Permissions & Scopes
Effective Date: September 28, 2026
This page lists every permission Blazium Games asks for, why we need it, and what we will never do with it. It sits alongside our Privacy Policy, Subprocessors, and the API disclosures for GitHub, X, and Discord.
Linked accounts and sign-in
You can link GitHub, X, and Discord from Linked accounts and then use any of them to log in.
- Only a linked account can log in. We never match a GitHub, X, or Discord account to yours by email, and signing in never links an account for you.
- Once you unlink an account, it can no longer be used to log in.
- If your account has no password, you must keep at least one account linked.
- Linking does not create a Blazium Games account. Create one with email first.
- After a linked account proves who you are, we still email you a sign-in code unless you have already verified that browser.
- If your account is already set up, signing in never sends you to account setup and never pre-fills anything from GitHub, X, or Discord.
GitHub
Scopes requested: read:user and user:email.
Why we need it
- To link GitHub to your account and let you log in with it.
- We read your GitHub user ID, login, and your primary verified email address. GitHub must report a verified email or sign-in and linking stop; we do not store the email or use it to find your account.
What we store
- Your GitHub user ID and login, so we can recognize the linked account and show which one is linked.
- The GitHub access token is used once during sign-in or linking and is never stored.
We will never
- Write to your repositories, issues, or any other GitHub data.
- Act on GitHub on your behalf.
- Ask for more scopes without updating this page first.
Details: GitHub API disclosure.
X
Scopes requested: users.read and tweet.read. X requires tweet.read alongside users.read to read your profile; we do not read your posts.
Why we need it
- To link X to your account and let you log in with it.
- We make one request to X's
/2/users/meand read your X user ID and username. X also returns your display name, which we ignore.
What we store
- Your X user ID and username. Nothing else.
- The X access token is used once during sign-in or linking and is never stored. We do not request offline access, so we get no refresh token.
We will never
- Post, like, repost, follow, or send messages on X for you.
- Read your posts, timeline, or direct messages.
- Ask for more scopes without updating this page first.
Details: X API disclosure.
Discord
Scopes requested: identify and email.
Why we need it
- To link Discord to your account and let you log in with it.
- We make one request to Discord's
/users/@meand read your Discord user ID and username.
What we store
- Your Discord user ID and username. Nothing else.
- Discord includes your email address, display name, and avatar in its reply. We ignore them: we do not store your Discord email or use it to find your account.
- The Discord access token is used once during sign-in or linking and is never stored.
We will never
- Join servers, read your servers or messages, or send messages for you.
- Ask for more scopes without updating this page first.
Details: Discord API disclosure.
MCP access (OAuth)
AI tools such as Cursor, VS Code, and Claude Code connect to one of two Blazium Games MCP servers. The developer server at https://mcp.blazium.games/mcp manages your games. The player server at https://mcp.blazium.games/player acts for you as a player.
When you approve a tool, it gets a token for one server only, with one or more of that server's scopes. A token never holds scopes for both servers, and neither server accepts the other's tokens or keys.
| Scope | Server | Allows |
|---|---|---|
mcp:read |
Developer | Reading your games, builds, analytics, crash reports, setup details, balance, and library. |
mcp:write |
Developer | Creating and updating game pages, setting prices, issuing deploy keys, and (until October 28, 2026) buying from your balance within the limits you set, in addition to everything mcp:read allows. |
mcp:catalog.write |
Developer | Changing game pages (text, taxonomy, similar titles, dependencies, engine compatibility, license kind, images, admins) and replying to player reviews. Reads of your profile and games are always included. |
mcp:build.write |
Developer | Managing builds and release channels, and reading deploy info and scan status. |
mcp:crash.read |
Developer | Reading crash reports, crash groups, and player bug tickets, and running crash analysis. |
mcp:analytics.read |
Developer | Reading visitor analytics and custom events. |
mcp:keys.manage |
Developer | Listing and rotating deploy keys and MCP keys. |
mcp:money |
Developer | Pricing, sales, game keys and gift links, wallet, library, and downloads. |
player:read |
Player | Reading your account, balance, wallet history, quotes, library, approvals, download links, the builds you can see, your reviews, recommendations, and your friends and what they're playing. |
player:write |
Player | Verifying your email, recording play time, confirming an approval with the code you give the tool, joining or leaving a game's beta, writing or deleting your reviews, "more/less like this" feedback, filing bug reports, sending and answering friend requests, setting your presence and activity sharing, and redeeming game keys. |
player:buy |
Player | Topping up and buying games or donating from your balance within the limits you set. Granted only if you tick Allow purchases. |
Why we need it
- So your AI tool can manage your store pages and read your game's data without you pasting passwords.
