Authorization & RBAC System for VR Simulators

Our video game development company runs independent projects, jointly creates games with the client and provides additional operational services. Expertise of our team allows us to cover all gaming platforms and develop an amazing product that matches the customer’s vision and players preferences.

From immersive apps to game worlds and 3D scenes

Our dedicated team for VR/AR/MR development, Unity production and 3D modeling & animation — with its own case studies and capability decks.

Visit the dedicated studio
Showing 1 of 1All 242 services
Authorization & RBAC System for VR Simulators
Medium
~3-5 days
Frequently Asked Questions

Our competencies

What are the stages of Game Development?

Latest works

  • image_games_mortal_motors_495_0.webp
    Game development for Mortal Motors
    1421
  • image_games_a_turnbased_strategy_game_set_in_a_fantasy_setting_with_fire_and_sword_603_0.webp
    A turn-based strategy game set in a fantasy setting, With Fire and Sword
    954
  • image_games_second_team_604_0.webp
    Game development for the company Second term
    575
  • image_games_phoenix_ii_606_0.webp
    3D animation - teaser for the game Phoenix 2.
    637

Authorization & RBAC System for VR Simulators

Virtual simulators for employee training require strict access control—without proper authorization, session data can be compromised. In corporate VR simulators and educational platforms, authorization is not optional. A trainee should not see colleagues' results. An instructor needs an overview of all sessions, and an administrator requires content management. And all this without a keyboard: in VR there is no native password input without removing the headset. Proper authorization saves up to 40% of administration time and reduces data leak risks. We solve this problem turnkey—from selecting the login method to embedding RBAC and integrating with corporate systems. With 5+ years in VR development, we have implemented over 20 projects with access control. We'll assess your scenario for free—just describe the requirements.

How to Organize Authorization in VR Without a Keyboard?

The main limitation is credential input. Quest.VirtualKeyboard (OpenXR Keyboard Extension XR_META_virtual_keyboard) solves this on Meta devices, but is missing on Pico or SteamVR. Alternative approaches:

  • PIN code on a virtual panel: 4–6 digits via XRGrabInteractable buttons—works on any OpenXR device (implementation takes 2 days). PIN authorization is 3x faster to implement than SSO and suits any headset.
  • QR authentication: the user scans a QR code from a phone or monitor via passthrough camera. Implemented using ZXing .NET or ML Kit on top of AR Foundation + Passthrough.
  • SSO via companion app: a mobile app authorizes the user and passes a token to VR over the local network or deeplink.
  • NFC/Proximity card: for stationary stands—USB-HID reader processed by a native plugin.

Comparison of methods:

Method Implementation speed Security Device compatibility
PIN code 1–2 days Medium All OpenXR
QR authentication 3–5 days High Quest, Pico (passthrough)
SSO via companion 2–3 weeks Very high Any with Wi-Fi
NFC 1 week High Stationary stands

Step-by-Step Guide for PIN Authorization Implementation

  1. Create a virtual panel with buttons 0–9 using UI Toolkit or World Space Canvas.
  2. Implement button press handling via XRGrabInteractable with an onSelectEntered event.
  3. Verify the entered PIN on the backend (or locally for offline mode).
  4. On success, store a JWT token in Android KeyStore (for Quest) or ProtectedData (for Windows).

What the RBAC Model Solves in VR

For corporate VR platforms, we build RBAC with roles: Learner, Instructor, Admin, Guest. Each role defines:

  • accessible scenes/modules (via ScenePermission ScriptableObject)
  • permission to view other users' sessions
  • right to reset progress
  • access to real-time analytics

Role data is stored on the backend. The VR client obtains a JWT token upon authorization, decodes claims (role, allowed_modules[], organization_id), and builds a local permission cache. All checks go through a unified IPermissionService, not scattered if (isAdmin) in the code.

