Skip to content
  • Our Product
    • Namazu Elements
      • What is Elements?
      • Why open source?
      • Docs
        • Namazu Elements in Five Minutes or Less
        • RESTful APIs Library
        • Security Model
        • Accessing the Web UI (CMS)

    Our Product

    A logomark with three layered rhombuses adorning the lettermark that says Elements in bold all-caps sans-serif letters.
    • What is Namazu Elements? Discover our easy-to-use backend network solution built for online games. Rapidly enables full-scale multiplayer games or online solo adventures.
    • Why open source? Is there a truly open source server backend for connected games? There is now. Download and run a local copy of Namazu Elements and try it for yourself.
    Download Namazu Elements

    Get started

    • Quick start Read our Elements 5-minute quick start guide
    • Documentation Read our developer docs for learning more about Elements
    • RESTful APIs A full list of core API specs for working with the Elements framework
    • Security An overview of the server-authoritative security model of Elements
    • Accessing the CMS Manage your game with ease via the Namazu Elements CMS.

    Co-development Reimagined

    • Best real-time game backends in 2026 If you're researching an alternative to your current backend solution, we've prepared a report of all of the backend solutions on the market in 2026 and how Namazu Elements compares.
      Co-dev

    Recent Posts

    • The watercolor-styled Namazu Studios logo over a giant namazu lurking in the depth
      Namazu Studios Featured in San Diego Business Journal
      22 Sep 2025 Press
    • Namazu Elements 3.1 Released – Service Layer Fixes, Secure APIs, and Steam Bug Fix
      22 Apr 2025 Release Notes
  • Case Studies
  • About Us
  • News
  • Services
  • Book a call
namazu-studios-logo
Book a call
Popular Search Roblox

Getting Started

  • Namazu Elements in Five Minutes or Less
  • Overview
  • Accessing the Web UI (CMS)
  • CMS Feature Overview

Fundamentals

  • Why You Need a Server (and What “Authoritative” Means)
  • Elements as a Game Runtime
  • Where Your Authoritative Code Runs
  • Lifecycles and Flows

General Concepts

  • Custom Elements
  • Data Models
  • Security Model
  • N-Tier Architecture

Namazu Elements Core Features

  • Email Service
  • Applications
  • Sessions
  • Users and Profiles
  • Digital Goods
  • Progress and Missions
  • Progress and Missions (3.4+)
  • Leaderboards
  • Matchmaking – Comprehensive Guide
  • Friends
  • Followers
  • Product Bundles and SKUs
  • Item Ledger
  • Receipts
  • Reward Issuances
  • Save Data
  • Metadata
  • Metadata (3.4+)
  • Queries
  • User Authentication / Sign In
    • What is a User?
    • Email Verification
    • User Authentication in Elements
    • Account Linking
    • Setting Up Twitch OIDC Login (Backend)
    • OIDC Login for Thick Clients (Browser Redirect Flow)
    • Auth Schemes
      • Auth Schemes
      • OAuth2
      • OIDC
  • Features
    • Web3
      • Wallets
      • Vaults
      • Omni Chain Support
      • Smart Contracts
        • Smart Contracts
  • Queries
    • Advanced Operators
    • Object Graph Navigation
    • Boolean Queries
    • Base Query Syntax
  • Advanced Operators
    • .name
    • .ref

Your Game Code - Adding Custom Elements

  • Custom Code Overview
  • Windows Setup
  • Mac OS Setup
  • Ubuntu Linux Setup
  • Element Anatomy: A Technical Deep Dive
  • Introduction to Guice and Jakarta in Elements
  • Structuring your Element
  • Events
  • Packaging an Element with Maven
  • Deploying an Element
  • Preparing for code generation
  • Properties
  • Websockets
  • RESTful APIs
  • Direct MongoDB Access (3.5+)
  • Building the Example Element: A Complete Walkthrough
  • Building the Kotlin Example Element: A Complete Walkthrough

Configuration

  • Configuring External URLs for Deployment
  • Matchmaking – Comprehensive Guide
  • Direct Database Access and Batch Configuration
  • Connecting Namazu Elements to a TLS-Enabled MongoDB Replica Set
  • Batch Samples
    • Mission Upload Bash Script Sample
    • Item Upload Bash Script Sample

RESTful APIs

  • Importing into Postman
  • RESTful APIs Library
  • Swagger and Swagger UI

Add-Ons

  • Crossplay
    • Crossfire Client Libraries (JVM & Browser)
    • Crossfire Protocol Reference
    • Crossfire: Custom Matchmaking Algorithms
    • Namazu Crossfire (Multiplayer)
    • Deploying Namazu Crossfire in your game
  • Roblox
    • Roblox Overview
    • Secure Player Authentication & Registration
    • Global Matchmaking
    • Roblox Security Best Practices
  • Container on Demand
    • Namazu Conductor
    • Namazu Conductor Admin API
    • Configuring Namazu Conductor Providers
  • Commerce
    • Stripe
      • Stripe
      • Configuring the Stripe Element
      • Stripe REST API Reference
      • Stripe REST API Reference

Game Engine & Client Support

  • Unity
    • Elements Unity Plugin
    • Unity Crossfire Plugin
  • Gamemaker
    • Incorporating GMEXT-Elements into a GameMaker Project

