Pre-release · v0.37.0 · Unity 2022.3 LTS

Amazon Web Services for Unity, including WebGL.

Cognito auth with SRP and MFA, Identity Pools, S3 multipart storage, DynamoDB with typed models, Lambda invocation and drop-in game systems — pure C# over the AWS REST surfaces. No aws-sdk-net DLLs, no native plugins, IL2CPP/AOT-safe.

867 EditMode + 2 PlayMode tests passing at v0.37.0 on Unity 6000.3.11f1, October 4, 2026 Try it with no AWS account: Demo mode runs every call in memory Guided Setup tab: empty project → verified backend One code path for WebGL, mobile and desktop Ships an agent bundle + Unity CLI commands for AI coding agents
PlayerBackend.cs
AwsClient.InitializeFromResources();
var aws = AwsClient.Instance;

await aws.Auth.SignInWithSrpAsync(email, password);

var top = await aws.Game.Leaderboards
    .GetTopAsync("global", 10);

await aws.Storage.UploadAsync(
    $"avatars/{userId}.png", pngBytes, "image/png");
869automated tests passing at v0.37.0
8editor tabs ending in a live smoke suite
0aws-sdk-net DLLs or native plugins
WebGLfirst-class target, CORS-checked

What you get, how long it takes, and what you need.

What you get

A pure C# client for Cognito, S3, DynamoDB, Lambda, WebSockets, SQS, SNS, Secrets Manager, Bedrock, Step Functions and EventBridge, plus game systems, editor tools, drop-in UI, IAM templates and Demo mode.

Setup time

Try Demo mode immediately without an AWS account. For a live backend, the starter stack takes a few minutes to provision; allow extra time to choose an AWS account, region and IAM setup.

Unity & prerequisites

Unity 2022.3 LTS or newer, including Unity 6. Live use needs your AWS account and resources. AWS CLI is optional; the CloudFormation console route works too.

Read the AWS setup and platform guideBrowse FAQs

The AWS services a game actually uses.

Everything is implemented clean-room against public AWS documentation, signs with temporary Identity Pool credentials, and runs on UnityWebRequest.

Auth & identity

Cognito User Pools with the flows hardened pools require, plus a pure-C# SRP-6a implementation so the password never leaves the device.

  • Password and SRP sign-in, refresh tokens, persistent sessions
  • MFA continuation: SMS, TOTP and e-mail OTP; forced password change
  • Phone OTP / passwordless via CUSTOM_AUTH, with a production-shaped Lambda template
  • Hosted UI social sign-in (Google, Apple, Facebook) via OAuth2 + PKCE with deep-link completion that survives app suspension
  • Identity Pools mint short-lived credentials that refresh automatically

S3 storage

Upload, download, metadata, delete, paginated listing, presigned GET/PUT URLs, chunked multipart with progress and resumable uploads after interruption, plus Texture/Sprite/AudioClip loaders.

DynamoDB data

[Serializable] model marshalling, reserved-word-safe expression builders, Query/Scan pagination, projections, conditional writes, batch and transactional writes, PartiQL and COUNT-only rank queries.

Lambda functions

Signed data-plane invokes, typed request/response overloads, response streaming through CRC-verified event-stream framing, and Function URLs as the WebGL path.

Signature V4

A pure-managed signer validated against official AWS example vectors and botocore, with presigning and every service path pinned by reference tests.

Also in the box: realtime WebSockets over API Gateway — IAM-signed wss:// URLs, an offline send queue, bounded reconnect with exponential backoff and heartbeats — push registration through AWS End User Messaging for re-engagement, and drop-in uGUI or UI Toolkit panels for auth and leaderboards.

The backend systems every game needs, included.

  • Leaderboards — best-wins conditionals, GSI top-N, COUNT ranks, optional server-authoritative scoring through the shipped Lambda template.
  • Cloud saves — multi-slot, cross-device, optimistic concurrency so a stale device cannot clobber newer progress.
  • Feature flags — deterministic percentage rollout per player, with a JSON payload.
  • Analytics — buffered, batched by 25, TTL-retained; flushed automatically on pause and quit.
  • Offline queue — durable mutations that survive restarts; key-aware coalescing, per-table replay policies, a dead-letter list and a live inspector in Diagnostics.

Provisioned from the editor

One click creates the four tables with the right keys, GSIs and TTL. Scoped player and admin IAM policy templates are generated next to them.

Cloud saves are scoped per player with dynamodb:LeadingKeys on the Cognito identity sub. Leaderboard writes move server-side when you deploy the scoring Lambda.

From empty project to verified backend, in one tab.

The Setup tab walks six self-checking steps. The other seven tabs cover day-to-day work.

01

Deploy & paste

Copy the one-stack CloudFormation template — or, with the AWS CLI installed, deploy and import the outputs without leaving Unity.

02

Verify

Credentials → DynamoDB ping → configuration doctor → live bucket-CORS check, logged in dependency order.

03

Provision & play

Create the game tables, then build the wired auth + leaderboard demo scene and press Play.

Day-to-day: settings, connection checks, pack provisioning with IAM templates, a read-only DynamoDB browser, a table → C# model + typed repository generator, configuration doctor, diagnostics — and a one-button live smoke suite that exercises every service against your real account, then deletes its own test user. Not ready to wire up AWS? Flip Demo mode and the whole stack runs in memory.

Works with your AI.

