log out of the Steam client, run login, and check that Unavailable is returned. If you quit the Steam client, FailedPrecondition is returned.

Verify the browser-based method in the following order.

  1. Run the app, and run Steam login.
  2. Check that the Steam login page appears in the browser, and complete login.
  3. Return to the app, and check for Success and PlayerId. If the user does not return to the app on Android, check 8.2.2. Register the Android app callback scheme.
  4. Quit the app completely, run it again, log in with the same Steam account, and check that PlayerId is the same.
  5. Cancel on the Steam login page, and check that UserCanceled is returned.

Next steps

To let logged-in users skip the login screen when they relaunch the app, see Automatic login.

To link another login method to an account that is already logged in, see the External authentication provider linking practical guide.

To let users leave the logged-in account and log in with a different account, see the Logout practical guide.