> ## Documentation Index
> Fetch the complete documentation index at: https://devdocs.xbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate Session Ticket

> Validated a client's session ticket, and if successful, returns details for that user

## Error codes

This operation may return the following PlayFab errors:

| Error | Code |
| --- | --- |
| InvalidSessionTicket | 1100 |




## OpenAPI

````yaml /services/playfab/api-references/rest/server/server.openapi.json post /Server/AuthenticateSessionTicket
openapi: 3.0.0
info:
  version: '260922'
  title: PlayFab Server API
  description: >-
    Provides functionality to allow external (developer-controlled) servers to
    interact with user inventories and data in a trusted manner, and to handle
    matchmaking and client connection orchestration
  termsOfService: https://playfab.com/terms/
  contact:
    url: https://community.playfab.com/index.html
  license:
    name: Apache 2.0
    url: https://github.com/PlayFab/API_Specs/blob/master/LICENSE
servers:
  - url: https://{titleId}.playfabapi.com
    description: PlayFab title endpoint
    variables:
      titleId:
        default: your_title_id
        description: Your PlayFab title ID (hex).
security: []
tags:
  - name: Account Management
    description: Account Management APIs
  - name: Analytics
    description: Analytics APIs
  - name: Authentication
    description: Authentication APIs
  - name: Character Data
    description: Character Data APIs
  - name: Characters
    description: Characters APIs
  - name: Content
    description: Content Service APIs
  - name: Friend List Management
    description: Friend List Management APIs
  - name: Matchmaking
    description: Matchmaking APIs
  - name: Platform Specific Methods
    description: Platform Specific Methods APIs
  - name: Player Data Management
    description: Player Data Management APIs
  - name: Player Item Management
    description: Player Item Management APIs
  - name: PlayStream
    description: PlayStream Management APIs
  - name: Server-Side Cloud Script
    description: Server-Side Cloud Script APIs
  - name: Shared Group Data
    description: Shared Group Data APIs
  - name: Title-Wide Data Management
    description: Title-Wide Data Management APIs
paths:
  /Server/AuthenticateSessionTicket:
    post:
      tags:
        - Authentication
      summary: Authenticate Session Ticket
      description: >
        Validated a client's session ticket, and if successful, returns details
        for that user


        ## Error codes


        This operation may return the following PlayFab errors:


        | Error | Code |

        | --- | --- |

        | InvalidSessionTicket | 1100 |
      operationId: AuthenticateSessionTicket
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AuthenticateSessionTicketRequest'
        description: >-
          Note that data returned may be Personally Identifying Information
          (PII), such as email address, and so care should be taken in how this
          data is stored and managed. Since this call will always return the
          relevant information for users who have accessed the title, the
          recommendation is to not store this data locally.
      responses:
        '200':
          $ref: '#/components/responses/AuthenticateSessionTicketResult'
        '400':
          $ref: '#/components/responses/ApiErrorWrapper'
      security:
        - SecretKey: []
components:
  schemas:
    AuthenticateSessionTicketRequest:
      description: >-
        Note that data returned may be Personally Identifying Information (PII),
        such as email address, and so care should be taken in how this data is
        stored and managed. Since this call will always return the relevant
        information for users who have accessed the title, the recommendation is
        to not store this data locally.
      type: object
      properties:
        SessionTicket:
          description: Session ticket as issued by a PlayFab client login API.
          type: string
      required:
        - SessionTicket
      example:
        SessionTicket: 4D2----8D11F4249A80000-7C64AB0A9F1D8D1A.CD803BF233CE76CC
    AuthenticateSessionTicketResult:
      type: object
      properties:
        IsSessionTicketExpired:
          description: Indicates if token was expired at request time.
          type: boolean
        UserInfo:
          allOf:
            - $ref: '#/components/schemas/UserAccountInfo'
          description: Account info for the user whose session ticket was supplied.
