Verify login and retrieve user info
Login verification and user information retrieval is an API that verifies login information using a temporary authentication code (state) redirected from the login page and returns user information. When returning user information, it includes the access token and refresh token.
The values returned by the Login Verification and User Information Retrieval API request are largely as follows.
- IdP information
- User information
- Access/refresh tokens
Note
After successful login verification, the cases where user information or token information is needed are as follows.
- For users who have successfully validated web login and have a PlayerID generated, the response includes user information (
user_info). However, if the user information has changed or needs to be verified separately, you can check it by calling the User Information Retrieval API. - If access/refresh tokens are needed, you must perform web login again or renew them through the Token Refresh API before the token expires.
Request URL
Request body
| Field Name | Type | Description | Required |
| grant_type | String | OAuth 2.0 authorization code flow default: authorization_code | Y |
| state | String | The temporary authorization code received after login (authorization_code) | Y |
| client_id | String | The OAuth 2.0 Client ID generated in the security key settings. You can check it in the Hive Console App Center > Security Key Settings. | Y |
| client_secret | String | The OAuth 2.0 Client Secret generated in the security key settings. You can check it in the Hive Console App Center > Security Key Settings. | Y |
| redirect_uri | String | This is the redirect URI address. It must match the Redirect URI set in the Hive Console Authentication > Authentication Environment Settings > Login Settings. | Y |
Request body example
{
"grant_type": "authorization_code",
"state": "1627881984263-jkx1B3GOY3EsJ",
"client_id": "58b48cd3-df47-5b52-2627-3f9c8d01",
"client_secret": "bec7760b237244c4c818d6174587d8e1",
"redirect_uri": "https://community.withhive.com/hivesdk/login/redirect"
}
Response body
| Field Name | Type | Description | Remarks |
| code | Integer | Web login response code | |
| appid | String | Game app ID | |
| idp_index | Integer | IdP index used for login | 1: HIVE2: FACEBOOK3: GOOGLE9: APPLE10: LINE14: GOOGLE_PLAY_GAMES18: STEAM19: X
|
| idp_user_id | String | IdP unique identifier used for login | |
| enc_idp | String | Encrypted key for IdP information | Key for issuing token for automatic login on external websites |
| user_info | JSON | User information | |
| user_info.auth_ver | String | Authentication server version | |
| user_info.user_id | BigInteger | Auth v4 PlayerID | |
| user_info.user_idp_list | Array | Linked IdP list | List containing IdP information linked by the user |
| user_info.user_idp_list.player_id | BigInteger | Linked IdP list - Auth v4 PlayerID | |
| user_info.user_idp_list.idp_user_id | String | Linked IdP list - IdP unique identifier | |
| user_info.user_idp_list.idp_index | Integer | Linked IdP list - IdP index | 1: HIVE2: FACEBOOK3: GOOGLE9: APPLE10: LINE14: GOOGLE_PLAY_GAMES18: STEAM19: X
|
| user_info.user_idp_list.idp_id | String | Linked IdP list - IdP ID | GUEST is created by default even if played with other IdPs |
| user_info.is_blocked | Boolean | Service suspension status | true: Service suspended userfalse: Normal user
|
| user_info.is_refund | Boolean | Refund user repurchase eligibility | true: Refund user eligible for repurchasefalse: Refund user not eligible for repurchase
|
| user_info.access_token | String | Access token (JWT) - Asymmetric algorithm | - Not issued if account (PlayerID) does not exist.
- Valid for: 1 hour
|
| user_info.refresh_token | String | Refresh token (JWT) - Asymmetric algorithm | - Not issued if account (PlayerID) does not exist.
- Valid for: 30 days
|
Web login response code
| code | Description | Remarks |
| 100 | Success | |
| 1050 | Invalid parameter | |
| 1075 | Authentication server communication error | |
| 2011 | No project information | |
| 2013 | Project is in a terminated state | |
| 2021 | User has not completed IdP authentication or the user's token session has expired | |
| 2023 | User's token information is abnormal | |
| 7000 | OAuth2.0 security key not generated | Check in Hive Console App Center > Security Key Settings |
| 7001 | OAuth2.0 Client ID value is missing | 〃 |
| 7002 | OAuth2.0 Client information mismatch | 〃 |
| 7003 | OAuth2.0 Client information not found | 〃 |
| 7004 | OAuth2.0 unsupported token issuance type | Check the grant_type in the Request Body |
| 7005 | OAuth2.0 redirect URI mismatch | Check the redirect_uri in the Request Body |
| 8001 | OAuth2.0 JWT token creation failed | |
Response body sample (Success - User information exists)
Here is an example of the response data returned when the following conditions are met.
