Attract Mode / Developers
Keep your game site. Give accounts a secure backend.
Understand how a static browser game connects to Attract Mode through a same-origin backend-for-frontend, with server-side tokens and reviewed client registration.
Can a static browser game use Attract Mode accounts?
Yes, with an approved backend-for-frontend. Your HTML, JavaScript and game assets can remain static. The account adapter needs a server to handle the authorization-code exchange, keep credentials private and issue the game’s session cookie.
The kit does not provide a browser-only login SDK. Putting a confidential client secret into a frontend bundle, environment value embedded by the bundler or browser storage exposes it to players. Keep that configuration server-side.
Serve the game and account routes from one origin
Route /auth/login, /auth/callback, /auth/logout and /api/me to your backend while serving the game assets normally. The kit’s account panel expects same-origin routes. An API hosted on an unrelated domain is not a drop-in replacement.
Use your host’s server or routing facilities to make the backend available on the game origin. Register the exact HTTPS callback URL before real sign-in. Do not guess host-specific settings or relax origin validation to make a preview work.
The frontend only needs the current game-session status and controls for starting login or logout. It does not need the issuer’s access token, refresh token, ID token or client secret.
Replace development storage before deployment
The kit uses bounded in-memory storage for local development and tests. Production needs durable server-only storage with expiry and an atomic one-use operation for authorization transactions, especially when more than one server instance can handle a callback.
Apply the kit’s go-live checklist: HTTPS and secure cookies, trusted proxy configuration, rate limits, session expiry, deletion and revocation handling, and tests for failure paths. The provided loopback demo server refuses production mode; running its tests is not a production deployment.
Keep progress and identity separate
An authenticated account gives your game a stable issuer-and-subject identity. Decide explicitly how your own backend stores game progress and how players link an existing account. Matching emails alone are not an account-linking policy.
Attract Mode does not currently offer public shared saves, XP, achievements, payments or entitlement APIs through this integration. Guest progress remains your game’s responsibility unless a separate supported contract says otherwise.
Example source files
Static frontend and backend guide ↗
