Blazium Games logoBlazium Games

Permissions & Scopes

Effective Date: September 28, 2026

This page lists every permission Blazium Games asks for, why we need it, and what we will never do with it. It sits alongside our Privacy Policy, Subprocessors, and the API disclosures for GitHub, X, and Discord.

Linked accounts and sign-in

You can link GitHub, X, and Discord from Linked accounts and then use any of them to log in.

GitHub

Scopes requested: read:user and user:email.

Why we need it

What we store

We will never

Details: GitHub API disclosure.

X

Scopes requested: users.read and tweet.read. X requires tweet.read alongside users.read to read your profile; we do not read your posts.

Why we need it

What we store

We will never

Details: X API disclosure.

Discord

Scopes requested: identify and email.

Why we need it

What we store

We will never

Details: Discord API disclosure.

MCP access (OAuth)

AI tools such as Cursor, VS Code, and Claude Code connect to one of two Blazium Games MCP servers. The developer server at https://mcp.blazium.games/mcp manages your games. The player server at https://mcp.blazium.games/player acts for you as a player. When you approve a tool, it gets a token for one server only, with one or more of that server's scopes. A token never holds scopes for both servers, and neither server accepts the other's tokens or keys.

Scope Server Allows
mcp:read Developer Reading your games, builds, analytics, crash reports, setup details, balance, and library.
mcp:write Developer Creating and updating game pages, setting prices, issuing deploy keys, and (until October 28, 2026) buying from your balance within the limits you set, in addition to everything mcp:read allows.
mcp:catalog.write Developer Changing game pages (text, taxonomy, similar titles, dependencies, engine compatibility, license kind, images, admins) and replying to player reviews. Reads of your profile and games are always included.
mcp:build.write Developer Managing builds and release channels, and reading deploy info and scan status.
mcp:crash.read Developer Reading crash reports, crash groups, and player bug tickets, and running crash analysis.
mcp:analytics.read Developer Reading visitor analytics and custom events.
mcp:keys.manage Developer Listing and rotating deploy keys and MCP keys.
mcp:money Developer Pricing, sales, game keys and gift links, wallet, library, and downloads.
player:read Player Reading your account, balance, wallet history, quotes, library, approvals, download links, the builds you can see, your reviews, recommendations, and your friends and what they're playing.
player:write Player Verifying your email, recording play time, confirming an approval with the code you give the tool, joining or leaving a game's beta, writing or deleting your reviews, "more/less like this" feedback, filing bug reports, sending and answering friend requests, setting your presence and activity sharing, and redeeming game keys.
player:buy Player Topping up and buying games or donating from your balance within the limits you set. Granted only if you tick Allow purchases.

Why we need it

How it is limited

We will never

Agent spending

AI tools connected through MCP can buy games and send donations for you, but only if you allow it.

How it is limited

We will never

Keys

Cookies

Sign-in cookies are always on because the site does not work without them. They are HTTPS-only, hidden from page scripts, and SameSite=Lax, so other sites can't make signed-in requests with them. Analytics cookies are only set if you accept them in the cookie banner.

Cookie Purpose Lifetime Needs consent
BG_T Your signed-in session. 7 days No
BG_UD Your display name, username, and avatar for the header. 7 days No
BG_DEV Remembers a browser that verified an emailed sign-in code. Survives logout. 30 days No
BG_NEXT Returns you to the page you came from after logging in with GitHub, X, or Discord. 15 minutes No
BG_SETUP Finishes setup for an account that never completed it, after logging in with a linked account. 15 minutes No
BG_CONSENT Remembers your cookie banner choice. 1 year No
_ga, _ga_* Google Analytics. Up to 2 years (set by Google) Yes

Game pages also keep a visit session ID in your browser's session storage. It is cleared when you close the tab.

You can change your choice at any time with Cookie settings in the site footer. Declining removes the Google Analytics cookies.

Revoking access