> ## Documentation Index
> Fetch the complete documentation index at: https://devdocs.xbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate Entity Token

> Method for a server to validate a client provided EntityToken. Only callable by the title entity.

Allowed entity token types: title



## OpenAPI

````yaml /services/playfab/api-references/rest/authentication/authentication.openapi.json post /Authentication/ValidateEntityToken
openapi: 3.0.0
info:
  version: '260922'
  title: PlayFab Authentication API
  description: >-
    The Authentication APIs provide a convenient way to convert classic
    authentication responses into entity authentication models. These APIs will
    provide you with the entity authentication token needed for subsequent
    Entity API calls. The game_server API is designed to create uniquely
    identifiable game_server entities. The game_server Entity token can be used
    to call Matchmaking Lobby and Pubsub for server scenarios.
  termsOfService: https://playfab.com/terms/
  contact:
    url: https://community.playfab.com/index.html
  license:
    name: Apache 2.0
    url: https://github.com/PlayFab/API_Specs/blob/master/LICENSE
servers:
  - url: https://{titleId}.playfabapi.com
    description: PlayFab title endpoint
    variables:
      titleId:
        default: your_title_id
        description: Your PlayFab title ID (hex).
security: []
tags:
  - name: Authentication
    description: Authentication APIs
paths:
  /Authentication/ValidateEntityToken:
    post:
      tags:
        - Authentication
      summary: Validate Entity Token
      description: >-
        Method for a server to validate a client provided EntityToken. Only
        callable by the title entity.


        Allowed entity token types: title
      operationId: ValidateEntityToken
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ValidateEntityTokenRequest'
        description: >-
          Given an entity token, validates that it hasn't expired or been
          revoked and will return details of the owner.
      responses:
        '200':
          $ref: '#/components/responses/ValidateEntityTokenResponse'
        '400':
          $ref: '#/components/responses/ApiErrorWrapper'
      security:
        - EntityToken: []
components:
  schemas:
    ValidateEntityTokenRequest:
      description: >-
        Given an entity token, validates that it hasn't expired or been revoked
        and will return details of the owner.
      type: object
      properties:
        CustomTags:
          description: >-
            The optional custom tags associated with the request (e.g. build
            number, external trace identifiers, etc.).
          type: object
        EntityToken:
          description: Client EntityToken
          type: string
      required:
        - EntityToken
      example:
        EntityToken: 50c61b9065b27a124a400ee3b95d404313986969
    ValidateEntityTokenResponse:
      type: object
      properties:
        Entity:
          allOf:
            - $ref: '#/components/schemas/EntityKey'
          description: The entity id and type.
        IdentifiedDeviceType:
          allOf:
            - $ref: '#/components/schemas/IdentifiedDeviceType'
          description: The authenticated device for this entity, for the given login
        IdentityProvider:
          allOf:
            - $ref: '#/components/schemas/LoginIdentityProvider'
          description: The identity provider for this entity, for the given login
        IdentityProviderIssuedId:
          description: The ID issued by the identity provider, e.g. a XUID on Xbox Live
          type: string
        Lineage:
          allOf:
            - $ref: '#/components/schemas/EntityLineage'
          description: The lineage of this profile.
      example:
        Lineage:
          NamespaceId: '1679471093'
          TitleId: '26917491733'
          MasterPlayerAccountId: '1234567787392'
          TitlePlayerAccountId: '42434567785265'
        IdentityProvider: PlayFab
        IdentifiedDeviceType: XboxOne
        IdentityProviderIssuedId: '2533274790395904'
        Entity:
          Id: '42434567785265'
          Type: title_player_account
          TypeString: title_player_account
    ApiErrorWrapper:
      description: The basic wrapper around every failed API response
      type: object
      properties:
        code:
          description: Numerical HTTP code
          type: integer
        status:
          description: String HTTP code
          type: string
        error:
          description: Playfab error code
          type: string
        errorCode:
          description: Numerical PlayFab error code
          type: integer
        errorMessage:
