Seamless authentication via social network access token

When to use this

Use seamless token authentication when your game client or app already has a valid social network access token. Instead of a browser redirect, the client exchanges that token for Xsolla Login credentials in a single request. Depending on the protocol, the response returns a JWT (JWT protocol) or a login URL with an authorization code (OAuth 2.0 protocol). Seamless authentication fits the following cases:

  • In-game auto-login into a webshop, where the player has already signed in to the social network inside the game client.
  • Desktop and console applications, where authentication with a redirect isn’t available or degrades the user experience.

Seamless authentication via social network access token works for the following social networks: Xsolla, Facebook, Google, LinkedIn, Twitter, Discord, Naver, Baidu, Battle.net, WeChat, QQ.

If the client doesn’t have a social network access token (for example, the user hasn’t authenticated with it yet), the seamless scenario won’t work. For such cases, implement the browser-redirect scenario using the following methods:

Comparison of seamless authentication and browser-redirect flow

Browser-redirect flowSeamless token authentication
User experienceThe game opens a browser with the social network’s login page. The user authenticates and is redirected back to the game.The game passes the social network token, and the user is authenticated automatically. No browser opens.
Number of requestsSeveral requests.One.
In-game auto-loginNo — the user needs to switch to a browser.Yes.

During seamless authentication, Xsolla Login accepts the social network access token the client already has, validates it via the social network’s API, finds the matching user or creates a new one, and returns a JWT or a login URL — all in a single request, with no browser involvement.

Seamless token authentication

Browser-redirect flow

Seamless authentication API calls

To implement seamless token authentication for a social network, use the following API calls, depending on the authentication protocol you choose:

Was this article helpful?
Thank you!
Is there anything we can improve? Message
We’re sorry to hear that
Please explain why this article wasn’t helpful to you. Message
Thank you for your feedback!
We’ll review your message and use it to help us improve your experience.
Last updated: September 30, 2026

Found a typo or other text error? Select the text and press Ctrl+Enter.

Report a problem
We always review our content. Your feedback helps us improve it.
Provide an email so we can follow up
Thank you for your feedback!
We couldn't send your feedback
Try again later or contact us at [email protected].