Skip to Content

Session & Auth

The events the iFrame sends when a player tries to log in, register, or when authentication fails — plus the one message you are obliged to send back when a session ends.

Tip

Every message exchanged between the iFrame and your page — its direction, payload and exact envelope — is listed on the postMessage Reference page.

Ending a session

The iFrame logs out every time the player enters the iFrame page, then logs in again if a JWT was provided.

Important

When a player’s session expires on your platform, it is the operator’s responsibility to either send the logout command or re-render the iFrame. Without it the player stays authorized inside the iFrame after logging out of your site.

Example:
import integration from "services/integration"; integration.helpers.logout();

logout is one key in the shared iframe command envelope — see The iframe command envelope for the others.

Auth events from the iFrame

The iFrame emits these when a player attempts something that needs an account. Handle all three: an unhandled login.click means a player who clicks Login inside the iFrame sees nothing happen.

EventFires whenYou must
login.clickThe player clicks Login, or attempts an action that requires authorization while anonymousOpen your login modal, or route to your login page
register.clickThe player clicks Register, or attempts an action that requires an accountOpen your registration modal, or route to your registration page
auth.failAuthentication succeeded on your site but the JWT was rejected inside the iFrameHandle the failure — re-issue a token, or log the player out

auth.fail is especially useful during initial integration: it tells you the token you generated could not be used to log the player in, which is otherwise invisible from your side.

Example:
import integration from "path_to/integration"; const on = integration.on; const unsubscriptions = []; unsubscriptions.push( on("login.click", () => { // open the login modal, or route to your login page }), ); unsubscriptions.push( on("register.click", () => { // open the registration modal, or route to your registration page }), ); unsubscriptions.push( on("auth.fail", () => { // the JWT was rejected — re-issue a token or log the player out }), ); // Later, to clean up every listener at once: unsubscriptions.forEach((sub) => sub.off());