- When the web login is successfully completed
- When the PlayerID is created on the authentication server
{
"code": 100,
"appid": "com.com2us.hivesdk.ios.community.global.normal",
"idp_index": 3,
"idp_user_id": "105213591741718897220",
"enc_idp": "K+A4xduO7kf5OrJ/iDPqL2wrbMQTkNQ+jDz3OCCdGiezVsfW74kV0c/Qn2ipdP/ChFBUXoZkEUP03X26MVHnvgqHo9JG2BUCsRVcrsx+03IPRvpzjXAiY5c0tihk45jMWuPYo7q+j5Rsz8eSTKQo1vE9N85huOJWc8IAJKMqBRlpmiNfj+CgZQ5I7uV2u1nHhiLfwRqpt0vG/dT9mpdQisiKUS2mFIpgPnVSZaVMY7qnTvP+mTU11Yv2DhOq2VEycAic9Ko8UkBnllXEApqarqF5s4jg6bu9DxcnRNtZeaGbh4fZKEptjGuE6qqo3CsC1PN5TnU0Wf5uav07CaazsTpEBvA9SNZefWEeTDP2ePK8qd573vpXy4OQHpTOJkVm1AsN/Ir8Fssj9SKGdYyVuZ282VDAiFLAIlVyK4pAfjJRAve+G9tIm/i4mgQmuAqW",
"user_info": {
"auth_ver": "v4",
"user_id": 20000018552,
"user_idp_list": [
{
"player_id": 20000018552,
"idp_user_id": "105213591741718897220",
"idp_index": 3,
"idp_id": "GOOGLE"
},
{
"player_id": 20000018552,
"idp_user_id": "0",
"idp_index": 0,
"idp_id": "GUEST"
}
],
"is_blocked": false,
"is_refund": false,
"access_token": "eyJraWQiOiIwYThlMThkOS1hNmZiLTM3ZDMtNjkwYy02Zjg1ZTllNCIsInR5cCI6IkpXVCIsImFsZyI6IlJTMjU2In0.eyJpc193aGl0ZWxpc3QiOmZhbHNlLCJwcm9qZWN0X2lkIjoiY29tLmNvbTJ1cy5oaXZlc2RrIiwiZ3JhbnRfdHlwZSI6InVzZXIiLCJ1c2VyX2lkIjoyMDAwMDAxODU1MiwidG9rZW5fdHlwZSI6ImFjY2Vzc190b2tlbiIsImV4cCI6MTc0NTU2MTk4MywiaWF0IjoxNzQ1NTU4MzgzLCJhdXRoX3ZlciI6InY0In0.e4mCIirRpAni4A1ZEF3FDOFng3Da8hq6IqZmyyRQZsc7W3LfFi_id5TIQSDbvmagmT4GcwHztovpoYZxf8blwqES1lJmEVXsBBJ3qpEOAem0K9aVwY0zmOO3A0Eeh6Y0APABewNCpHiKPCMZwxSsMaUE56FfuYgnbhpsipR638VgyPniRVU-Bzcu0Pi2zo-5yUKbg2FCXex510fvZRxqGZPg8Rfhm-jXqAYuwALLIFf2ZykOWqVRFtczfPXwB6fLQrQvQeBnOYcHHnR1q8Fi-Rk_bQPsAffIemGvaC4vUeyx6Szzt_Gok1BsuF76lYZ5ogCn4lAlZ0SJLrgMM2-DNQ",
"refresh_token": "eyJraWQiOiIwYThlMThkOS1hNmZiLTM3ZDMtNjkwYy02Zjg1ZTllNCIsInR5cCI6IkpXVCIsImFsZyI6IlJTMjU2In0.eyJpc193aGl0ZWxpc3QiOmZhbHNlLCJwcm9qZWN0X2lkIjoiY29tLmNvbTJ1cy5oaXZlc2RrIiwiZ3JhbnRfdHlwZSI6InVzZXIiLCJ1c2VyX2lkIjoyMDAwMDAxODU1MiwidG9rZW5fdHlwZSI6InJlZnJlc2hfdG9rZW4iLCJleHAiOjE3NDgxNTAzODMsImlhdCI6MTc0NTU1ODM4MywiYXV0aF92ZXIiOiJ2NCJ9.fvXTfRDYhlk21EY-ngAXbQMgYM9f-rFYPBa_GMV3JDz3cy9wwGfPTnF-VO0WkpxzpPdbG1ZX0HAdIkT4kF873ee2d-g6-JeuIEy0SFcTMpdYWXnlOfsuZlFIkzCm0OB_mlnNo_wxXHvjHM_dFDF-SfK2r9_ga8yLOXDfLJeA4XUYGwwsG3XT9x5Vy8RlUcF2aeuf-2bXdLSD2NGssZh18RTayV2CNtGuX0kj-nABVVTzLWUqbwKSrIVXjlS76zxl3SisUW_pz97iM98yLLRdpe_56_VDPzKEqVmn4bCyhhlAT1LEdu_uudlBY7hSUX0cJzcLAtj_4GReuLU9SnvQpw"
}
}
Response body sample (Success - No user information)
Here is an example of the response data returned when the following conditions are met.