The package ships an agent bundle — llms.txt, a package agent guide and five task skills (setup, auth, WebGL, data, troubleshooting) — so coding agents load the correct AWS patterns instead of guessing. One menu click — Install Agent Skills — copies the skills into your project's .claude/skills/ folder for auto-discovery. Diagnostics are machine-readable too: doctor findings and smoke reports come as JSON as well as Markdown.

  • Unity CLI commands — with Unity's Pipeline package (Unity 6+), eleven aws_* commands cover the doctor, stack deploy, output import, verification, model and repository generation, table provisioning, IAM policies, cost estimates, the release gate and the store export.
  • Safe by default — every mutating command refuses without confirm=true, and dry_run previews the change. Live commands use the credentials you already configured; the toolkit itself never stores long-lived keys.
  • Honest boundaries — the agent guide points at the published verification report, so an agent never claims a live pass that has not been run.

Files first, CLI second

Plain files work on every supported Unity version; the CLI commands need Unity 6+ and never affect the runtime player. The command assembly is version-guarded, so the Unity 2022.3 floor is untouched.

The exported .unitypackage ships the documentation set and the agent bundle under Documentation/, so Asset Store buyers get the same surface.

Readable C#. No proxy SDK.

Typed models, async/await, cancellation on every call, and errors that carry the AWS error type.

Open the docs

Leaderboard.cs
// Best-wins submission, server-authoritative
var result = await aws.Game.Leaderboards
    .SubmitScoreViaLambdaAsync("global", userId, 9001);

// Top 10 with reserved-word-safe expressions
var top = await aws.Game.Leaderboards
    .GetTopAsync("global", 10);

// Only the metadata — payloads stay in DynamoDB
var slots = await aws.Data.QueryAsync<CloudSaveRow>(
    new DynamoQueryRequest
{
    TableName = "GameSaves",
    KeyCondition = DynamoKeyCondition.HashEquals(
        "UserId", AttributeValue.S(userId)),
    Projection = DynamoProjection.Of(
        "Slot", "Revision", "UpdatedAt", "DeviceLabel"),
});

WebGL, honestly.

SurfaceDesktop / mobileWebGL
Cognito auth + identitydirectdirect (CORS-enabled endpoints)
S3 objectsdirectafter a one-time bucket CORS rule (validated by the doctor)
Lambdadata planeFunction URLs
DynamoDB data planedirectvia Function URL / API Gateway proxy
Where AWS is architecturally closed to browsers, the toolkit ships the documented proxy pattern instead of hand-waving — and the Doctor validates your live bucket CORS before a build ships.

Security & compatibility

No long-lived keys in clients, server-authoritative paths where they matter — and an inline cost estimator so the monthly AWS bill is visible before launch, not after.

No long-lived keys

Every signed call uses temporary Identity Pool credentials; player rows are scoped to the caller by IAM condition.

Server-authoritative paths

The scoring Lambda template ships with the toolkit; the doctor flags extractable app-client secrets and client-trust gaps.

Proven, not asserted

Reference vectors from AWS docs, RFCs and botocore pin every protocol path. The package's verification report records each version's test count and the reference provenance, and every device pass produces a saved smoke report, from the editor or the on-device runner.

Unity support

Unity 2022.3 LTS and Unity 6 · Mono and IL2CPP · Windows, macOS, Linux, Android, iOS and WebGL. The v0.37.0 suites pass on Unity 6000.3.11f1; live device verification against AWS remains a separate step before production use.

Dependency story

No aws-sdk-net assemblies, no NuGet resolution, no native plugins, no TextMeshPro requirement. link.xml included for stripping.

Before you connect AWS.

Can I try the toolkit without an AWS account?

Yes. Demo mode runs in memory in the editor and development builds. It is for evaluating and prototyping; a live game needs your own AWS resources.

Does it use the AWS SDK or native plugins?

No. The runtime uses a pure C# REST implementation over UnityWebRequest, with its own SigV4 signer. It does not ship aws-sdk-net DLLs or native plugins.

What should I know about WebGL?

WebGL is supported, with service-specific setup: S3 needs bucket CORS, and DynamoDB data calls need a Function URL or API Gateway proxy because DynamoDB has no browser CORS support.

Are long-lived AWS keys included in the game?

No. Player calls use temporary Cognito Identity Pool credentials. Keep administrative permissions and sensitive operations on a trusted backend.

A direct Studio licence, after the live verification pass.

Teams that need an invoice, named seats for one title and a support term will be able to license the toolkit directly, under commercial terms you can hand to procurement rather than the Asset Store EULA.

The Studio licence opens once the live device pass against real AWS is complete, because that verification report is what a studio should judge it on. Ask when the Studio licence opens, or start with the documentation today.
Pre-release

Evaluate the toolkit against your own AWS account.

The Asset Store listing is not live yet. Read the documentation, try Demo mode with no AWS account, or ask about release timing.

Running a different backend?

The same playbook, with full C# source and WebGL support: the Unity Supabase Toolkit for Postgres, Row Level Security and live-ops, and the Unity Firebase Toolkit for Firebase over REST.

See all toolkits

Trademarks

Amazon Web Services, AWS, Amazon Cognito, Amazon DynamoDB, Amazon S3 and AWS Lambda are trademarks of Amazon.com, Inc. or its affiliates. An independent integration, not affiliated with or endorsed by Amazon. "Unity" is a trademark of Unity Technologies.