Skip to main content
POST
Set Player Secret

Authorizations

X-Authorization
string
header
required

This API requires a client session ticket, available from any Client Login function.

Body

application/json

APIs that require signatures require that the player have a configured Player Secret Key that is used to sign all requests. Players that don't have a secret will be blocked from making API calls until it is configured. To create a signature header add a SHA256 hashed string containing UTF8 encoded JSON body as it will be sent to the server, the current time in UTC formatted to ISO 8601, and the players secret formatted as 'body.date.secret'. Place the resulting hash into the header X-PlayFab-Signature, along with a header X-PlayFab-Timestamp of the same UTC timestamp used in the signature.

APIs that require signatures require that the player have a configured Player Secret Key that is used to sign all requests. Players that don't have a secret will be blocked from making API calls until it is configured. To create a signature header add a SHA256 hashed string containing UTF8 encoded JSON body as it will be sent to the server, the current time in UTC formatted to ISO 8601, and the players secret formatted as 'body.date.secret'. Place the resulting hash into the header X-PlayFab-Signature, along with a header X-PlayFab-Timestamp of the same UTC timestamp used in the signature.

EncryptedRequest
string

Base64 encoded body that is encrypted with the Title's public RSA key.

PlayerSecret
string

Player secret that is used to verify API request signatures.

Response

code
integer

The Http status code. If X-ReportErrorAsSuccess header is set to true, this will report the actual http error code.

status
string

The Http status code as a string.

data
object
Example:
Last modified on October 1, 2026