Skip to content

PHP SDK ​

Server helpers in sdk/php/PlayFlow.php, package retentionplay/sdk 0.3.0. Use Composer classmap autoloading, or include the file explicitly as below. SDK_FILE points to the installed file. API keys and webhook secrets stay on your server. Package metadata is in the repository; registry publication is separate.

Issue a session token ​

php
<?php
require getenv('SDK_FILE');
$result = \PlayFlow\SessionTokens::issue([
    'api_base' => getenv('API_BASE'),
    'api_key' => getenv('SERVER_API_KEY'),
    'project_id' => getenv('PROJECT_ID'),
    'external_user_id' => getenv('EXTERNAL_USER_ID'),
]);
$token = $result['session_token'];
// Pass $token to your page renderer; do not log it.

The helper calls POST /v1/server/session-token using Bearer authorization and requires scope session:issue. HTTP errors throw; local session signing is unsupported. Compatibility and migration.

Verify a webhook ​

This receiver fragment needs your HTTP application's request environment.

php
<?php
require getenv('SDK_FILE');
$raw = file_get_contents('php://input');
$sig = $_SERVER['HTTP_X_RETENTIONPLAY_SIGNATURE']
    ?? $_SERVER['HTTP_X_PLAYFLOW_SIGNATURE'] ?? '';
$webhookSecret = getenv('PROJECT_WEBHOOK_SECRET');
if (!\PlayFlow\Webhook::verify($raw, $sig, $webhookSecret)) {
    http_response_code(400);
    exit('invalid signature');
}
$event = json_decode($raw, true, 512, JSON_THROW_ON_ERROR);
// Fulfil once, keyed by $event['idempotency_key'], then return 204.
http_response_code(204);

The project secret comes from admin reveal, not the platform JWT/master key. Verification accepts versioned and legacy signature headers, checks the default 300-second clock window and compares HMAC-SHA256 in constant time. Preserve the exact raw body. See webhooks.

Internal & integration documentation