Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Hathora AuthV1 API

Player authentication - issue short-lived player tokens.

Hathora AuthV1 API is one of 11 APIs that Hathora publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include AuthV1. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 3 operations across 3 paths, and defines 2 schemas. It is described by OpenAPI 3.0.3, at version 3.0.

Requests are made against a single base URL, https://api.hathora.dev.

3 operations 3 paths 2 schemas 3 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.3
API Version
3.0
Base URL
https://api.hathora.dev
Authentication
HTTP Bearer, HTTP Bearer
Terms of Service
Resource Areas
1

Authentication & Security 2

Hathora AuthV1 API declares 2 security schemes for authenticating requests. It accepts HTTP bearer tokens (JWT) (hathoraDevToken). It accepts HTTP bearer tokens (JWT) (playerAuth). By default, every request must be authenticated.

  • hathoraDevToken — Organization developer/API token used for management endpoints (apps, builds, deployments, processes, rooms, logs, metrics, billing, tokens).
  • playerAuth — Short-lived player token issued by the AuthV1 login endpoints, used by game clients for room and lobby operations.

Paths & Operations 3

Across 3 paths, the API surfaces 3 operations — 3 POST. Each is listed below with its method, path, parameters, and response codes.

AuthV1 3

Player authentication - issue short-lived player tokens.

POST
/auth/v1/{appId}/login/anonymous
Returns a unique player token for an anonymous user.
LoginAnonymous 1 param → 200404
POST
/auth/v1/{appId}/login/nickname
Returns a unique player token with a specified nickname.
LoginNickname 1 param body → 200
POST
/auth/v1/{appId}/login/google
Returns a unique player token using a Google-signed OIDC idToken.
LoginGoogle 1 param body → 200

Schemas 2

The contract defines 2 schemas that model the data the API accepts and returns. The most detailed are ApiError (1 property), PlayerTokenObject (1 property). Each schema is shown below with its type and property counts.

PlayerTokenObject
object
1 property
ApiError
object
1 property

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

hathora-authv1-api-openapi.yml Raw ↑

Other APIs Hathora publishes across the network.

Hathora AppsV2 API
Hathora BillingV1 API
Hathora BuildsV3 API
Hathora DeploymentsV3 API
Hathora DiscoveryV2 API
Hathora LogsV1 API
Hathora MetricsV1 API
Hathora ProcessesV3 API
Hathora RoomsV2 API
Hathora TokensV1 API