# Build a game. Give players a way in. Attract Mode developer documentation: browser-game listings, verified studio pages, reviewed account integration and the open-source starter kit. ## Start with your game Attract Mode helps players discover browser games and the people making them. Your game can have its own listing, while your studio page brings your games together. A listing can link to your existing site. You do not need to replace your game’s accounts to be listed. If you want players to use their Attract Mode account in your game, request a reviewed account integration. Listing, verified page management and account integration are separate steps. None automatically grants the others. ## Run the demo in a few minutes Install Node.js 24 or later, download the .zip and extract it. Open a terminal in the extracted folder containing package.json. Review the source before running it. npm ci --ignore-scripts npm run dev Open http://127.0.0.1:3000. Click targets, choose Simulate sign-in (offline), then sign out. No real credentials are needed. This simulation creates no Attract Mode account and makes no real sign-in requests. Dependencies download during installation; the default demo runs offline afterward. Stop it with Ctrl+C. Have an existing game? The agent setup guide at /docs/agents explains how to install the integration skill into that project without replacing its engine or guest play. ## Get a playable starting point The browser-game kit contains a playable example and a backend account adapter. Read its README and run its tests before changing the game. It is a starting point for your own implementation, not a registered production OAuth client. You can build a game without an Attract Mode integration. To connect real accounts, get a client registered for your game and its exact callback URLs. Keep credentials on your server. The example’s mock tests do not establish that your production integration has passed review. ## What is available today Public game and studio pages, search and game reviews are available. Verified developers can propose changes to their approved pages in the developer workspace. Changes receive an independent review before publication. Reviewed OAuth 2.0 / OpenID Connect account integration is available for approved clients. Player consent applies to third-party games. Account identity does not include a general API for shared saves, friends, XP, playtime, achievements, purchases or entitlements. There is no public payments, subscription billing, developer payout or revenue-sharing API in this kit. Commercial arrangements require separate agreement. A listing does not promise traffic, income or a particular position in search. ## Choose your next step Use the publishing guide to submit or claim a listing. Use the account guide when you are ready to request a real login integration. The developer workspace is where signed-in developers manage their own requests. The machine-readable capability manifest records the same availability limits as these pages. It is documentation, not an API endpoint for creating clients, changing listings or accessing player data. ## Resources - [Agent setup guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/agents/README.md) - [Local MCP guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/mcp/README.md) - [Integration skill](https://github.com/AttractMode-io/browser-game-kit/tree/main/skills/attract-mode-integration) - [Developer workspace](https://attractmode.io/developers) - [Source code](https://github.com/AttractMode-io/browser-game-kit) - [Download the starter kit (.zip)](https://github.com/AttractMode-io/browser-game-kit/releases/latest/download/attract-mode-browser-game-kit.zip) - [Developer docs](https://attractmode.io/docs) --- # Connect accounts without guessing the contract. Request reviewed Attract Mode OAuth and OpenID Connect integration, register exact callbacks, and protect player sessions with PKCE, state and token validation. ## Request a client for your game Send the team your game URL, backend stack, exact HTTPS callback URLs and the minimum player information you need. Use the developer workspace or hello@attractmode.io. Production and test callbacks need separate review. Client creation is not self-service. Each approved third-party game gets its own registered OAuth client. Do not reuse another game’s client ID. You receive the approved client configuration and scopes during onboarding. Do not infer permissions from another game or from Attract Mode’s internal account routes. ## Use the registered OpenID Connect configuration The identity issuer is https://dupwygdktojsuuzatmih.supabase.co/auth/v1. Use its discovery document and the client configuration supplied after review. The browser-game kit demonstrates authorization code flow with PKCE S256, state and nonce. Only request the scopes approved for your client. Store the PKCE verifier, random state and nonce in a short-lived server-side session tied to the initiating browser. Redirect to the discovered authorization endpoint with the exact registered callback. On return, reject a missing or mismatched state, an expired flow and reused