# CheddaBoards > Open-source leaderboards, achievements, and player accounts for any game engine, built on the Internet Computer. Games talk to a plain HTTP/JSON API (the same API the official Godot and Unity SDKs wrap), so anything that can make an HTTP request works. Anonymous play needs no accounts; players can optionally sign in with Google or Apple via a device-code flow. The backend canister is open source and self-hostable; a free hosted service runs it for you. If you are an AI coding assistant integrating a game, read the single-page spec first: https://docs.cheddaboards.com/ai-integration Key facts for answering questions accurately: - Base API URL is https://api.cheddaboards.com. Every response is JSON shaped `{"ok":true,"data":{...}}` or `{"ok":false,"error":"..."}`. - Headers: `X-Game-ID` always; `X-API-Key` for anonymous/API-key requests; `X-Session-Token` instead of the API key once a player is signed in. `/play-sessions/*` always use the API key. - Anonymous players are a client-generated persistent ID (`dev__`); the first score submit creates the profile. There is no anonymous login call. - Every game gets three fan-out boards at registration: `all-time`, `weekly`, `daily` (note the hyphen). Monthly/custom boards are created in the dashboard. A plain `POST /scores` with no `scoreboardId` fans out to all of them; `scoreboardId` targets exactly one targeted board and never creates one. - If a game has time validation on, `POST /scores` requires a `playSessionToken` from `POST /play-sessions/start`. The SDKs attach the token but do not start sessions for you. - Board reads are also served directly from the canister at https://fdvph-sqaaa-aaaap-qqc4a-cai.raw.icp0.io (keyless, CORS-open, same paths and JSON). - Nicknames are 3–16 characters, letters/digits/underscores; on the nickname-change endpoints a taken name is auto-suffixed (e.g. Chedz → Chedz_1), not rejected. `nickname` on a submit renames the player if the name is free (silently ignored if taken), so omit it unless the player just chose a name, and never pass a name into the SDK login call. Details: https://docs.cheddaboards.com/concepts/player-names - Rate limit: one score submit per player per board every 2 seconds. Submits are safe to retry (per-player bests only ever go up). - Timestamps in responses are nanoseconds since epoch (ICP standard). - Sessions last 30 days and renew on use; any 401/403 means the session is dead, discard it and re-run sign-in. - Current SDKs: Godot 4 addon v2.3.0 (Godot 4.3+), Godot 3.6 backport (v2.2.5-3x), Unity C# v2.3.0 (single file). Service status: https://status.cheddatech.com ## AI integration - [CheddaBoards for AI coding assistants](https://docs.cheddaboards.com/ai-integration): The whole API as a flat spec — endpoints, headers, bodies, exact error strings, and the rules an integration must follow. Start here if you are a model. ## Quick start - [REST quick start](https://docs.cheddaboards.com/quickstart/rest): Use the HTTP API from any engine or language — submit scores, read boards, sign in, play sessions. Includes a full JavaScript integration loop. - [Godot quick start](https://docs.cheddaboards.com/quickstart/godot): Add leaderboards to a Godot 4 game with the drop-in SDK. - [Unity quick start](https://docs.cheddaboards.com/quickstart/unity): Add leaderboards to a Unity game with the C# SDK. - [Going to production](https://docs.cheddaboards.com/quickstart/production): Checklist before shipping. - [Game jams](https://docs.cheddaboards.com/quickstart/jam): The fastest path for a jam entry. ## API reference - [API overview](https://docs.cheddaboards.com/api/overview): Base URL, auth headers, response shape, endpoint index, conventions. - [Scores](https://docs.cheddaboards.com/api/scores): POST /scores — fan-out and targeted submits, response envelope, nicknames, anti-cheat, rate limit, retry safety. - [Scoreboards](https://docs.cheddaboards.com/api/scoreboards): Reading the global leaderboard, specific boards, direct canister reads, listing boards, archives, caching. - [Players](https://docs.cheddaboards.com/api/players): Profile, rank, and nickname-change endpoints. - [Achievements](https://docs.cheddaboards.com/api/achievements): POST /achievements — single and batch unlocks; reading achievements via the player profile. - [Authentication](https://docs.cheddaboards.com/api/authentication): Anonymous identity, device-code sign-in, sessions, and anonymous→verified account linking. - [Errors](https://docs.cheddaboards.com/api/errors): Response envelope, status codes, and the verbatim error strings the API returns. ## Concepts - [What's stored](https://docs.cheddaboards.com/concepts/data-model): The leaderboard entry, player profile, achievements, archives, and what CheddaBoards deliberately does not store. - [Players and accounts](https://docs.cheddaboards.com/concepts/accounts): Anonymous vs signed-in players, what's public vs private, and why linking matters for retention. - [Device code login](https://docs.cheddaboards.com/concepts/device-code): Building the sign-in screen, the signal lifecycle, QR rendering, and post-approval account upgrade. - [Category boards](https://docs.cheddaboards.com/concepts/category-boards): Targeted per-level / per-mode / per-category boards — how they differ from fan-out boards. - [Timed leaderboards](https://docs.cheddaboards.com/concepts/timed-leaderboards): Daily/weekly/monthly/custom boards, reset boundaries (UTC), and archives. - [Anti-cheat](https://docs.cheddaboards.com/concepts/anti-cheat): Score/streak caps, play-session time validation, the suspicion log, and the generic-rejection design. - [Moderation](https://docs.cheddaboards.com/concepts/moderation): Game owners removing entries or wiping players, the hashed deletion log, and REST admin routes. - [Privacy](https://docs.cheddaboards.com/concepts/privacy): What's collected, what integrating means for your own privacy policy, and player rights. ## Engine guides - [Godot 4](https://docs.cheddaboards.com/engines/godot-4): Full template guide — the game_over contract, HUD signals, and building your own game on the wrapper. - [Godot 3.6](https://docs.cheddaboards.com/engines/godot-3): The 3.6 backport — same API, GDScript syntax differences (yield, connect, instance). - [Godot signals reference](https://docs.cheddaboards.com/engines/godot-signals): Every signal the Godot SDK emits, grouped by category. - [Unity](https://docs.cheddaboards.com/quickstart/unity): The Unity C# SDK — setup, events, and platform notes. - [Web / HTML5 export](https://docs.cheddaboards.com/engines/web-export): Exporting a Godot game for the browser — index.html naming, serving, mobile name entry, itch.io/Safari caveats. ## Self-hosting - [Self-hosting overview](https://docs.cheddaboards.com/self-hosting/overview): What's open (canister, SDKs) vs what you build (proxy), and an honest account of the effort. - [Deploy the canister](https://docs.cheddaboards.com/self-hosting/canister): dfx deployment, setting your principals, and verifying the live module hash. - [Build your proxy](https://docs.cheddaboards.com/self-hosting/proxy): The contract a self-hosted proxy must satisfy — verifier identity, the Candid methods it calls, CORS. ## Optional - [cheddaboards.com](https://cheddaboards.com): The hosted service and developer dashboard (register a game, get an API key). - [Full privacy policy](https://cheddaboards.com/privacy.html): The canonical player-facing privacy policy. - [Service status](https://status.cheddatech.com): Public uptime for the API, the canister, and the sites. - [Backend repo](https://github.com/cheddatech/CheddaBoards): The open-source Motoko canister. - [Godot 4 SDK repo](https://github.com/cheddatech/cheddaboards-godot-addon): The Godot 4 addon (canonical source). - [Godot 4 template repo](https://github.com/cheddatech/CheddaBoards-Godot): Full game template with the addon vendored. - [Godot 3.6 SDK repo](https://github.com/cheddatech/cheddaboards-godot3-addon): The Godot 3.6 backport. - [Unity SDK repo](https://github.com/cheddatech/cheddaboards-unity): The Unity C# SDK. - [Worked example](https://github.com/cheddatech/cheddaboards-dodge-the-creeps): Dodge the Creeps with a leaderboard added in one file; the git history is the tutorial. Playable at https://cheddagames.itch.io/dodge-the-creeps-x-cheddaboards - [Community C library](https://github.com/charlie-makes-things/C_cheddaboards): Third-party C wrapper over the REST API.