Attract Mode / Developers
Connect accounts without guessing the contract.
Request reviewed Attract Mode OAuth and OpenID Connect integration, register exact callbacks, and protect player sessions with PKCE, state and token validation.
Request a client for your game
Send the team your game URL, backend stack, exact HTTPS callback URLs and the minimum player information you need. Use the developer workspace or hello@attractmode.io. Production and test callbacks need separate review. Client creation is not self-service.
Each approved third-party game gets its own registered OAuth client. Do not reuse another game’s client ID. You receive the approved client configuration and scopes during onboarding. Do not infer permissions from another game or from Attract Mode’s internal account routes.
Use the registered OpenID Connect configuration
The identity issuer is https://dupwygdktojsuuzatmih.supabase.co/auth/v1. Use its discovery document and the client configuration supplied after review. The browser-game kit demonstrates authorization code flow with PKCE S256, state and nonce. Only request the scopes approved for your client.
Store the PKCE verifier, random state and nonce in a short-lived server-side session tied to the initiating browser. Redirect to the discovered authorization endpoint with the exact registered callback. On return, reject a missing or mismatched state, an expired flow and reused authorization codes.
Exchange the code on your backend. Validate ID token signature, issuer, audience, expiry and nonce using the issuer’s current keys. Use the stable subject as the player account identifier. Do not link existing game accounts simply because their email addresses match.
Keep the session on your side
Create a secure HttpOnly session for your own game after validation. Protect state-changing requests against CSRF. Keep secrets and provider tokens out of browser bundles, URLs, analytics, logs and local storage. Do not ask players for their Attract Mode password.
Third-party players review consent. First-party consent exceptions do not carry over to other publishers. Do not iframe the login page or attempt to read cookies from another domain. Handle declined consent, account switching, revoked authorization and expired sessions. Make local sign-out clear; it should end your game’s session.
Test before asking for the connected label
Check new and returning players, enabled social providers, consent acceptance and cancellation, incorrect state and verifier, expired and replayed codes, account switching and sign-out. Test mobile Safari and Chrome as well as desktop browsers.
Send the build and test evidence to the team. A verified listing alone does not make a game an Attract Mode account integration. Only registered and tested integrations receive the connected label.
Identity is the current boundary
The account integration identifies a consenting player. It does not grant a shared saves, friends, XP, achievements, playtime, purchase or entitlement API. Do not ship requests to undocumented internal endpoints. Any additional capability needs a separate published contract and authorization review.
