Kongregate provides an ecosystem of services, available to all developers. We use a signed request mechanism for our API callbacks. This makes it easy to verify that a given callback request is indeed coming from Kongregate. When you receive a signed request from Kongregate you must decode and verify it before using the parameters inside.
You can see full details here.
Support
Quick Reference Guide - Where To Find What You're Looking For
SUBMISSION | How do I submit a game to Kongregate? It's Easy!
REGISTRATION | How to complete the Developer Application Form
SUBMISSION | Checklist before uploading a game
MONETIZATION | How do I add In-App Purchases to my game?
API | Where can I find more details about Kongregate APIs?
HOSTING | Notes on hosting your game securely
TIPS | Useful URLs and Resources
BADGES | How do I add Badges to my game?
PAYMENT | How and when are developers paid?
AGE RATING | Are there age restrictions for games submitted to Kongregate?
CONTENT | What content is allowed on Kongregate?
PROHIBITED | What content is prohibited on Kongregate?
SUPPORT | Where can developers find documentation and guidance?
Comments
1 comment
Signed callbacks are an important part of API security, especially when applications need to verify that incoming requests are legitimate. Clear documentation of the signing process, required parameters, example requests, and how developers should validate signatures would make this guide especially useful.
Please sign in to leave a comment.