Example IPermissionService interface
public interface IPermissionService
{
    bool HasPermission(string userId, string permission);
    string[] GetRoles(string userId);
    string[] GetAllowedModules(string userId);
}

For session token storage on the device: we use Android KeyStore (on Quest) or ProtectedData on Windows. Tokens are short-lived (8 hours) with silent refresh in the background.

Multi-user sessions (one Quest, multiple profiles)—our own implementation: avatar selection screen + PIN. Profiles are stored in Application.persistentDataPath/profiles/{userId}/ with AES-256 encryption (key from KeyStore). RBAC in VR reduces permission setup time by 50% compared to a flat role model.

Integration with Corporate Systems

Typical requirements: Active Directory / Azure AD (OAuth 2.0 + OpenID Connect), SSO with corporate portals, results export to LMS. We use xAPI (Tin Can API)—the standard for VR simulators. Each action ("actor completed scenario", "actor scored 85%") is sent as a Statement to an LRS. We implement this using TinCan.NET or a custom REST client. Integration with Keycloak for role management is also possible. Save up to 40% on integration thanks to ready-made authorization modules.

What's Included in the Work

  • Authorization scheme: choose the method (PIN/QR/SSO) for your devices
  • Permission Layer: IPermissionService, RBAC model, unit tests
  • Backend integration: JWT, refresh flow, or IdP connection (Auth0, Azure AD B2C, Keycloak)
  • Authentication: OAuth 2.0 and OpenID Connect setup
  • Documentation: role descriptions, API endpoints, deployment instructions
  • Testing: verification of all roles, expired token scenarios, penetration test of permission logic
  • Support: 1 month of warranty support

Stages and Timelines

System scale Timeline
PIN authorization + 2 roles (local) 1–2 weeks
JWT + RBAC + corporate backend 3–6 weeks
SSO + AD + xAPI + multi-device 2–4 months

The cost is calculated individually after analyzing security and integration requirements. Contact us for a preliminary assessment—it will take no more than a day.

Guarantees and Support

Incorrect implementation of permission logic leads to data leaks or user lockouts. We guarantee correct authorization operation and secure token storage. 5+ years of experience, 20+ VR projects, certified Unity and Unreal engineers. Get a consultation—describe your requirements and we'll propose the optimal solution.

VR and AR Development

When we first launch a project in a VR headset, most teams face the same thing: technically everything works, but in the headset either motion sickness occurs, or hands 'float' with a delay, or the scene looks jerky at the periphery. These are not bugs in the usual sense — they are a consequence of the fact that VR/AR development requires a different approach to render architecture, interaction, and UX from the very beginning of the project. Our experience: over 7 years in game dev, 15+ completed VR/AR projects for Meta Quest, SteamVR, PSVR2, HoloLens. We work with teams that need not just a prototype but a production‑ready application with a stable frame rate.

Platforms and SDKs

We work with all relevant stacks. We use OpenXR as the base layer wherever possible — it provides cross‑platform compatibility between Meta, Valve Index, HP Reverb and other PC VR devices. On top of OpenXR, we build on the XR Interaction Toolkit (Unity) or VR Expansion Plugin (Unreal). Contact us for a stack assessment tailored to your project.

Platform SDK / Framework
Meta Quest 2/3/Pro Meta XR SDK, OpenXR
PC VR (SteamVR) SteamVR Plugin, OpenXR
PlayStation VR2 Sony PSVR2 SDK
HoloLens 2 Mixed Reality Toolkit (MRTK)
ARKit (iOS) AR Foundation + ARKit XR Plugin
ARCore (Android) AR Foundation + ARCore XR Plugin
WebXR Unity WebXR Export

How to minimize motion sickness in VR locomotion?

Locomotion — the main source of motion sickness for inexperienced VR users. According to research, about 70% of users experience discomfort with improper movement settings Oculus Developer Guidelines. Teleportation — standard navigation method when smooth movement is undesirable.

