REST API: authentication
Base URL: https://allgameclub.com/api/v1. All responses are JSON:
{ "ok": true, "data": { … }, "meta": { … } }
{ "ok": false, "error": { "code": "not_found", "message": "Unknown game." } }
Three ways to authenticate
| Method | Header | Who | Typical use |
|---|---|---|---|
| Portal session | cookie + X-Requested-With: AllGameSDK | the logged-in player | the SDK inside the play shell |
| Player token | Authorization: Bearer agp_… | one player | companion apps, scripts, local development |
| Developer key | Authorization: Bearer agk_… | your game's backend | server-to-server, acting for any player of your game |
Player tokens
Created under Account → Security → API tokens, or via the API:
curl -X POST https://allgameclub.com/api/v1/auth/login \
-H 'Content-Type: application/json' \
-d '{"login":"ada@example.com","password":"…","device_name":"CLI"}'
{ "ok": true, "data": { "player": { … }, "token": "agp_3f9…", "token_expires_at": "2027-01-09T10:00:00+00:00", "entitlement": { … } } }
Tokens expire after 90 days by default (api.token_ttl_days). Up to 10 active tokens per player. POST /auth/logout revokes the token used for the call.
Registration via API
curl -X POST https://allgameclub.com/api/v1/auth/register \
-H 'Content-Type: application/json' \
-d '{"email":"ada@example.com","password":"correct horse","display_name":"Ada"}'
Returns the new player and a token (201). A verification email is sent; players can play immediately.
Developer keys
See Developer keys. They never grant access to email addresses or account settings.
Session cookie calls from JavaScript
When your code runs on the portal origin (inside the play shell), fetch with credentials: 'same-origin' and the header X-Requested-With: AllGameSDK is enough. The custom header is what protects against cross-site request forgery; browsers will not send it cross-origin without a preflight, and the API does not allow cross-origin requests.
HTTPS and CORS
The API is served over HTTPS only. Cross-origin browser requests are not allowed; call the API from your server or from code running on the portal.
Last updated October 11, 2026.