Hosted pages
A member’s credentials and personal details are only ever entered on STX pages. Your app sends the member to STX with an authorize request; STX signs them in, asks for consent, and sends them back to your redirect_uri. None of these pages can be framed.
Sign-in and sign-up
Section titled “Sign-in and sign-up”A member who is not signed in is sent to the STX login, with a line naming your app, and returned to the authorize request when they sign in. Two-factor, when the member has it, is part of that login.
A person without an STX account signs up on /player/register. Sign-up ends by asking them to verify their email and log in. When they log in in the same browser session, STX returns them to the pending authorize request and on to consent. In a different browser the pending request is lost; start the authorize request again.
Consent
Section titled “Consent”/connect/authorize is the consent screen the member reaches from /oauth/authorize. It shows your app’s name and logo, the line “If you allow this, App will be able to:”, one plain-language line per scope, then Allow and Deny. The member approves or denies the list as a whole.
- Allow issues the authorization code and redirects to your
redirect_uriwithcodeandstate. - Deny redirects with
error=access_deniedandstate. - A member whose identity verification is still pending may still allow; the screen notes that some actions, such as placing orders, stay unavailable until verification completes.
A returning member whose grant already covers the request skips this screen; see silent re-authorization.
Connected apps
Section titled “Connected apps”Every app a member has connected appears on Connected apps in their STX account, with your name and logo, the scopes they granted, when, and when your app last used it. From there they can revoke your app, which revokes the grant and every token under it at once: your next call for that member returns 401. Design for this; a member may disconnect at any time.
Money stays with the member
Section titled “Money stays with the member”No scope moves money, and no hosted step lets your app initiate a deposit or withdrawal. A member funds their account themselves on STX.