- If the web login is completed successfully
- Even if the PlayerID is not created on the authentication server, the developer can use the IdP identifiers (
idp_index, idp_user_id) as the user's account identifiers to process the login. However, if the login is done without user information, there will be no PlayerID, so Keep Login (SSO) cannot be used.
{
"code": 100,
"appid": "com.com2us.hivesdk.ios.community.global.normal",
"idp_index": 3,
"idp_user_id": "105213591741718897220",
"enc_idp": "K+A4xduO7kf5OrJ/iDPqL2wrbMQTkNQ+jDz3OCCdGiezVsfW74kV0c/Qn2ipdP/ChFBUXoZkEUP03X26MVHnvgqHo9JG2BUCsRVcrsx+03IPRvpzjXAiY5c0tihk45jMWuPYo7q+j5Rsz8eSTKQo1vE9N85huOJWc8IAJKMqBRlpmiNfj+CgZQ5I7uV2u1nHhiLfwRqpt0vG/dT9mpdQisiKUS2mFIpgPnVSZaVMY7qnTvP+mTU11Yv2DhOq2VEycAic9Ko8UkBnllXEApqarqF5s4jg6bu9DxcnRNtZeaGbh4fZKEptjGuE6qqo3CsC1PN5TnU0Wf5uav07CaazsTpEBvA9SNZefWEeTDP2ePK8qd573vpXy4OQHpTOJkVm1AsN/Ir8Fssj9SKGdYyVuZ282VDAiFLAIlVyK4pAfjJRAve+G9tIm/i4mgQmuAqW"
}
Response body sample (Failure)
This is an example of the response data returned when the following conditions are met.
Issue token for automatic login on external websites
- When running the Crossplay Launcher, the corresponding token value (web_idp_token) is passed for automatic login.
- web_idp_token is a one-time token that needs to be obtained anew each time the game is launched.
Note
- Please be careful not to expose the enc_idp value that delivers the request for security reasons.
- It is essential to apply server-to-server when making API calls.
Request URL
Request body
| Field Name | Type | Description | Required |
| appid | String | App ID | Y |
| enc_idp | String | Encrypted key for IdP information | Y |
Request body example
{
"appid": "com.com2us.hivesdk.ios.community.global.normal",
"enc_idp": "K+A4xduO7kf5OrJ/iDPqL2wrbMQTkNQ+jDz3OCCdGiezVsfW74kV0c/Qn2ipdP/ChFBUXoZkEUP03X26MVHnvgqHo9JG2BUCsRVcrsx+03IPRvpzjXAiY5c0tihk45jMWuPYo7q+j5Rsz8eSTKQo1vE9N85huOJWc8IAJKMqBRlpmiNfj+CgZQ5I7uV2u1nHhiLfwRqpt0vG/dT9mpdQisiKUS2mFIpgPnVSZaVMY7qnTvP+mTU11Yv2DhOq2VEycAic9Ko8UkBnllXEApqarqF5s4jg6bu9DxcnRNtZeaGbh4fZKEptjGuE6qqo3CsC1PN5TnU0Wf5uav07CaazsTpEBvA9SNZefWEeTDP2ePK8qd573vpXy4OQHpTOJkVm1AsN/Ir8Fssj9SKGdYyVuZ282VDAiFLAIlVyK4pAfjJRAve+G9tIm/i4mgQmuAqW"
}
Response body
| Field Name | Type | Description | Remarks |
| result_code | Integer | Result code | |
| result_msg | String | Result Message | |
| data | JSON | Result Data | |
| data.web_idp_token | String | External PC Auto Login Token | |
Response body sample
{
"result_code": 0,
"result_msg": "SUCCESS",
"data": {
"web_idp_token": "c47e61856f04f0a6194ddcbabca70a7f10552d044181386e625676fd07a63aee5d2b162a78a55bad350ed58fb07b79be8fea1c786108307f32b602019f31ac8d"
}
}
Result code
| result_code | Description |
| 0 | Success |
| 4000 | Invalid request parameter |
| 4012 | enc_idp decryption error |