# Authentication for matchmaker

> Use authentication in Matchmaker to securely identify and authorize players.

There are two ways to authenticate in Matchmaker:

* Player authentication
* Service Account authentication

## Player authentication

Player authentication uses [Unity Authentication](/authentication.md) to enable player-driven matchmaking so that a game client can contact the Matchmaker service to create a ticket.

Make sure to [initialize](/services/getting-started.md#initialize-unity-services-in-your-game-code) the Authentication service and sign in before making any calls using the Matchmaker SDK.

There are multiple ways to [sign in](https://services.docs.unity.com/docs/client-auth/index.html). The simplest method is to use [anonymous sign-in](/authentication/use-anon-sign-in.md).

### Multiplayer Services SDK implementation

In the Multiplayer Services SDK (`com.unity.services.multiplayer`), player authentication is a hard requirement, not an optional path. `MultiplayerInitializer` registers `IAccessToken` (from `Unity.Services.Authentication.Internal`) as a required dependency for the entire package, so the SDK can't initialize matchmaking without it.

Every client-facing matchmaking call `MatchmakeSessionAsync`, `CreateTicketAsync`, `GetTicketAsync`, `DeleteTicketAsync`, and `GetMatchmakingResultsAsync` internally calls a guard method (`EnsureSignedIn()` in `WrappedMatchmakerService`) that checks `IAccessToken.AccessToken`. If the player hasn't signed in through the Authentication service, the call throws:

```cs
MatchmakerServiceException(Unauthorized, "You are not signed in to the Authentication Service. Please sign in.")
```

In practice, this means calling `AuthenticationService.Instance.SignInAnonymouslyAsync()` (or another sign-in method) before any matchmaking call, as shown in the SDK's own examples.

## Service Account authentication

Use Service Account authentication when a backend service creates a matchmaking ticket on behalf of a game client. This is useful when it's required to add server authoritative data to a matchmaking ticket, like a skill value, for example.

To create a Service Account, follow these [instructions](https://services.docs.unity.com/docs/service-account-auth/index.html#step-1-creating-a-service-account).

To use the Service Account in Matchmaker, follow those [steps](https://services.docs.unity.com/docs/service-account-auth/index.html#extra-step-use-the-token-exchange-api).

Here's an example of a typical service-to-service authentication flow:

1. The client performs an anonymous authentication as described in Player authentication.
2. The client calls a custom backend server with the `PlayerId` as the parameter.
3. The custom backend calls the ticket creation route with the `impersonate-user-id` header set to the `PlayerId` value:
   ```curl
   curl --location --request POST 'https://matchmaker.services.api.unity.com/v2/tickets' \
   --header 'Content-Type: application/json' \
   --header 'Authorization: {{SERVICE-ACCOUNT-TOKEN}}' \
   --header 'impersonated-user-id: {{PLAYER-ID}}' \
   --data-raw '{ "players": [ { "id": "{{PLAYER-ID}}","customData": { "Skill": {{ENRICHED-DATA}} } } ] }'
   ```
4. The custom backend sends the ticket ID back to the client.
5. The client polls the ticket status using the client SDK.

## Additional resources

* [ISession interface](https://docs.unity3d.com/Packages/com.unity.services.multiplayer@latest/index.html?subfolder=/api/Unity.Services.Multiplayer.ISession.html)
* [MatchmakerOptions](https://docs.unity3d.com/Packages/com.unity.services.multiplayer@latest/index.html?subfolder=/api/Unity.Services.Multiplayer.MatchmakerOptions.html)
