Login allowlist
Overview
AccelByte Gaming Services (AGS) offers you the ability to configure an allowlist for player account logins. This provides the ability to allow only specified player accounts to access certain features and can help streamline processes such as testing, feedback gathering, and event management, among others.
This article shows you how to set up a login allowlist in the AGS Admin Portal or with the AGS CLI.
Login allowlist is not yet available in AGS Public Cloud.
Permissions
Make sure your account has the permissions shown in the table below before you attempt to configure a login allowlist in the AGS Admin Portal.
| Usage | Permission Tag | Action |
|---|---|---|
| View the login allowlist configuration | ADMIN:NAMESPACE:{namespace}:LOGINALLOWLIST | READ |
| Update the login allowlist configuration | ADMIN:NAMESPACE:{namespace}:LOGINALLOWLIST | UPDATE |
To follow the AGS CLI steps, you have installed the AGS CLI and signed in with an account that has the permissions above, plus READ on ADMIN:ROLE to list roles. See Install and sign in. The examples use a Bash shell.
Configure login allowlist
- Admin Portal
- AGS CLI
-
In the AGS Admin Portal, go to your game namespace.
-
Go to Foundations > Tools & Utilities > Login Allowlist.
-
In the Role Allowlist section, add or remove the Roles from your allowlist, so that you can easily control the access for users with that specific role.
-
Click Activate to enable the login allowlist. By default, it's disabled.
-
Find the IDs of the roles that you want to allow. In the output, find each role by its
roleNameand copy itsroleId:ags iam roles list --format json -
Save the current login allowlist to a file. Replace
<YourGameNamespace>with your game namespace:ags iam allow-list get --namespace <YourGameNamespace> --format json > allowlist.json -
In
allowlist.json, add or remove role IDs inroleIds, and setactive:{
"active": true,
"namespace": "<YourGameNamespace>",
"roleIds": ["<RoleId>"]
}roleIds: the roles whose users can log in while the allowlist is active.active:trueenables the login allowlist, andfalsedisables it. IfroleIdsis empty, set it tofalse. The Admin Portal only lets you enable the allowlist when it has at least one role, and disables it when you remove the last role.
-
Send the updated allowlist. After
@, pass the path to your JSON file:ags iam allow-list update --namespace <YourGameNamespace> --json @allowlist.jsonwarningThe update replaces the whole allowlist. Always start from the current allowlist in step 2, or the update removes every role that isn't in your file.