authorization codes. Exchange the code on your backend. Validate ID token signature, issuer, audience, expiry and nonce using the issuer’s current keys. Use the stable subject as the player account identifier. Do not link existing game accounts simply because their email addresses match. ## Keep the session on your side Create a secure HttpOnly session for your own game after validation. Protect state-changing requests against CSRF. Keep secrets and provider tokens out of browser bundles, URLs, analytics, logs and local storage. Do not ask players for their Attract Mode password. Third-party players review consent. First-party consent exceptions do not carry over to other publishers. Do not iframe the login page or attempt to read cookies from another domain. Handle declined consent, account switching, revoked authorization and expired sessions. Make local sign-out clear; it should end your game’s session. ## Test before asking for the connected label Check new and returning players, enabled social providers, consent acceptance and cancellation, incorrect state and verifier, expired and replayed codes, account switching and sign-out. Test mobile Safari and Chrome as well as desktop browsers. Send the build and test evidence to the team. A verified listing alone does not make a game an Attract Mode account integration. Only registered and tested integrations receive the connected label. ## Identity is the current boundary The account integration identifies a consenting player. It does not grant a shared saves, friends, XP, achievements, playtime, purchase or entitlement API. Do not ship requests to undocumented internal endpoints. Any additional capability needs a separate published contract and authorization review. ## Resources - [Agent setup guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/agents/README.md) - [Local MCP guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/mcp/README.md) - [Integration skill](https://github.com/AttractMode-io/browser-game-kit/tree/main/skills/attract-mode-integration) - [Developer workspace](https://attractmode.io/developers) - [Source code](https://github.com/AttractMode-io/browser-game-kit) - [Download the starter kit (.zip)](https://github.com/AttractMode-io/browser-game-kit/releases/latest/download/attract-mode-browser-game-kit.zip) - [Developer docs](https://attractmode.io/docs) --- # Give your game a page players can trust. Submit a browser game, verify control of an existing listing, manage approved pages and understand the review process for links, media and launch domains. ## Submit a browser game Use the developer workspace to submit your game’s public URL and a useful description of how it plays. Include the real creator or studio, supported devices and controls, and original screenshots or other media you have permission to use. Be clear about sign-in requirements and whether the build is unfinished. Catalog selection is editorial. The team checks the playable build and supporting sources. Submission does not guarantee a listing or a daily feature. A listing describes a game; it does not imply a commercial partnership or account integration. ## One studio, several games A studio page can collect multiple games. Developer and publisher credits can be different. Each approved claim is scoped to a particular page and role. Control of one game does not give you control of another developer’s game or an unrelated studio. If a page already exists, use its claim option while signed into your Attract Mode account. Select the studio you represent. Never send passwords, private keys or identity documents as ownership evidence. ## Prove control of the established identity The team checks the creator’s established public identity independently of your claim. The claim flow supplies an expiring challenge bound to your account, studio and requested page. Available proof routes include a post from the established X account, a fixed website proof or a DNS record. Follow the exact challenge shown in your workspace and submit its evidence for review. An operator checks the evidence and conflicts before granting scoped access. A matching display name or a paid social badge is not enough. Proof is one-use, and verification can be revoked if authority changes or evidence fails. ## Make changes with a record After verification, submit copy changes with source evidence in the workspace. The review history keeps decisions and versions. An independent operator reviews proposed copy. Approved copy is queued for the next site publication, so approval does not mean the live page has already changed. You can also propose links, media and structured corrections through the workspace. These receive editorial review and a publication record. New launch domains require fresh domain proof and checking of the proposed site. A proposed URL does not automatically change the live launch link. Use factual descriptions and media you have the right to publish. Include supporting sources for changes. Reviewers can reject a proposal or ask for clarification. Rollbacks preserve history rather than erasing earlier decisions. ## What verification does not grant Page