# Attract Mode: developer integration brief

Updated September 28, 2026. Public information; no credentials.

## Start with a listing

Submit a browser game at https://attractmode.io/developers. Existing listings have a claim link. One developer, studio or publisher profile can be credited on multiple games. A game can have distinct developer and publisher credits. Each role and ownership claim is reviewed separately.

Editorial pages are not partnerships. A claim request is private, is stored against your signed-in Attract Mode account and studio, and does not automatically grant control. The review team checks the original creator and game domain. Link to a public ownership reference; never submit passwords, secret keys or identity documents.

After a verified claim, the team can update your page and approved media. Public self-service page editing is not open yet. SSO is a separate onboarding step, not a requirement to be listed.

## Request an account integration

Tell us your game URL, server stack, exact HTTPS callback URLs, and the minimum player information you need. Attract Mode registers each approved third-party game as a separate OAuth client. There is no self-service client-creation endpoint. Request production and test URLs separately. Do not use another game's client ID.

Use the authorization-code flow with PKCE (S256) and a cryptographically random state value. The identity issuer is https://dupwygdktojsuuzatmih.supabase.co/auth/v1. Use issuer discovery and the registered client configuration supplied after review; do not infer endpoint URLs or scopes from this brief. Do not copy Attract Mode's internal account APIs or credentials into your game.

Your backend must:

1. Save state and the PKCE verifier in a short-lived server-side session bound to the initiating browser.
2. Redirect to the configured authorization endpoint using the exact registered callback and minimum approved scopes.
3. Validate state and expiry on the callback, exchange the one-use code with its verifier, and reject replay or mismatched callbacks.
4. Validate issuer, audience, signature and expiry of identity tokens using the issuer's current keys. Use the stable subject as the account key, not an email address.
5. Create its own secure, HttpOnly session. Never put tokens in game URLs, analytics, logs, local storage or client-side bundles. Keep client secrets on the backend when the registered client requires one.
6. Handle cancellation, revoked authorization, expired sessions and local sign-out. Do not silently link an existing game account by email alone.

Third-party games show a player consent screen. First-party consent exceptions do not apply to external publishers. Do not iframe the sign-in page or attempt cross-domain cookie access. Do not collect Attract Mode passwords.

## Separate capabilities

Account identity does not automatically provide shared saves, friends, XP, achievements, hours, purchases or entitlements. Each capability needs an explicit contract, authorization design and implementation. Purchases, subscription inclusion and revenue sharing require separate commercial terms. No revenue split, payout schedule or traffic guarantee is promised by a listing.

## Review before the connected badge

Test new/returning users; each enabled social provider; consent acceptance and cancellation; wrong state/verifier; expired/replayed codes; account-switch behavior; sign-out; mobile Safari and Chrome. Provide the build and test evidence to the Attract Mode team. Only registered, tested integrations receive the connected label.

Contact: hello@attractmode.io