          description: Description for the PlayFab errorCode
          type: string
        errorDetails:
          description: Detailed description of individual issues with the request object
          type: object
      required:
        - code
        - errorCode
    EntityKey:
      description: >-
        Combined entity type and ID structure which uniquely identifies a single
        entity.
      type: object
      properties:
        Id:
          description: Unique ID of the entity.
          type: string
        Type:
          description: >-
            Entity type. See
            https://learn.microsoft.com/gaming/playfab/features/data/entities/available-built-in-entity-types
          type: string
      required:
        - Id
    IdentifiedDeviceType:
      type: string
      enum:
        - Unknown
        - XboxOne
        - Scarlett
        - WindowsOneCore
        - WindowsOneCoreMobile
        - Win32
        - android
        - iOS
        - PlayStation
        - Nintendo
    LoginIdentityProvider:
      type: string
      enum:
        - Unknown
        - PlayFab
        - Custom
        - GameCenter
        - GooglePlay
        - Steam
        - XBoxLive
        - PSN
        - Kongregate
        - Facebook
        - IOSDevice
        - AndroidDevice
        - Twitch
        - WindowsHello
        - GameServer
        - CustomServer
        - NintendoSwitch
        - FacebookInstantGames
        - OpenIdConnect
        - Apple
        - NintendoSwitchAccount
        - GooglePlayGames
        - XboxMobileStore
        - King
        - BattleNet
    EntityLineage:
      type: object
      properties:
        CharacterId:
          description: The Character Id of the associated entity.
          type: string
        GroupId:
          description: The Group Id of the associated entity.
          type: string
        MasterPlayerAccountId:
          description: The Master Player Account Id of the associated entity.
          type: string
        NamespaceId:
          description: The Namespace Id of the associated entity.
          type: string
        TitleId:
          description: The Title Id of the associated entity.
          type: string
        TitlePlayerAccountId:
          description: The Title Player Account Id of the associated entity.
          type: string
  responses:
    ValidateEntityTokenResponse:
      description: ''
      content:
        application/json:
          schema:
            type: object
            properties:
              code:
                type: integer
                description: >-
                  The Http status code. If X-ReportErrorAsSuccess header is set
                  to true, this will report the actual http error code.
              status:
                type: string
                description: The Http status code as a string.
              data:
                $ref: '#/components/schemas/ValidateEntityTokenResponse'
            example:
              code: 200
              status: OK
              data:
                Lineage:
                  NamespaceId: '1679471093'
                  TitleId: '26917491733'
                  MasterPlayerAccountId: '1234567787392'
                  TitlePlayerAccountId: '42434567785265'
                IdentityProvider: PlayFab
                IdentifiedDeviceType: XboxOne
                IdentityProviderIssuedId: '2533274790395904'
                Entity:
                  Id: '42434567785265'
                  Type: title_player_account
                  TypeString: title_player_account
    ApiErrorWrapper:
      description: This is the outer wrapper for all responses with errors
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorWrapper'
  securitySchemes:
    EntityToken:
      type: apiKey
      in: header
      name: X-EntityToken
      description: >-
        This API requires an Entity Session Token, available from the Entity
        GetEntityToken method.

````

## Related topics

- [Validate Entity Token](/services/playfab/api-references/rest/authentication/authentication/validate-entity-token.md)
- [PFAuthenticationValidateEntityTokenRequest](/services/playfab/api-references/c/pfauthenticationtypes/structs/pfauthenticationvalidateentitytokenrequest.md)
- [PFAuthenticationValidateEntityTokenAsync](/services/playfab/api-references/c/pfauthentication/functions/pfauthenticationvalidateentitytokenasync.md)
- [PFAuthenticationValidateEntityTokenResponse](/services/playfab/api-references/c/pfauthenticationtypes/structs/pfauthenticationvalidateentitytokenresponse.md)
- [PFAuthenticationValidateEntityTokenGetResult](/services/playfab/api-references/c/pfauthentication/functions/pfauthenticationvalidateentitytokengetresult.md)
