# How can a Godot server verify the authenticity of a client connected to a Nakama server?

**URL:** <https://forum.heroiclabs.com/t/how-can-a-godot-server-verify-the-authenticity-of-a-client-connected-to-a-nakama-server/5911>\
**Category:** Client Libraries\
**Tags:** sdk-godot\
**Created:** [January 3, 2025, 4:58pm UTC](https://forum.heroiclabs.com/t/how-can-a-godot-server-verify-the-authenticity-of-a-client-connected-to-a-nakama-server/5911 "2025-01-03T16:58:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Serh](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@Serh](https://forum.heroiclabs.com/u/Serh)\
**Post date:** [January 3, 2025, 4:58pm UTC](https://forum.heroiclabs.com/t/how-can-a-godot-server-verify-the-authenticity-of-a-client-connected-to-a-nakama-server/5911/1 "2025-01-03T16:58:33Z")

</div>

There is a Godot server and clients from the same project code with Nakama Godot SDK. The Godot server and clients connect to the Nakama server (using any authentication method). The clients also connect to the Godot server. How can the Godot server ensure that the connecting client is not a fraud and corresponds to a specific Nakama client?  
Is it possible to identify a Nakama server client using the token on godot server?  
"Or maybe I am missing a simpler mechanism for creating an authoritative Godot server, but with some degree of client freedom regarding the Nakama server?

---

<div class="post-metadata">

**Author:** ![sesposito](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/sesposito/32/2594_2.png) [@sesposito](https://forum.heroiclabs.com/u/sesposito)\
**Post date:** [January 6, 2025, 4:58pm UTC](https://forum.heroiclabs.com/t/how-can-a-godot-server-verify-the-authenticity-of-a-client-connected-to-a-nakama-server/5911/2 "2025-01-06T16:58:35Z")

</div>

Hello @Serh,

The [socket.server\_key](https://heroiclabs.com/docs/nakama/getting-started/configuration/#properties.socket.server_key) does prevent clients not in possession of the key from connecting, this should give you some protection against unwanted actors trying to connect to the server.

---

<div class="post-metadata">

**Author:** ![Serh](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@Serh](https://forum.heroiclabs.com/u/Serh)\
**Post date:** [January 6, 2025, 8:46pm UTC](https://forum.heroiclabs.com/t/how-can-a-godot-server-verify-the-authenticity-of-a-client-connected-to-a-nakama-server/5911/3 "2025-01-06T20:46:26Z")

</div>

So far I have settled on the fact that the client authenticates on the nakama server and receives a session, and with it an access token and a refresh token, then it connects to the godot server and sends it an access token, the godot server creates a session (I did not find a validation function), then the godot server checks the client ID from the session for a match with the ID of the connecting client.

---

<div class="post-metadata">

**Author:** ![sesposito](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/sesposito/32/2594_2.png) [@sesposito](https://forum.heroiclabs.com/u/sesposito)\
**Post date:** [January 7, 2025, 12:05pm UTC](https://forum.heroiclabs.com/t/how-can-a-godot-server-verify-the-authenticity-of-a-client-connected-to-a-nakama-server/5911/4 "2025-01-07T12:05:43Z")

</div>

To validate the tokens you could create a [server-to-server](https://heroiclabs.com/docs/nakama/server-framework/runtime-examples/server-to-server/#server-to-server) RPC that uses the same logic as [here](https://github.com/heroiclabs/nakama/blob/v3.25.0/server/api.go#L434).

We’ve recently added a subset of the configuration values to be available to read from the runtimes to access the encryption key.

Best.

---

<div class="post-metadata">

**Author:** ![Serh](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@Serh](https://forum.heroiclabs.com/u/Serh)\
**Post date:** [January 7, 2025, 12:51pm UTC](https://forum.heroiclabs.com/t/how-can-a-godot-server-verify-the-authenticity-of-a-client-connected-to-a-nakama-server/5911/5 "2025-01-07T12:51:17Z")

</div>

thanks for the links, I need more experience to understand these concepts.

---

<div class="post-metadata">

**Author:** ![Serh](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@Serh](https://forum.heroiclabs.com/u/Serh)\
**Post date:** [January 8, 2025, 2:36pm UTC](https://forum.heroiclabs.com/t/how-can-a-godot-server-verify-the-authenticity-of-a-client-connected-to-a-nakama-server/5911/6 "2025-01-08T14:36:43Z")

</div>

If I understood correctly, then Godot server can be a client with ID 000000…00000? then how do I log in with this account? I tried to add an authentication method to this account in the nakama web interface. but this is prohibited by the system.

---

<div class="post-metadata">

**Author:** ![sesposito](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/sesposito/32/2594_2.png) [@sesposito](https://forum.heroiclabs.com/u/sesposito)\
**Post date:** [January 8, 2025, 2:52pm UTC](https://forum.heroiclabs.com/t/how-can-a-godot-server-verify-the-authenticity-of-a-client-connected-to-a-nakama-server/5911/7 "2025-01-08T14:52:53Z")

</div>

You can call S2S RPCs using just the runtime HTTP key, this means there’s no authentication step to get a session - these invocations won’t have a user\_id set in the context, because of it - you should populate whatever data you need in the payload (e.g.: the user\_id) as the Godot server is authoritatively calling Nakama on behalf of the user.

Hope this clarifies.