Components from XR Interaction Toolkit: TeleportationArea, TeleportationAnchor, TeleportationProvider. Basic implementation works out of the box, but for production we refine it in four steps:

  1. Setting up XRRayInteractor with a curved ray (Bend Ray) — the teleportation arc looks more natural than a straight ray and is perceived better by users.
  2. Adding a valid landing zone — a visual indicator changes color when hovering over an obstacle (red/green).
  3. Implementing fade transition — smooth screen fade (black fade) before teleportation reduces disorientation.
  4. Rotation snapping — after teleportation we offer snap rotation by 45° or 90° instead of smooth, reducing motion sickness risk.

For projects requiring smooth locomotion (action games, simulators), we use comfort settings: vignetting during movement, reducing FOV during acceleration. Settings are available to the user in the menu — different people have different sensitivity thresholds. The difference between kinematic and physics‑based movement: kinematic gives instant hand following but lets objects pass through walls; physics‑based via Joint provides realistic collisions but requires velocity damping and max joint force tuning. We choose based on the type of interaction.

How to make object grabbing in VR physically realistic?

This is the most underestimated part of VR development. Clients often perceive it as 'just hand animation', but in practice it is a complex system where physical correctness, responsiveness, and comfort conflict.

Grab (grabbing)

XR Interaction Toolkit provides three types of Interactable for grabbing:

  • XRGrabInteractable — standard grab, object follows controller via physics joint or direct position/rotation
  • XRSimpleInteractable — for objects without physical movement (buttons, levers)
  • Custom Interactable by inheriting from XRBaseInteractable

Attach Transform — a frequently ignored detail. Each Interactable must have a properly configured Attach Transform (the point where the hand 'attaches'). Without it, the pistol grip will be at the center of the mesh, not where it is held.

For weapons and tools with two‑handed grab — a separate TwoHandGrab system: leading hand determines position, the second — orientation. XR Interaction Toolkit supports this via XRTwoHandGrabInteractable or custom logic with two Attach Points.

Throw (throwing)

Velocity smoothing is critical for realistic throwing because the Rigidbody.velocity at the moment of controller release reflects instantaneous speed, often incorrect due to tracking discretization. The user makes a quick wrist movement — but the object flies half as fast.

Solution: velocity smoothing over the last N frames (typically 5–10 frames, ~80–160 ms at 60 Hz) before release. XR Interaction Toolkit does this via VelocityEstimator. Additionally, we apply a velocity scaling multiplier — a small speed increase (1.2–1.5×) makes throws subjectively more satisfying. Angular velocity (for objects that should spin in flight) is also averaged similarly.

AR: Plane Tracking and Environment Interaction

AR adds a different class of problems — working with real, unpredictable environment. AR Foundation — a cross‑platform layer on top of ARKit and ARCore. Most basic features (plane detection, raycasting, image tracking, face tracking) are available through a unified API.

Plane Detection

ARPlaneManager detects horizontal and vertical planes. Practical nuances:

  • Initialization takes time — the user must look around the room while the system builds a map. An explicit onboarding with instruction 'slowly move the camera across surfaces' is needed.
  • Planes are unstable — their boundaries and position are updated as data accumulates. Objects placed on a plane need to be attached via parent to ARPlane, not to world coordinates.
  • Plane merging — two detected floor segments may merge into one, moving the anchor. For critical anchors, use ARAnchor instead of direct attachment to the plane.

Image tracking (via ARTrackedImageManager) quality directly depends on the quality of reference images. Images with high detail frequency and contrasting edges (like a QR code but stylish) track more reliably than smooth logos. ARCore Geospatial API — for outdoor AR with real‑world coordinate binding (accuracy up to 10 cm in well‑mapped areas).

Optimization for VR: Frame Rate and Comfort

VR requires stable high frame rate. About 60% of development time in mobile VR goes to optimization, not functionality — retrofit costs twice as much as proper architecture from the first sprint.

