DEVELOPER GUIDE
Start as a guest.
Keep your progress.
Give visitors a persistent identity before they sign in. When they choose Hybrid ID, link their guest profile to the account they authenticate. Your application keeps its own activity and progress.
Connect in four steps
- Enable guest profiles in your registered Developer App.
- Create a separate app-scoped guest credential. Keep it in your backend secret manager.
- Register one stable guest ID and a hashed guest-session proof. Retry with the same ID; keep gameplay in your database.
- When the user chooses to keep their progress, request
guest:linkthrough Hybrid ID sign-in and link with both the guest proof and current OIDC token.
Your SSO client secret cannot create guest profiles. A guest is not an authenticated or verified user, and linking does not confer wallet or agent authority.
One endpoint, explicit operations
POST /api/developer/v1/guests
- Create: idempotent registration by app and external guest ID.
- Read: retrieve only your app’s guest record.
- Link: verify guest possession and user-approved sign-in.
- Usage: inspect retained guests and pooled capacity.
Protect existing accounts
- Use the validated issuer and pairwise subject as the registered-account key.
- Preserve existing history and deduplicate match or award events.
- Never merge by email or accept a client’s claimed score as verified progress.
- Use bounded retries for transient failures; stop automatic retries when capacity is exhausted.
The full guide includes the StarQuest handoff, credential setup, request bodies, errors and retry behavior.
Usage and boundaries
Unclaimed guest capacity is 5× your plan’s included monthly user allowance, pooled across all your apps: 5,000 on Developer, 12,500 on Growth, 50,000 on Pro and 250,000 on Scale. Linking frees a slot while preserving guest history. At capacity, new guest registrations pause. Notify the developer and present the plan upgrade action; existing guests remain available. Guests do not consume your monthly active-user allowance and guest access is not billed at present. Registered monthly sign-ins and optional key-value data have separate meters. See guest counts under Plans & usage.
Persisted guests contribute to the public managed-identity count. This is not a count of unique humans or verified accounts. Explorer proof publication is pending; API responses explicitly say when no proof has been published.
Guest registration does not open public Hybrid ID account registration or create an email/password account automatically.