Link Xbox Id
Links the Xbox Live account associated with the provided Xbox ID and Sandbox to the user’s PlayFab account
Error codes
This operation may return the following PlayFab errors:
| Error | Code |
|---|---|
| AccountAlreadyLinked | 1011 |
| AccountNotFound | 1001 |
| InvalidNamespaceMismatch | 1561 |
| LinkedAccountAlreadyClaimed | 1012 |
POST
/
Server
/
LinkXboxId
Link Xbox Id
curl --request POST \
--url https://{titleId}.playfabapi.com/Server/LinkXboxId \
--header 'Content-Type: application/json' \
--header 'X-SecretKey: <api-key>' \
--data '
{
"XboxId": "12344553",
"Sandbox": "RETAIL",
"PlayFabId": "5A446C83645201",
"ForceLink": false
}
'import requests
url = "https://{titleId}.playfabapi.com/Server/LinkXboxId"
payload = {
"XboxId": "12344553",
"Sandbox": "RETAIL",
"PlayFabId": "5A446C83645201",
"ForceLink": False
}
headers = {
"X-SecretKey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-SecretKey': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
XboxId: '12344553',
Sandbox: 'RETAIL',
PlayFabId: '5A446C83645201',
ForceLink: false
})
};
fetch('https://{titleId}.playfabapi.com/Server/LinkXboxId', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{titleId}.playfabapi.com/Server/LinkXboxId",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'XboxId' => '12344553',
'Sandbox' => 'RETAIL',
'PlayFabId' => '5A446C83645201',
'ForceLink' => false
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-SecretKey: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{titleId}.playfabapi.com/Server/LinkXboxId"
payload := strings.NewReader("{\n \"XboxId\": \"12344553\",\n \"Sandbox\": \"RETAIL\",\n \"PlayFabId\": \"5A446C83645201\",\n \"ForceLink\": false\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-SecretKey", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{titleId}.playfabapi.com/Server/LinkXboxId")
.header("X-SecretKey", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"XboxId\": \"12344553\",\n \"Sandbox\": \"RETAIL\",\n \"PlayFabId\": \"5A446C83645201\",\n \"ForceLink\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{titleId}.playfabapi.com/Server/LinkXboxId")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-SecretKey"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"XboxId\": \"12344553\",\n \"Sandbox\": \"RETAIL\",\n \"PlayFabId\": \"5A446C83645201\",\n \"ForceLink\": false\n}"
response = http.request(request)
puts response.read_body{
"code": 123,
"status": "<string>",
"data": {}
}{
"code": 123,
"errorCode": 123,
"status": "<string>",
"error": "<string>",
"errorMessage": "<string>",
"errorDetails": {}
}Authorizations
This API requires a title secret key, available to title admins, from PlayFab Game Manager.
Body
application/json
PlayFab unique identifier of the user to link.
The id of Xbox Live sandbox.
Unique Xbox identifier for a user.
The optional custom tags associated with the request (e.g. build number, external trace identifiers, etc.).
If another user is already linked to the account, unlink the other user and re-link.
Last modified on October 1, 2026
Was this page helpful?
⌘I
Link Xbox Id
curl --request POST \
--url https://{titleId}.playfabapi.com/Server/LinkXboxId \
--header 'Content-Type: application/json' \
--header 'X-SecretKey: <api-key>' \
--data '
{
"XboxId": "12344553",
"Sandbox": "RETAIL",
"PlayFabId": "5A446C83645201",
"ForceLink": false
}
'import requests
url = "https://{titleId}.playfabapi.com/Server/LinkXboxId"
payload = {
"XboxId": "12344553",
"Sandbox": "RETAIL",
"PlayFabId": "5A446C83645201",
"ForceLink": False
}
headers = {
"X-SecretKey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-SecretKey': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
XboxId: '12344553',
Sandbox: 'RETAIL',
PlayFabId: '5A446C83645201',
ForceLink: false
})
};
fetch('https://{titleId}.playfabapi.com/Server/LinkXboxId', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{titleId}.playfabapi.com/Server/LinkXboxId",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'XboxId' => '12344553',
'Sandbox' => 'RETAIL',
'PlayFabId' => '5A446C83645201',
'ForceLink' => false
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-SecretKey: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{titleId}.playfabapi.com/Server/LinkXboxId"
payload := strings.NewReader("{\n \"XboxId\": \"12344553\",\n \"Sandbox\": \"RETAIL\",\n \"PlayFabId\": \"5A446C83645201\",\n \"ForceLink\": false\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-SecretKey", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{titleId}.playfabapi.com/Server/LinkXboxId")
.header("X-SecretKey", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"XboxId\": \"12344553\",\n \"Sandbox\": \"RETAIL\",\n \"PlayFabId\": \"5A446C83645201\",\n \"ForceLink\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{titleId}.playfabapi.com/Server/LinkXboxId")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-SecretKey"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"XboxId\": \"12344553\",\n \"Sandbox\": \"RETAIL\",\n \"PlayFabId\": \"5A446C83645201\",\n \"ForceLink\": false\n}"
response = http.request(request)
puts response.read_body{
"code": 123,
"status": "<string>",
"data": {}
}{
"code": 123,
"errorCode": 123,
"status": "<string>",
"error": "<string>",
"errorMessage": "<string>",
"errorDetails": {}
}