      example:
        UserInfo:
          PlayFabId: '10931252888739651331'
          Username: accountname
        IsSessionTicketExpired: false
    ApiErrorWrapper:
      description: The basic wrapper around every failed API response
      type: object
      properties:
        code:
          description: Numerical HTTP code
          type: integer
        status:
          description: String HTTP code
          type: string
        error:
          description: Playfab error code
          type: string
        errorCode:
          description: Numerical PlayFab error code
          type: integer
        errorMessage:
          description: Description for the PlayFab errorCode
          type: string
        errorDetails:
          description: Detailed description of individual issues with the request object
          type: object
      required:
        - code
        - errorCode
    UserAccountInfo:
      type: object
      properties:
        AndroidDeviceInfo:
          allOf:
            - $ref: '#/components/schemas/UserAndroidDeviceInfo'
          description: >-
            User Android device information, if an Android device has been
            linked
        AppleAccountInfo:
          allOf:
            - $ref: '#/components/schemas/UserAppleIdInfo'
          description: >-
            Sign in with Apple account information, if an Apple account has been
            linked
        BattleNetAccountInfo:
          allOf:
            - $ref: '#/components/schemas/UserBattleNetInfo'
          description: >-
            Battle.net account information, if a Battle.net account has been
            linked
        Created:
          description: Timestamp indicating when the user account was created
          type: string
        CustomIdInfo:
          allOf:
            - $ref: '#/components/schemas/UserCustomIdInfo'
          description: Custom ID information, if a custom ID has been assigned
        FacebookInfo:
          allOf:
            - $ref: '#/components/schemas/UserFacebookInfo'
          description: User Facebook information, if a Facebook account has been linked
        FacebookInstantGamesIdInfo:
          allOf:
            - $ref: '#/components/schemas/UserFacebookInstantGamesIdInfo'
          description: >-
            Facebook Instant Games account information, if a Facebook Instant
            Games account has been linked
        GameCenterInfo:
          allOf:
            - $ref: '#/components/schemas/UserGameCenterInfo'
          description: User Gamecenter information, if a Gamecenter account has been linked
        GoogleInfo:
          allOf:
            - $ref: '#/components/schemas/UserGoogleInfo'
          description: User Google account information, if a Google account has been linked
        GooglePlayGamesInfo:
          allOf:
            - $ref: '#/components/schemas/UserGooglePlayGamesInfo'
          description: >-
            User Google Play Games account information, if a Google Play Games
            account has been linked
        IosDeviceInfo:
          allOf:
            - $ref: '#/components/schemas/UserIosDeviceInfo'
          description: User iOS device information, if an iOS device has been linked
        KongregateInfo:
          allOf:
            - $ref: '#/components/schemas/UserKongregateInfo'
          description: >-
            User Kongregate account information, if a Kongregate account has
            been linked
        NintendoSwitchAccountInfo:
          allOf:
            - $ref: '#/components/schemas/UserNintendoSwitchAccountIdInfo'
          description: >-
            Nintendo Switch account information, if a Nintendo Switch account
            has been linked
        NintendoSwitchDeviceIdInfo:
          allOf:
            - $ref: '#/components/schemas/UserNintendoSwitchDeviceIdInfo'
          description: >-
            Nintendo Switch device information, if a Nintendo Switch device has
            been linked
        OpenIdInfo:
          description: >-
            OpenID Connect information, if any OpenID Connect accounts have been
            linked
          type: array
          items:
            $ref: '#/components/schemas/UserOpenIdInfo'
          x-isclass: true
        PlayFabId:
          description: Unique identifier for the user account
          type: string
        PrivateInfo:
          allOf:
            - $ref: '#/components/schemas/UserPrivateAccountInfo'
          description: Personal information for the user which is considered more sensitive
        PsnInfo:
          allOf:
            - $ref: '#/components/schemas/UserPsnInfo'
          description: >-
            User PlayStation™ Network account information, if a PlayStation™
            Network account has been linked
        ServerCustomIdInfo:
          allOf:
            - $ref: '#/components/schemas/UserServerCustomIdInfo'
          description: >-
            Server Custom ID information, if a server custom ID has been
            assigned
        SteamInfo:
          allOf:
            - $ref: '#/components/schemas/UserSteamInfo'
