> ## Documentation Index
> Fetch the complete documentation index at: https://devdocs.xbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set Player Secret

> Sets or resets the player's secret. Player secrets are used to sign API requests.



## OpenAPI

````yaml post /Admin/SetPlayerSecret
openapi: 3.0.0
info:
  version: '260922'
  title: PlayFab Admin API
  description: >-
    APIs for managing title configurations, uploaded Game Server code
    executables, and user data
  termsOfService: https://playfab.com/terms/
  contact:
    url: https://community.playfab.com/index.html
  license:
    name: Apache 2.0
    url: https://github.com/PlayFab/API_Specs/blob/master/LICENSE
servers:
  - url: https://{titleId}.playfabapi.com
    description: PlayFab title endpoint
    variables:
      titleId:
        default: your_title_id
        description: Your PlayFab title ID (hex).
security: []
tags:
  - name: Account Management
    description: Account Management APIs
  - name: Authentication
    description: Authentication APIs
  - name: Characters
    description: Characters APIs
  - name: Content
    description: Content Service APIs
  - name: Custom Server Management
    description: Custom Server Management APIs
  - name: Matchmaking
    description: Matchmaking APIs
  - name: Player Data Management
    description: Player Data Management APIs
  - name: Player Item Management
    description: Player Item Management APIs
  - name: PlayStream
    description: PlayStream Management APIs
  - name: ScheduledTask
    description: Task management APIs
  - name: Segments
    description: Segment management APIs
  - name: Server-Side Cloud Script
    description: Server-Side Cloud Script APIs
  - name: Shared Group Data
    description: Shared Group Data APIs
  - name: Title-Wide Data Management
    description: Title-Wide Data Management APIs
  - name: Xbox Store
    description: Xbox Store APIs
paths:
  /Admin/SetPlayerSecret:
    post:
      tags:
        - Authentication
      summary: Set Player Secret
      description: >-
        Sets or resets the player's secret. Player secrets are used to sign API
        requests.
      operationId: SetPlayerSecret
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SetPlayerSecretRequest'
        description: >-
          APIs that require signatures require that the player have a configured
          Player Secret Key that is used to sign all requests. Players that
          don't have a secret will be blocked from making API calls until it is
          configured. To create a signature header add a SHA256 hashed string
          containing UTF8 encoded JSON body as it will be sent to the server,
          the current time in UTC formatted to ISO 8601, and the players secret
          formatted as 'body.date.secret'. Place the resulting hash into the
          header X-PlayFab-Signature, along with a header X-PlayFab-Timestamp of
          the same UTC timestamp used in the signature.
      responses:
        '200':
          $ref: '#/components/responses/SetPlayerSecretResult'
        '400':
          $ref: '#/components/responses/ApiErrorWrapper'
      security:
        - SecretKey: []
components:
  schemas:
    SetPlayerSecretRequest:
      description: >-
        APIs that require signatures require that the player have a configured
        Player Secret Key that is used to sign all requests. Players that don't
        have a secret will be blocked from making API calls until it is
        configured. To create a signature header add a SHA256 hashed string
        containing UTF8 encoded JSON body as it will be sent to the server, the
        current time in UTC formatted to ISO 8601, and the players secret
        formatted as 'body.date.secret'. Place the resulting hash into the
        header X-PlayFab-Signature, along with a header X-PlayFab-Timestamp of
        the same UTC timestamp used in the signature.
      type: object
      properties:
        PlayerSecret:
          description: Player secret that is used to verify API request signatures.
          type: string
        PlayFabId:
          description: >-
            Unique PlayFab assigned ID of the user on whom the operation will be
            performed.
          type: string
      required:
        - PlayFabId
      example:
        PlayerSecret: ExampleSecret
        PlayFabId: ABCD1234
    SetPlayerSecretResult:
      type: object
      properties: {}
    ApiErrorWrapper:
      description: The basic wrapper around every failed API response
      type: object
      properties:
        code:
          description: Numerical HTTP code
          type: integer
        status:
          description: String HTTP code
          type: string
        error:
          description: Playfab error code
          type: string
        errorCode:
          description: Numerical PlayFab error code
          type: integer
        errorMessage:
          description: Description for the PlayFab errorCode
          type: string
        errorDetails:
          description: Detailed description of individual issues with the request object
          type: object
      required:
        - code
        - errorCode
  responses:
    SetPlayerSecretResult:
      description: ''
      content:
        application/json:
          schema:
            type: object
            properties:
              code:
                type: integer
                description: >-
                  The Http status code. If X-ReportErrorAsSuccess header is set
                  to true, this will report the actual http error code.
              status:
                type: string
                description: The Http status code as a string.
              data:
                $ref: '#/components/schemas/SetPlayerSecretResult'
    ApiErrorWrapper:
      description: This is the outer wrapper for all responses with errors
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorWrapper'
  securitySchemes:
    SecretKey:
      type: apiKey
      in: header
      name: X-SecretKey
      description: >-
        This API requires a title secret key, available to title admins, from
        PlayFab Game Manager.

````

## Related topics

- [Set Player Secret](/services/playfab/api-references/rest/client/authentication/set-player-secret.md)
- [Player Encryption Services](/services/playfab/identity/player-identity/encryption/player-encryption-services.md)
- [Profile Writes Meter API Description](/services/playfab/pricing/meters/profile-writes.md)
- [Delete Player Shared Secret](/services/playfab/api-references/rest/admin/authentication/delete-player-shared-secret.md)
- [Get Player Shared Secrets](/services/playfab/api-references/rest/admin/authentication/get-player-shared-secrets.md)
