> For the complete documentation index, see [llms.txt](https://docs.thndr.io/integration/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.thndr.io/integration/launch-game/custom/authenticate-users.md).

# Authenticate Users

## Generating an Authentication Token

To allow your users to authenticate with our web app through the THNDR SDK, you need to generate an **authentication token**. This token should be created when the user initiates an action to open the THNDR game (e.g., a button click).

<figure><img src="/files/acJkVjcG837rcLYzEWkq" alt=""><figcaption></figcaption></figure>

## **Steps to Generate the Authentication Token:**

1. **Server-Side Service**: The authentication token must be generated server-side to securely handle the **API key** that we provide. **Do not expose the API key** on the client-side to avoid security risks.
2. **Calling the Authentication Endpoint**: Your server should make a `POST` request to the following endpoint, including the user's metadata:

   ```url
   POST https://api-sandbox.clinch.gg/v0/wager/operator/create-token
   ```

   **Request Body**:

   ```json
   {
     "userId": "<userId>",
     "displayName": "<userName>",
     "currency": "<OPTIONAL_USER_CURRENCY>",
     "subOperatorId": "<OPTIONAL_SUB_OPERATOR_ID>"
   }
   ```

   * `userId`: The unique ID of your user.
   * `displayName`: The display name of the user.
   * `currency` - Player's wallet currency (read more in [Currencies](/integration/server-webhooks/currencies.md)).
   * `subOperatorId` - Identifies a specific sub-operator under a main operator, enabling separate tracking and reporting across multiple game portals

   **Request Header:**

   ```
   x-operator-id: your_operator_id
   x-api-key: your_api_key
   ```
3. **Response**: Upon successful authentication, the endpoint will return a token in the response:

   **Response Example**:

   ```json
   {
     "status": 200,
     "data": {
       "token": "eyJhbGciOiJSUzI1NiIsInR5cC..."
     }
   }
   ```
4. **Using the Token in the `getToken` Callback**: Once you receive the token in the server response, return this token in the `getToken` callback of the THNDR SDK. Here's an example:

   ```javascript
   async function getToken() {
     const response = await post('https://your-server.com/thndr/login');
     const data = await response.json();
     return data.token;
   }
   ```

## Token Expiry

Authentication tokens used during SDK initialization are JWTs that expire after 1 hour. If an expired token is passed when opening the game, it will fail to load. To prevent this, it's recommend to generate a fresh token each time the game initializes.&#x20;

Alternatively, you can decode the token (e.g., using [jwt.io](http://jwt.io/)) to inspect the `exp` field and only regenerate when it's close to expiration. However, generating a new token on each game load is the simpler and more robust approach.
