Releases / v0.108.0

v0.108.0 Knows Who You Are

2026-10-01 Engine Latest

A game server can now be sure who a player is. A signed-in player's account arrives proven by fopull.com, so a ban list, an invite list or a leaderboard can trust the id it reads.

Verified players

net.identity(peer).verified used to be false for everyone: a server took a player's word for which account they were. Now a signed-in player joining a server first gets a join token from fopull.com that names that one server and lasts five minutes. The server checks it and reports the player as verified, with the account's id, name and plan as fopull.com has them.

  • Your sign-in never reaches the server. A join token proves who you are to the server you are joining and does nothing else: it cannot spend your Fobucks, read your account, or get you into a different server.
  • No call to fopull.com per join. A server fetches fopull.com's signing keys once when it starts hosting and checks every token itself, so a busy server never waits on fopull.com.
  • net.host{ requireVerified = true } admits only verified players. Anyone else is turned away with a reason their game can show. Without it, a player whose token could not be fetched still joins, unverified, exactly as before.
  • A direct host needs to know its address. A server on Floptle Cloud needs nothing: its lobby code is its address. A server players join with quic:// cannot learn its own public address, so tell it: net.host{ port = 30000, address = "play.example.com:30000" }.
  • A token works once, for the server it names, for five minutes, with two minutes of leeway for a server whose clock is off. The server's Console says why it refused any token.

The multiplayer guide's "Identity" section covers which address each kind of server answers to.

Lobby codes

A Floptle Cloud or self-hosted relay no longer reuses a closed lobby's code for ten minutes, so a player holding the old code can't land in a stranger's new lobby.

Upgrading

Verification needs both sides on this version: the player's game to fetch the token, and the server to check it. Until a server is updated, its players join unverified, as they do today. Re-export your game and redeploy its server.

Floptle Hub

Linux x86_64 9.0 MB Download → sha256 277b10f74a4f34bd0ad71f6e78e748aeeed8119920c97ee5f4d382eb51dc8c74
macOS Apple Silicon 5.9 MB Download → sha256 4e9b562c928d7c436a0aa118c1cfcfa04d65cfff402952847aeff4bc901242c3
macOS Intel 6.4 MB Download → sha256 76c48a9a9cb36d17c27477347f724cba5b3d984cc415ece0deb2cc0abbdf310c
Windows x86_64 7.3 MB Download → sha256 09f02575cbc0829e6ebe71c0d1666a4de7a845e6c521e3f2c5c12ac11b28fdb0

Engine

Linux x86_64 52.0 MB Download → sha256 0bd23388f81da3b481997956e47796927c197d4af48a64bcae4e78713cdf2ba4
macOS Apple Silicon 40.1 MB Download → sha256 e5ffcc882ed0569358fbd23b50456e16efc650b6a11a702e6255624aa5d685d4
macOS Intel 43.2 MB Download → sha256 b63cae5a6920c7451772205ae4df352f17c39b93104cec52cdbcc70be4a85281
web 4.8 MB Download → sha256 876e55a13f6e42f4c4466bc7d22cce2f136db5d6108cee729045aaaa2e02798d
Windows x86_64 48.9 MB Download → sha256 d2674402e83900bb236b3fea96badf8f92f933daeb677d1bfa626c90e90aaa5b

The binaries are not signed yet. On macOS, right-click the app and pick Open the first time. On Windows, if SmartScreen appears, pick More info then Run anyway.