Turn-Based Multiplayer for a Mobile Game: Server Validation and Development
Imagine: a player makes a move in a chess game, the client validates it, sends it to the server. The server applies it without validation. A cheater intercepts the request and sends the queen to any square. Result — a broken match, lost rating. Our experience shows: 99.9% of support tickets about multiplayer are due to missing server-side validation.
We have specialized in turn-based multiplayer solutions for over 9 years. One project was a chess game with ELO rating and matchmaking, where up to 5,000 active users played simultaneously. Server validation eliminated cheating, and an atomic Redis queue reduced opponent search time to under 2 seconds in 95% of cases. Over that time, we have implemented more than 50 projects with turn-based multiplayer. Our solutions reduce support costs by 40% by automating validation and queues.
Why Is Server Validation Critical?
The main mistake is trusting the client to validate move legality. The client checks "move possible" and sends it to the server. A cheater intercepts the request and sends an illegal move directly. The server applies it without validation. Result: inconsistent state, disqualification of honest players.
The correct scheme: the server holds the authoritative game state. The client sends an intention (moveFrom: e2, moveTo: e4), the server validates it against the rules, applies it, and broadcasts the new state. The client only renders. Game logic is duplicated on the server — for Unity this is a headless build, for other stacks a microservice in Go or Node.js. According to Wikipedia, an authoritative server is the standard for reliable multiplayer systems.
| Criteria |
Client Validation |
Server Validation |
| Reliability |
Low (cheating) |
High (authoritative) |
| Performance |
High |
Medium (needs server) |
| Implementation Complexity |
Low |
High (logic duplication) |
Server validation is 10 times more reliable than client validation. This is critical for ranked games where every match affects the rating. Load testing shows throughput of up to 1,000 requests per second with an average move processing time of less than 50 ms.
How to Manage Sessions via Push Notifications?
In turn-based multiplayer, the connection does not need to be persistent. After a move, the player can close the app. The next opponent move must arrive via push notification: FCM on Android, APNs on iOS.
The server stores the device token (Firebase Cloud Messaging or Apple Push Notification Service). When the turn changes, it sends a notification with game_session_id. The client opens the specific session via deep link (Universal Link / App Link).
On Android: FirebaseMessagingService, override onMessageReceived. On iOS: UNUserNotificationCenter + UNNotificationRequest. Important: on iOS set content-available: 1 for background state update without showing a banner. Otherwise the player won't see the current state until opening the app.
In one project, we handled up to 10,000 push notifications per day. Errors occurred only due to outdated tokens — regular cleanup (API returns 410 Gone) solved the problem. Average notification delivery time was under 200 ms.
How to Implement Matchmaking with Minimal Delay?
Ranked ELO matchmaking is done in several steps:
- Client sends
findMatch with current rating.
- Server atomically checks the queue on a Redis Sorted Set using a Lua script: searches for a player with rating ±150 points.
- If not found after 30 seconds, expand range to ±300.
- After 60 seconds, offer to play against a bot.
The Lua script guarantees atomicity: two matchmakers cannot take the same player twice. Search time in 95% of cases does not exceed 2 seconds with 1,000 concurrent players. Collision probability with atomic access is reduced to 0.01%. Learn more about the ELO rating system on Wikipedia.
Session Recovery After Disconnection
A player leaves mid-match. The server stores a full move log (event sourcing). On reconnect, the client receives a GameStateSnapshot — the current state — and renders it without replaying history. History is only needed for displaying the "move log". Average session recovery time is under 500 ms.
Move timeout: the server starts a timer after the turn changes. If the player does not move within N minutes, an auto-move or loss is triggered. Implementation via ScheduledExecutorService on JVM backend or setTimeout in Node.js with jobId stored in Redis. This prevents the match from hanging forever.
Timelines and What's Included
| Component |
Timeline |
| Basic mechanics (2 players, validation, push) |
3–6 weeks |
| Matchmaking |
+1–2 weeks |
| Rooms, spectators, asynchronous matches |
+2–3 weeks |
We guarantee code review and load testing at each stage. Get a consultation on your project's architecture — order an audit of your current solution. Contact us for a detailed development plan within 1–2 days.
Avoid typical mistakes: missing server validation ruins game balance; no move timeout causes hanging sessions; push notifications without deep links don't return the player to the match; matchmaking without atomicity leads to duplicate players. Our processes eliminate these issues.
How to Start Integrating API into a Mobile App?
