# Keep your game site. Give accounts a secure backend.

Understand how a static browser game connects to Attract Mode through a same-origin backend-for-frontend, with server-side tokens and reviewed client registration.

## Can a static browser game use Attract Mode accounts?

Yes, with an approved backend-for-frontend. Your HTML, JavaScript and game assets can remain static. The account adapter needs a server to handle the authorization-code exchange, keep credentials private and issue the game’s session cookie.

The kit does not provide a browser-only login SDK. Putting a confidential client secret into a frontend bundle, environment value embedded by the bundler or browser storage exposes it to players. Keep that configuration server-side.

## Serve the game and account routes from one origin

Route /auth/login, /auth/callback, /auth/logout and /api/me to your backend while serving the game assets normally. The kit’s account panel expects same-origin routes. An API hosted on an unrelated domain is not a drop-in replacement.

Use your host’s server or routing facilities to make the backend available on the game origin. Register the exact HTTPS callback URL before real sign-in. Do not guess host-specific settings or relax origin validation to make a preview work.

The frontend only needs the current game-session status and controls for starting login or logout. It does not need the issuer’s access token, refresh token, ID token or client secret.

## Replace development storage before deployment

The kit uses bounded in-memory storage for local development and tests. Production needs durable server-only storage with expiry and an atomic one-use operation for authorization transactions, especially when more than one server instance can handle a callback.

Apply the kit’s go-live checklist: HTTPS and secure cookies, trusted proxy configuration, rate limits, session expiry, deletion and revocation handling, and tests for failure paths. The provided loopback demo server refuses production mode; running its tests is not a production deployment.

## Keep progress and identity separate

An authenticated account gives your game a stable issuer-and-subject identity. Decide explicitly how your own backend stores game progress and how players link an existing account. Matching emails alone are not an account-linking policy.

Attract Mode does not currently offer public shared saves, XP, achievements, payments or entitlement APIs through this integration. Guest progress remains your game’s responsibility unless a separate supported contract says otherwise.

- [Static frontend and backend guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/docs/static-frontend.md)
- [Account integration contract](https://github.com/AttractMode-io/browser-game-kit/blob/main/docs/account-integration.md)
- [Production checklist](https://github.com/AttractMode-io/browser-game-kit/blob/main/docs/go-live.md)
- [Troubleshooting](https://github.com/AttractMode-io/browser-game-kit/blob/main/docs/troubleshooting.md)

## Resources

- [Agent setup guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/agents/README.md)
- [Local MCP guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/mcp/README.md)
- [Integration skill](https://github.com/AttractMode-io/browser-game-kit/tree/main/skills/attract-mode-integration)
- [Developer workspace](https://attractmode.io/developers)
- [Source code](https://github.com/AttractMode-io/browser-game-kit)
- [Download the starter kit (.zip)](https://github.com/AttractMode-io/browser-game-kit/releases/latest/download/attract-mode-browser-game-kit.zip)
- [Developer docs](https://attractmode.io/docs)
