Session & Auth
The events the iFrame sends when a player tries to log in, register, or when authentication fails — plus the one message you are obliged to send back when a session ends.
Every message exchanged between the iFrame and your page — its direction, payload and exact envelope — is listed on the postMessage Reference page.
Ending a session
The iFrame logs out every time the player enters the iFrame page, then logs in again if a JWT was provided.
When a player’s session expires on your platform, it is the operator’s responsibility to either send the logout command or re-render the iFrame. Without it the player stays authorized inside the iFrame after logging out of your site.
import integration from "services/integration";
integration.helpers.logout();logout is one key in the shared iframe command envelope — see The iframe command envelope for the others.
Auth events from the iFrame
The iFrame emits these when a player attempts something that needs an account. Handle all three: an unhandled login.click means a player who clicks Login inside the iFrame sees nothing happen.
| Event | Fires when | You must |
|---|---|---|
login.click | The player clicks Login, or attempts an action that requires authorization while anonymous | Open your login modal, or route to your login page |
register.click | The player clicks Register, or attempts an action that requires an account | Open your registration modal, or route to your registration page |
auth.fail | Authentication succeeded on your site but the JWT was rejected inside the iFrame | Handle the failure — re-issue a token, or log the player out |
auth.fail is especially useful during initial integration: it tells you the token you generated could not be used to log the player in, which is otherwise invisible from your side.
import integration from "path_to/integration";
const on = integration.on;
const unsubscriptions = [];
unsubscriptions.push(
on("login.click", () => {
// open the login modal, or route to your login page
}),
);
unsubscriptions.push(
on("register.click", () => {
// open the registration modal, or route to your registration page
}),
);
unsubscriptions.push(
on("auth.fail", () => {
// the JWT was rejected — re-issue a token or log the player out
}),
);
// Later, to clean up every listener at once:
unsubscriptions.forEach((sub) => sub.off());Related
- Players Authorization — generating and signing the JWT
- Balance & Currency —
user.balanceand the other balance events - All Events — the full event list