Seamless authentication via social network access token
When to use this
Use seamless token authentication when your game client or app already has a valid social network access token. Instead of a browser redirect, the client exchanges that token for Xsolla Login credentials in a single request. Depending on the protocol, the response returns a JWT (JWT protocol) or a login URL with an authorization code (OAuth 2.0 protocol). Seamless authentication fits the following cases:
- In-game auto-login into a webshop, where the player has already signed in to the social network inside the game client.
- Desktop and console applications, where authentication with a redirect isn’t available or degrades the user experience.
Seamless authentication via social network access token works for the following social networks: Xsolla, Facebook, Google, LinkedIn, Twitter, Discord, Naver, Baidu, Battle.net, WeChat, QQ.
If the client doesn’t have a social network access token (for example, the user hasn’t authenticated with it yet), the seamless scenario won’t work. For such cases, implement the browser-redirect scenario using the following methods:
Comparison of seamless authentication and browser-redirect flow
| Browser-redirect flow | Seamless token authentication | |
|---|---|---|
| User experience | The game opens a browser with the social network’s login page. The user authenticates and is redirected back to the game. | The game passes the social network token, and the user is authenticated automatically. No browser opens. |
| Number of requests | Several requests. | One. |
| In-game auto-login | No — the user needs to switch to a browser. | Yes. |
During seamless authentication, Xsolla Login accepts the social network access token the client already has, validates it via the social network’s API, finds the matching user or creates a new one, and returns a JWT or a login URL — all in a single request, with no browser involvement.
Seamless token authentication
%%{init: {'themeVariables': { 'noteBkgColor': 'transparent', 'noteBorderColor': 'transparent' }}}%%
sequenceDiagram
participant G as Game client
participant X as Xsolla Login
participant B as Social network
G->>X: Sends Auth via access token of social network call
X->>B: Validates access token
B-->>X: Confirms token validity
X-->>G: Returns JWT / Login URL
Browser-redirect flow
%%{init: {'themeVariables': { 'noteBkgColor': 'transparent', 'noteBorderColor': 'transparent' }}}%%
sequenceDiagram
participant G as Game client
participant X as Xsolla Login
participant B as Social network
G->>X: Sends Auth via social network call
X->>B: Redirects to login page
B->>G: Displays login form
G->>B: Submits credentials
B->>X: Returns callback with code
X-->>G: Returns JWT / Login URL
Seamless authentication API calls
To implement seamless token authentication for a social network, use the following API calls, depending on the authentication protocol you choose:
Found a typo or other text error? Select the text and press Ctrl+Enter.