How it is limited
- The consent screen has a Read-only access option. Tick it and the tool only gets
mcp:read(orplayer:read); any attempt to change data is refused. - On the developer server you can pick a narrower preset on the consent screen (store page, CI, crash triage, keys, money, or read-only), so the tool only gets the scopes that job needs.
- On the player server the tool can't buy unless you tick Allow purchases.
- Over MCP, rotating or creating MCP and deploy keys, deleting a deploy key, promoting a build to stable, deleting a game or build, creating more than 100 game keys at once, and adding a project admin wait until you approve them by the emailed link or code, even with full access.
- A token is either for your whole account or for a single game (project). A project token is refused (error 4030) for any other game and for account-level actions: your profile, balance, wallet, library, account analytics, MCP keys, creating games, and buying.
- Access tokens last 1 hour. Refresh tokens last 30 days from when you approved the tool. Each refresh issues a new refresh token and the old one stops working; if an old one is used again, the whole chain is revoked and the tool has to ask you again. All of them stop working if your account is deleted.
- Every request made with an MCP key or token is recorded in an audit log (key, game, method, and path).
We will never
- Accept a read-only token for a change.
- Share your keys or tokens with third parties.
Agent spending
AI tools connected through MCP can buy games and send donations for you, but only if you allow it.
How it is limited
- Every agent starts on Ask me each time: each purchase or donation waits until you approve it by the emailed link or code. Each MCP API key and each OAuth-connected app is a separate agent with its own setting.
- At MCP settings you can let an agent spend on its own: unlimited, or up to a monthly, yearly, or one-time limit (up to $1,000, UTC periods). Anything beyond the limit waits for your approval. Agents cannot change their own limits.
- An approval covers one purchase, for the amount shown, and expires after 30 minutes.
- The limit counts each purchase's total, including tax. Refunded purchases stop counting.
- Buying needs a player token with
player:buy, or until October 28, 2026 a developer token withmcp:writefor your whole account. Read-only and single-game (project) tokens can never buy (error 4030). - From October 28, 2026 the developer server no longer buys: its buying tools are removed and direct requests get error 4034. Use the player server instead.
- Agents pay only from your account balance, never by card. They cannot cash out, set up payouts, or request refunds.
- Your email must be verified before agents can buy.
- Each agent purchase is recorded with the agent that made it, and shows in your wallet transactions and library.
We will never
- Let an agent charge your card.
- Let an agent spend beyond the limit you set without your approval.
Keys
- MCP keys (account keys and project keys) are shown once when you create them and are stored only as a hash. You can rotate them at /settings/mcp or on a game's MCP tab; rotating invalidates the previous key.
- Player keys (starting
bgames_play_) work only on the player server. They are shown once, stored only as a hash, and rotated at /settings/mcp separately from MCP keys. - Deploy keys let the chauffeur CLI or CI upload builds and debug symbols for one game. Issuing a new deploy key invalidates the previous one.
Cookies
Sign-in cookies are always on because the site does not work without them. They are HTTPS-only, hidden from page scripts, and SameSite=Lax, so other sites can't make signed-in requests with them. Analytics cookies are only set if you accept them in the cookie banner.
| Cookie | Purpose | Lifetime | Needs consent |
|---|---|---|---|
BG_T |
Your signed-in session. | 7 days | No |
BG_UD |
Your display name, username, and avatar for the header. | 7 days | No |
BG_DEV |
Remembers a browser that verified an emailed sign-in code. Survives logout. | 30 days | No |
BG_NEXT |
Returns you to the page you came from after logging in with GitHub, X, or Discord. | 15 minutes | No |
BG_SETUP |
Finishes setup for an account that never completed it, after logging in with a linked account. | 15 minutes | No |
BG_CONSENT |
Remembers your cookie banner choice. | 1 year | No |
_ga, _ga_* |
Google Analytics. | Up to 2 years (set by Google) | Yes |
Game pages also keep a visit session ID in your browser's session storage. It is cleared when you close the tab.
You can change your choice at any time with Cookie settings in the site footer. Declining removes the Google Analytics cookies.
Revoking access
- Linked accounts: unlink GitHub, X, or Discord at /settings/connections. An unlinked account can no longer log in. If you have no password, the last linked account cannot be removed until you set one or link another.
- Removing Blazium Games in the other service's settings does not unlink it here. Unlink it at /settings/connections to stop it logging in.
- GitHub: remove Blazium Games under GitHub > Settings > Applications > Authorized OAuth Apps.
- X: remove Blazium Games under X > Settings > Security and account access > Apps and sessions.
- Discord: remove Blazium Games under Discord User Settings > Authorized Apps.
- Agent spending: set any agent back to Ask me each time at MCP settings.
- MCP keys and tokens: rotate keys at /settings/mcp. OAuth access tokens expire after 1 hour and refresh tokens after 30 days; all of them stop working when your account is deleted.
- Everything: email [email protected] to delete your account. See the Privacy Policy.