Skip to main content
POST
Set Player Secret

Authorizations

X-SecretKey
string
header
required

This API requires a title secret key, available to title admins, from PlayFab Game Manager.

Body

application/json

APIs that require signatures require that the player have a configured Player Secret Key that is used to sign all requests. Players that don't have a secret will be blocked from making API calls until it is configured. To create a signature header add a SHA256 hashed string containing UTF8 encoded JSON body as it will be sent to the server, the current time in UTC formatted to ISO 8601, and the players secret formatted as 'body.date.secret'. Place the resulting hash into the header X-PlayFab-Signature, along with a header X-PlayFab-Timestamp of the same UTC timestamp used in the signature.

APIs that require signatures require that the player have a configured Player Secret Key that is used to sign all requests. Players that don't have a secret will be blocked from making API calls until it is configured. To create a signature header add a SHA256 hashed string containing UTF8 encoded JSON body as it will be sent to the server, the current time in UTC formatted to ISO 8601, and the players secret formatted as 'body.date.secret'. Place the resulting hash into the header X-PlayFab-Signature, along with a header X-PlayFab-Timestamp of the same UTC timestamp used in the signature.

PlayFabId
string
required

Unique PlayFab assigned ID of the user on whom the operation will be performed.

PlayerSecret
string

Player secret that is used to verify API request signatures.

Response

code
integer

The Http status code. If X-ReportErrorAsSuccess header is set to true, this will report the actual http error code.

status
string

The Http status code as a string.

data
object
Last modified on October 1, 2026