          description: User Steam information, if a Steam account has been linked
        TitleInfo:
          allOf:
            - $ref: '#/components/schemas/UserTitleInfo'
          description: Title-specific information for the user account
        TwitchInfo:
          allOf:
            - $ref: '#/components/schemas/UserTwitchInfo'
          description: User Twitch account information, if a Twitch account has been linked
        Username:
          description: User account name in the PlayFab service
          type: string
        XboxInfo:
          allOf:
            - $ref: '#/components/schemas/UserXboxInfo'
          description: User XBox account information, if a XBox account has been linked
      required:
        - Created
      example:
        PlayFabId: '10931252888739651331'
        Created: '2013-04-07T09:04:28'
        Username: accountname
        TitleInfo:
          DisplayName: User in-game name
          Origination: IOS
          Created: '2014-01-08T11:03:18'
          LastLogin: '2014-04-07T09:04:28'
          FirstLogin: '2014-01-08T11:03:18'
          TitlePlayerAccount:
            Id: 174812abf712
            Type: title_player_account
            TypeString: title_player_account
        FacebookInfo:
          FacebookId: '23525445454'
        SteamInfo:
          SteamCountry: US
          SteamCurrency: USD
        GameCenterInfo:
          GameCenterId: someone
    UserAndroidDeviceInfo:
      type: object
      properties:
        AndroidDeviceId:
          description: Android device ID
          type: string
    UserAppleIdInfo:
      type: object
      properties:
        AppleSubjectId:
          description: Apple subject ID
          type: string
    UserBattleNetInfo:
      type: object
      properties:
        BattleNetAccountId:
          description: Battle.net identifier
          type: string
        BattleNetBattleTag:
          description: Battle.net display name
          type: string
    UserCustomIdInfo:
      type: object
      properties:
        CustomId:
          description: Custom ID
          type: string
    UserFacebookInfo:
      type: object
      properties:
        FacebookId:
          description: Facebook identifier
          type: string
        FullName:
          description: Facebook full name
          type: string
    UserFacebookInstantGamesIdInfo:
      type: object
      properties:
        FacebookInstantGamesId:
          description: Facebook Instant Games ID
          type: string
    UserGameCenterInfo:
      type: object
      properties:
        GameCenterId:
          description: Gamecenter identifier
          type: string
    UserGoogleInfo:
      type: object
      properties:
        GoogleEmail:
          description: Email address of the Google account
          type: string
        GoogleGender:
          description: Gender information of the Google account
          type: string
        GoogleId:
          description: Google ID
          type: string
        GoogleLocale:
          description: Locale of the Google account
          type: string
        GoogleName:
          description: Name of the Google account user
          type: string
    UserGooglePlayGamesInfo:
      type: object
      properties:
        GooglePlayGamesPlayerAvatarImageUrl:
          description: Avatar image url of the Google Play Games player
          type: string
        GooglePlayGamesPlayerDisplayName:
          description: Display name of the Google Play Games player
          type: string
        GooglePlayGamesPlayerId:
          description: Google Play Games player ID
          type: string
    UserIosDeviceInfo:
      type: object
      properties:
        IosDeviceId:
          description: iOS device ID
          type: string
    UserKongregateInfo:
      type: object
      properties:
        KongregateId:
          description: Kongregate ID
          type: string
        KongregateName:
          description: Kongregate Username
          type: string
    UserNintendoSwitchAccountIdInfo:
      type: object
      properties:
        NintendoSwitchAccountSubjectId:
          description: Nintendo Switch account subject ID
          type: string
    UserNintendoSwitchDeviceIdInfo:
      type: object
      properties:
        NintendoSwitchDeviceId:
          description: Nintendo Switch Device ID
          type: string
    UserOpenIdInfo:
      type: object
      properties:
        ConnectionId:
          description: OpenID Connection ID
          type: string
        Issuer:
          description: OpenID Issuer
          type: string
        Subject:
          description: OpenID Subject
          type: string
    UserPrivateAccountInfo:
      type: object
      properties:
        Email:
          description: user email address
          type: string
    UserPsnInfo:
      type: object
      properties:
        IssuerId:
          description: >-
            Id of the PlayStation™ Network issuer environment this account is
            keyed under. Supply this value as IssuerId when looking the account
            up.
