
已验证操作
由服务器检查的对局,适用于排行榜和游戏内货币,无需编写服务器代码。一次性对局票据、仅存于服务器的规则、高分对局的输入日志以及审核机制,限制了作弊者能获得的收益。仅限云端,不支持自托管的 simpleServer。
一次性对局票据
每局都以服务器票据开始,票据绑定玩家、排行榜和服务器种子。一张票据只计一次,被拒绝的对局同样会消耗它,因此没人能用一张票据试探你的限制。
规则只在服务器上
分数上下限、最短时长、每秒得分、关卡规则以及每局货币上限都保存在服务器上。它们从不出现在应用响应或错误信息中,货币也只由服务器写入。
输入日志与审核
对于高分对局和被标记的对局,服务器会向游戏索取输入日志。你可以用种子和日志亲自重放可疑对局,再决定如何处理。
快速集成
设置已验证操作
视频即将上线
为排行榜开启已验证提交,并在“已验证操作”中设置服务器规则。之后即可在控制台中跟踪已检查的游戏局,并审查高分游戏局的证据。
// Unity C#: Validated Actions
// Dashboard: turn on "Validated submissions only" for the leaderboard "weekly"
var va = ValidatedActionsManager.Instance;
// Round start: single-use ticket plus server seed
var run = await va.StartRun("weekly");
if (run == null) { Debug.Log(va.LastErrorCode); return; } // e.g. RUN_RATE_LIMITED
var random = new System.Random(run.seed);
// ... play, record the inputs into inputLog (byte[]) ...
// Round end: score plus input log (the SDK sends its SHA-256 hash)
var result = await va.SubmitValidated(18250, inputLog);
if (result == null)
{
Debug.Log($"{va.LastErrorCode}, run kept: {va.HasActiveRun}"); // e.g. DURATION_TOO_SHORT
}# REST API: Validated Actions (needs the player's session token)
# Start a run: returns runId, a single-use ticket, seed and expiresAt
curl -X POST https://eu.horizon.pm/api/v1/app/validated-actions/runs \
-H "X-API-Key: YOUR_API_KEY" \
-H "Authorization: Bearer SESSION_TOKEN" \
-H "Content-Type: application/json" \
-d '{"userId":"USER_ID","leaderboardKey":"weekly"}'
# Submit the run: score plus the SHA-256 hex of the input log
curl -X POST https://eu.horizon.pm/api/v1/app/validated-actions/submit \
-H "X-API-Key: YOUR_API_KEY" \
-H "Authorization: Bearer SESSION_TOKEN" \
-H "Content-Type: application/json" \
-d '{"userId":"USER_ID","ticket":"TICKET","leaderboardKey":"weekly","score":18250,"inputLogHash":"SHA256_HEX"}'
# Rejected runs answer 422 with a code, e.g. TICKET_EXPIRED or DURATION_TOO_SHORT