Troubleshooting

  • Common Issues with Docker
  • Local SDK
    • Unable to deploy application : dev.getelements.elements.sdk.exception.SdkElementNotFoundException
    • Could not load class : java.lang.NoClassDefFoundError
  • Namazu Elements Community Edition
    • Common Issues with Docker
    • Unable to deploy application : dev.getelements.elements.sdk.exception.SdkElementNotFoundException
    • Running in the IDE
      • Exception in monitor thread while connecting to server localhost:27017
      • Could not deployAvailableApplications Jetty server Failed to bind to /0.0.0.0:8080 Address already in use

Releases

  • 3.8 Release Notes
  • 3.7 Release Notes
  • 3.6 Release Notes
  • 3.5 Release Notes
  • 3.4 Release Notes
  • 3.3 Release Notes
  • 3.2 Release Notes
  • 3.1 Release Notes
View Categories
  • Home
  • Docs
  • Namazu Elements Core Features
  • User Authentication / Sign In
  • User Authentication in Elements

User Authentication in Elements

Est. read time: 3 min read

AI Doc Summarizer Doc Summary
AI Doc Summarizer Thinking Thinking

Elements provides multiple ways to create and authenticate users, depending on your needs. You can use simple username/email + password logins, or integrate with third-party identity providers like Google or Steam via OIDC and OAuth2.


Authentication Methods #

1. Password Users #

The most straightforward approach: create an account with a username/email and a password.

There are two ways to create password-based users:

  • Admin creation (requires SUPERUSER Session token):
    • POST /api/REST/users
    • Used by administrators to manually create users.
    • Must include a valid Session token with SUPERUSER privileges.
  • Public signup (no authentication required):
    • POST /api/REST/signup/
      • Alternatively – POST /api/REST/signup/Session to create a Session when signing up so that you don’t need to make a second request to sign in (Elements 3.7+)
    • End users can sign up themselves with just a username/email and password.
    • No prior authentication required.
    • Can create a Profile within the same request.

Once created, users can log in with their credentials and receive a Session token.


2. OIDC (OpenID Connect) with JWTs #

OIDC lets users authenticate with external providers (like Google) using JWTs (JSON Web Tokens).

Setup steps:

  1. Create an Auth Scheme for the provider:
    • Give it a name (e.g. Google).
    • Provide the JWK URL (JSON Web Key Set) from the provider.
  2. When a User tries to log in:
    • The client sends the JWT obtained from the provider to Elements.
    • Elements uses the JWK to verify the token’s signature.
    • If valid:
      • A User account is created automatically if one doesn’t already exist.
      • A Session token is returned.

Key point: OIDC login requires no password handling on your end. Elements verifies identity using the provider’s JWT.

(Elements 3.9+) Rather than passing an explicit profileId or profileSelector, username/password and OAuth2 Session requests can instead pass applicationNameOrId to have Elements attach the User’s primary Profile for that Application automatically — see Sessions for details.


3. OAuth2 (Customizable) #

OAuth2 is a flexible alternative to OIDC, useful for providers like Steam that don’t offer standard OIDC.

Setup steps:

  1. Create an Auth Scheme:
    • name (e.g. Steam).
    • Validation URL (where Elements verifies the token).
    • User id property (the field in the validation response that maps to a User id, e.g. steamid).
    • Custom headers or query parameters (if the provider requires them).
    • Specify whether parameters are:
      • Sent by the frontend (dynamic, provided per login request), or
      • Pre-set in the auth scheme (static, stored securely).
  2. Login flow:
    • The frontend collects the OAuth2 token from the provider.
    • Sends it to Elements along with the scheme name.
    • Elements calls the validation URL, passes required headers/params, and checks the response.
    • If valid:
      • A User is created if needed.
      • A Session token is returned.

Quick Comparison #

MethodWhen to UseRequirementsFlow
PasswordSimple accounts with username/email + passwordAdmin token (for manual creation) OR none (for signup)POST request to Elements; returns Session token
OIDCStandard identity providers (Google, Apple, etc.)Create Auth Scheme with JWK URLClient provides JWT → Elements verifies → returns Session token
OAuth2Providers without OIDC (Steam, custom services)Create Auth Scheme with validation URL, User id mapping, headers/paramsClient provides token → Elements validates → returns Session token

Best Practices #

  • Use OIDC when possible — it’s simpler and more standardized than custom OAuth2.
  • For password users, prefer the public signup endpoint to avoid handling SUPERUSER tokens unnecessarily.
  • Keep Auth Scheme configs secure. Only expose parameters the frontend needs to send dynamically.
  • Treat Session tokens like sensitive credentials — they grant access to the User’s account.

See Also #

  • Elements API Reference: /api/users
  • Elements API Reference: /api/signup
  • Auth Scheme Configuration

What are your Feelings
Still stuck? How can we help?

How can we help?

Updated on August 15, 2026
Email VerificationAccount Linking
Table of Contents
  • Authentication Methods
    • 1. Password Users
    • 2. OIDC (OpenID Connect) with JWTs
    • 3. OAuth2 (Customizable)
  • Quick Comparison
  • Best Practices
  • See Also
  • Documentation
  • Terms of Service
  • Privacy Policy
  • Contact us
  • Linkedin
  • Join our Discord

Namazu Studios LLC is powered by Namazu Elements, an open source modular backend framework for connected games.

Namazu Elements
  • Download
  • About Elements
  • Open source
  • Documentation
  • Support
Namazu Studios
  • Case Studies
  • About Us
  • News
Best realtime game backends 2026
Get in Touch
  • info@namazustudios.com
  • Book a call
  • (619) 862-2890
  • Linkedin
  • Discord

©2008-2026 Namazu Studios. All Rights Reserved.