          type: number
          x-actualtype: int32
        PsnAccountId:
          description: PlayStation™ Network account ID
          type: string
        PsnOnlineId:
          description: PlayStation™ Network online ID
          type: string
        PsnSandboxId:
          description: PlayStation™ Network sandbox ID
          type: string
    UserServerCustomIdInfo:
      type: object
      properties:
        CustomId:
          description: Custom ID
          type: string
    UserSteamInfo:
      type: object
      properties:
        SteamActivationStatus:
          allOf:
            - $ref: '#/components/schemas/TitleActivationStatus'
          description: >-
            what stage of game ownership the user is listed as being in, from
            Steam
        SteamCountry:
          description: the country in which the player resides, from Steam data
          type: string
        SteamCurrency:
          allOf:
            - $ref: '#/components/schemas/Currency'
          description: currency type set in the user Steam account
        SteamId:
          description: Steam identifier
          type: string
        SteamName:
          description: Steam display name
          type: string
    UserTitleInfo:
      type: object
      properties:
        AvatarUrl:
          description: URL to the player's avatar.
          type: string
        Created:
          description: >-
            timestamp indicating when the user was first associated with this
            game (this can differ significantly from when the user first
            registered with PlayFab)
          type: string
        DisplayName:
          description: name of the user, as it is displayed in-game
          type: string
        FirstLogin:
          description: >-
            timestamp indicating when the user first signed into this game (this
            can differ from the Created timestamp, as other events, such as
            issuing a beta key to the user, can associate the title to the user)
          type: string
        isBanned:
          description: >-
            boolean indicating whether or not the user is currently banned for a
            title
          type: boolean
        LastLogin:
          description: timestamp for the last user login for this title
          type: string
        Origination:
          allOf:
            - $ref: '#/components/schemas/UserOrigination'
          description: source by which the user first joined the game, if known
        TitlePlayerAccount:
          allOf:
            - $ref: '#/components/schemas/EntityKey'
          description: Title player account entity for this user
      required:
        - Created
    UserTwitchInfo:
      type: object
      properties:
        TwitchId:
          description: Twitch ID
          type: string
        TwitchUserName:
          description: Twitch Username
          type: string
    UserXboxInfo:
      type: object
      properties:
        XboxUserId:
          description: XBox user ID
          type: string
        XboxUserSandbox:
          description: XBox user sandbox
          type: string
    TitleActivationStatus:
      type: string
      enum:
        - None
        - ActivatedTitleKey
        - PendingSteam
        - ActivatedSteam
        - RevokedSteam
    Currency:
      type: string
      enum:
        - AED
        - AFN
        - ALL
        - AMD
        - ANG
        - AOA
        - ARS
        - AUD
        - AWG
        - AZN
        - BAM
        - BBD
        - BDT
        - BGN
        - BHD
        - BIF
        - BMD
        - BND
        - BOB
        - BRL
        - BSD
        - BTN
        - BWP
        - BYR
        - BZD
        - CAD
        - CDF
        - CHF
        - CLP
        - CNY
        - COP
        - CRC
        - CUC
        - CUP
        - CVE
        - CZK
        - DJF
        - DKK
        - DOP
        - DZD
        - EGP
        - ERN
        - ETB
        - EUR
        - FJD
        - FKP
        - GBP
        - GEL
        - GGP
        - GHS
        - GIP
        - GMD
        - GNF
        - GTQ
        - GYD
        - HKD
        - HNL
        - HRK
        - HTG
        - HUF
        - IDR
        - ILS
        - IMP
        - INR
        - IQD
        - IRR