verification does not grant billing access, OAuth client administration, access to other studios or control of player data. Account integration requires separate approval. Payments and revenue sharing require separate commercial terms. Claim evidence and review records belong in the private workspace, not a public game description. Public pages show approved editorial information. Contact hello@attractmode.io if a listing’s ownership or published information is wrong. ## Resources - [Agent setup guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/agents/README.md) - [Local MCP guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/mcp/README.md) - [Integration skill](https://github.com/AttractMode-io/browser-game-kit/tree/main/skills/attract-mode-integration) - [Developer workspace](https://attractmode.io/developers) - [Source code](https://github.com/AttractMode-io/browser-game-kit) - [Download the starter kit (.zip)](https://github.com/AttractMode-io/browser-game-kit/releases/latest/download/attract-mode-browser-game-kit.zip) - [Developer docs](https://attractmode.io/docs) --- # Give your coding agent the right starting point. Install the Attract Mode integration skill for Codex, Claude Code, Cursor or Gemini CLI, or connect the optional local read-only documentation MCP. ## Install the skill in your game project Download and extract the browser-game kit first. From the kit folder, choose one command below. Replace /absolute/path/to/game with the path to your existing game directory. Use Node.js 24 or later. node agents/install.mjs codex /absolute/path/to/game node agents/install.mjs claude /absolute/path/to/game node agents/install.mjs cursor /absolute/path/to/game node agents/install.mjs gemini /absolute/path/to/game Choose the command for your coding client. The installer copies the bundled skill into that project only. It does not download code, install dependencies, modify global settings or register an OAuth client. Existing skill destinations and symlinked destination directories are rejected. Review a new release before replacing an installed skill. ## Where each client finds it Codex: .agents/skills/attract-mode-integration. Invoke it with $attract-mode-integration. Claude Code: .claude/skills/attract-mode-integration. Invoke it with /attract-mode-integration. Cursor: .cursor/skills/attract-mode-integration. Ask the agent to use the Attract Mode integration skill. Gemini CLI: .gemini/skills/attract-mode-integration. Ask the agent to use the Attract Mode integration skill. Reload your coding client if it does not discover the new skill. This installs into a local coding environment, not a web chat. A plain chat cannot change your game without access to its development environment. ## A useful first request Use the Attract Mode integration skill to inspect this browser game. Run the kit’s mock locally, add optional sign-in using my existing backend, and test cancellation, session expiry and logout. Keep guest play intact. Tell me what needs real client registration before production. Do not invent achievement or payment APIs. ## Optional: searchable local documentation with MCP The kit includes a local, read-only documentation MCP server. The skill and demo work without it. It searches a fixed set of documents bundled with your downloaded release; it does not search the live game catalog. npm --prefix mcp ci --ignore-scripts npm --prefix mcp test After reviewing the MCP README, configure your client to launch node with /absolute/path/to/browser-game-kit/mcp/server.mjs as its argument. Merge the entry into the existing configuration. Do not replace the whole configuration or use npm start as the transport command. The server exposes get_capabilities, search_docs and read_doc. It requires no credentials, has no account connection, performs no writes and opens no network listener. It cannot create a client, change a listing, access player data, grant achievements or take payments. It is not a hosted API or automatic recommendation service. Local stdio requires a compatible local MCP client. The kit does not supply a bridge for remote web chat. Reconnect the client and confirm the tools are available before relying on them. ## Read the source and current setup instructions The GitHub agent setup guide covers installation and invocation. The MCP README includes client configuration examples and the full security boundary. The integration skill contains the account contract and review checklist. Update your downloaded kit when you need newer documentation. ## Resources - [Agent setup guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/agents/README.md) - [Local MCP guide](https://github.com/AttractMode-io/browser-game-kit/blob/main/mcp/README.md) - [Integration skill](https://github.com/AttractMode-io/browser-game-kit/tree/main/skills/attract-mode-integration) - [Developer workspace](https://attractmode.io/developers) - [Source code](https://github.com/AttractMode-io/browser-game-kit) - [Download the starter kit (.zip)](https://github.com/AttractMode-io/browser-game-kit/releases/latest/download/attract-mode-browser-game-kit.zip) - [Developer docs](https://attractmode.io/docs)