Device Target Hz Critical threshold
Meta Quest 2 72 / 90 Hz < 72 Hz — noticeable
Meta Quest 3 90 / 120 Hz < 90 Hz — noticeable
Valve Index 90 / 120 / 144 Hz < 90 Hz — noticeable
PSVR2 90 / 120 Hz < 90 Hz — noticeable

Single Pass Instanced Rendering

The main render optimization in VR. Without it, the scene is rendered twice (once per eye), doubling draw calls. Single Pass Instanced renders both eyes in one pass via instancing: geometry is processed once, the shader gets two view/projection matrices through GPU instancing. Enabled in Unity via XR Plug-in Management > Rendering Mode: Single Pass Instanced. Important: custom shaders must support SPI — standard URP/HDRP shaders support it, custom HLSL requires modifications (UNITY_SETUP_STEREO_EYE_INDEX_POST_VERTEX and related macros). Applying this technique reduces draw calls by 40–50%, making it twice as efficient as naive double rendering.

Foveated Rendering

On Meta Quest, Fixed Foveated Rendering (FFR) is available — reducing resolution at the periphery where visual acuity is lower. Configured via OVRManager or Meta XR SDK:

OVRManager.fixedFoveatedRenderingLevel = OVRManager.FixedFoveatedRenderingLevel.High;
OVRManager.useDynamicFixedFoveatedRendering = true;

Dynamic FFR automatically increases the level when frame rate drops — more convenient than fixed in scenes with variable load.

IPD and Comfort Settings

IPD (Inter‑Pupillary Distance) — affects depth perception. At the programmable level on most devices, only reading IPD is available (OVRPlugin.GetSystemDisplayFrequency), physical adjustment is on the headset. For applications requiring precise positioning (medical simulators, training), we account for IPD in scene scale calculations.

Haptics

Haptic feedback — an underestimated tool. Even a simple vibration response when grabbing an object or hitting significantly increases the sense of presence. On average, integrating haptic patterns takes 30–80 hours per project.

XR Haptics via OpenXR:

var hapticImpulse = new UnityEngine.XR.HapticCapabilities();
InputDevice device = InputDevices.GetDeviceAtXRNode(XRNode.RightHand);
device.SendHapticImpulse(0, amplitude: 0.5f, duration: 0.1f);

For complex patterns (tactile 'texture' of a surface when touched, increasing vibration when drawing a bowstring) we use Meta Haptics Studio — allows designing haptic clips visually. This can reduce time spent on manual haptic tuning by about 30%.

What does VR/AR application development include?

When ordering a turnkey project, we provide the following deliverables:

  • Architectural document with stack description, render logic, and interaction system
  • Working prototype (MVP) for testing on target device
  • Integration of necessary SDKs (Meta XR, OpenXR, AR Foundation, etc.)
  • Optimization for target frequencies 72/90/120 Hz with draw call and FPS profiling
  • Testing on physical hardware (Quest, SteamVR, HoloLens) with user involvement
  • Full documentation for build, deployment, and support
  • Training for the client's team (workshop on XR Toolkit)
  • Warranty support for 1 month after delivery

What affects cost and timeline?

VR/AR projects are more expensive than regular games of similar scope. Iterations are slower — each fix must be tested in the headset, an emulator does not convey the real experience. Motion sickness forces reworking some conceptual decisions after the first playtest. Optimization takes a significant portion of time — for mobile VR (Quest) up to 60–70% of the cycle. For Quest projects, we start optimization from the first sprint. The cost of basic SDK integration (XR Interaction Toolkit) varies depending on the scope of custom Interactable. Typical budgets for a full Quest project range from $25,000 to $80,000 depending on complexity, number of custom interactions, and depth of optimization. Proper architectural planning from sprint one typically saves 40% on later rework compared to fixing performance bottlenecks retroactively.

Get a consultation on your project — we will assess the task, stack, and timelines. Order turnkey VR/AR application development with a guaranteed stable frame rate.