        - ISK
        - JEP
        - JMD
        - JOD
        - JPY
        - KES
        - KGS
        - KHR
        - KMF
        - KPW
        - KRW
        - KWD
        - KYD
        - KZT
        - LAK
        - LBP
        - LKR
        - LRD
        - LSL
        - LYD
        - MAD
        - MDL
        - MGA
        - MKD
        - MMK
        - MNT
        - MOP
        - MRO
        - MUR
        - MVR
        - MWK
        - MXN
        - MYR
        - MZN
        - NAD
        - NGN
        - NIO
        - NOK
        - NPR
        - NZD
        - OMR
        - PAB
        - PEN
        - PGK
        - PHP
        - PKR
        - PLN
        - PYG
        - QAR
        - RON
        - RSD
        - RUB
        - RWF
        - SAR
        - SBD
        - SCR
        - SDG
        - SEK
        - SGD
        - SHP
        - SLL
        - SOS
        - SPL
        - SRD
        - STD
        - SVC
        - SYP
        - SZL
        - THB
        - TJS
        - TMT
        - TND
        - TOP
        - TRY
        - TTD
        - TVD
        - TWD
        - TZS
        - UAH
        - UGX
        - USD
        - UYU
        - UZS
        - VEF
        - VND
        - VUV
        - WST
        - XAF
        - XCD
        - XDR
        - XOF
        - XPF
        - YER
        - ZAR
        - ZMW
        - ZWD
    UserOrigination:
      type: string
      enum:
        - Organic
        - Steam
        - Google
        - Amazon
        - Facebook
        - Kongregate
        - GamersFirst
        - Unknown
        - IOS
        - LoadTest
        - Android
        - PSN
        - GameCenter
        - CustomId
        - XboxLive
        - Parse
        - Twitch
        - ServerCustomId
        - NintendoSwitchDeviceId
        - FacebookInstantGamesId
        - OpenIdConnect
        - Apple
        - NintendoSwitchAccount
        - GooglePlayGames
        - XboxMobileStore
        - King
        - BattleNet
    EntityKey:
      description: >-
        Combined entity type and ID structure which uniquely identifies a single
        entity.
      type: object
      properties:
        Id:
          description: Unique ID of the entity.
          type: string
        Type:
          description: >-
            Entity type. See
            https://learn.microsoft.com/gaming/playfab/features/data/entities/available-built-in-entity-types
          type: string
      required:
        - Id
  responses:
    AuthenticateSessionTicketResult:
      description: ''
      content:
        application/json:
          schema:
            type: object
            properties:
              code:
                type: integer
                description: >-
                  The Http status code. If X-ReportErrorAsSuccess header is set
                  to true, this will report the actual http error code.
              status:
                type: string
                description: The Http status code as a string.
              data:
                $ref: '#/components/schemas/AuthenticateSessionTicketResult'
            example:
              code: 200
              status: OK
              data:
                UserInfo:
                  PlayFabId: '10931252888739651331'
                  Username: accountname
                IsSessionTicketExpired: false
    ApiErrorWrapper:
      description: This is the outer wrapper for all responses with errors
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorWrapper'
  securitySchemes:
    SecretKey:
      type: apiKey
      in: header
      name: X-SecretKey
      description: >-
        This API requires a title secret key, available to title admins, from
        PlayFab Game Manager.

````

## Related topics

- [Authenticate Session Ticket](/services/playfab/api-references/rest/server/authentication/authenticate-session-ticket.md)
- [Multiplayer session templates](/services/xbox-services/multiplayer/mpsd/concepts/live-session-templates.md)
- [Using SmartMatch matchmaking](/services/xbox-services/multiplayer/matchmaking/concepts/live-matchmaking-how-tos.md)
- [Matchmaking overview](/services/xbox-services/multiplayer/matchmaking/live-matchmaking-overview.md)
- [Multiplayer concepts overview](/services/xbox-services/multiplayer/concepts/live-multiplayer-concepts.md)