The request goes out, the response doesn't come, timeout — 30 seconds. The user stares at the spinner. No network — mobile card in the subway. Or the network is there, but the server returns 200 with an HTML error page instead of JSON — and the app crashes on JSONDecoder.decode(). We see such cases on every second project. So integrating API into a mobile app is not just calling an endpoint, but designing a reliable network layer: error handling, caching, offline mode, certificate pinning. Order an audit of your current network layer — we will evaluate the project in 1 day. Our team guarantees a thorough analysis and provides a detailed roadmap.
Standard libraries like URLSession and OkHttp provide basic HTTP clients, but for production you need retries with exponential backoff, status code validation, typed deserialization, and network state monitoring. Without this, the app loses data and users. We have been doing mobile development for 5 years and implemented more than 30 projects with API integration on iOS, Android, and Flutter — from startups to enterprise solutions.
How to Choose a Protocol for API Integration?
| Protocol |
Response Size |
Parsing Speed |
Caching |
Suitable For |
| REST |
Large (fixed structure) |
Medium |
HTTP cache + local |
CRUD, typical screens |
| GraphQL |
Minimal (only needed fields) |
Medium (normalized cache) |
In-memory cache (Apollo) |
Complex UIs with different queries |
| gRPC |
Minimal (protobuf) |
High |
Stream-level |
High-load, real-time, IoT |
| WebSocket |
— (binary/text) |
— |
Manual |
Chats, quotes, synchronization |
REST remains the standard for most projects. But when a profile screen needs 5 fields out of 40, GraphQL eliminates over-fetching and reduces traffic by 30–60%. gRPC is justified for thousands of requests per minute (trading, IoT) — binary serialization is 3–5 times faster than JSON. WebSocket is the only choice for real-time without polling (messages, notifications).
Practical example: For a fintech app, we replaced REST (40 fields) with GraphQL — response size dropped from 12 KB to 2.5 KB, screen render time decreased by 70%. Traffic savings were significant. Our certified iOS and Android developers have deep experience with all these protocols — you can rely on proven solutions.
How to Ensure Reliable Connection and Offline-First?
Users lose network in the subway, elevator, tunnel. A mobile app must work without internet — at least in read-only mode. We implement the offline-first pattern:
- On screen open, first show data from the local cache (Core Data / Room).
- Simultaneously perform a network request, update UI after response.
- If network is unavailable — show cached data and a 'no connection' label.
- When network is restored, automatically synchronize changes.
For HTTP response caching we use URLCache (iOS) and OkHttp Cache (Android) with Cache-Control support. For structured data — SwiftData / Room. NWPathMonitor / ConnectivityManager.NetworkCallback monitor network state and trigger updates.
REST and Client Library Selection
Alamofire (iOS) — de facto standard for Swift projects. On top of URLSession it adds request chaining, response validation, automatic retry, certificate pinning via ServerTrustManager. AF.request() with .validate() returns an error for any status code outside 200–299. Without .validate(), Alamofire considers 404 and 500 as successful responses. With Swift Concurrency — async version via serializingDecodable.
Retrofit (Android) — annotation-based HTTP client on top of OkHttp. An interface with annotations compiles into implementation. @GET, @POST, @Path, @Query, @Body — declarative API description. OkHttp under the hood: connection pooling, transparent gzip, HTTP/2 multiplex. HttpLoggingInterceptor — logging in debug builds. Authenticator — automatic token refresh on 401.
Ktor (KMM/Flutter) — multiplatform HTTP client. On iOS it works via Darwin engine (URLSession), on Android — via OkHttp. Single code for both platforms with KMM architecture.
GraphQL: When REST Falls Short
REST returns a fixed structure. A profile screen needs name, avatar, email — the server sends 40 fields. Over-fetching. GraphQL solves this: the client requests exactly the needed fields. This is critical for mobile where traffic and parsing time are real constraints. Apollo iOS and Apollo Kotlin generate typed classes from schema: schema.graphql + query files → strict types at compile time. Subscriptions via WebSocket — real-time without polling. Limitation: GraphQL is harder to cache at the HTTP level. Apollo uses a normalized in-memory cache InMemoryNormalizedCache — requests with overlapping data update the cache without duplication.
WebSocket: Real-Time Without Extra Traffic
Polling (setInterval every 5 seconds) — battery and traffic waste. WebSocket is a persistent bidirectional connection. iOS: URLSessionWebSocketTask (native, iOS 13+). Android: OkHttp WebSocket. Mandatory reconnect handling: on onFailure — exponential backoff (1s → 2s → 4s → 8s → max 60s). Socket.IO is an overlay with automatic reconnect, but for new projects native WebSocket is preferable (fewer dependencies).
gRPC: For High-Load Services
gRPC with protobuf — binary serialization: smaller size, faster parsing. grpc-swift for iOS, grpc-kotlin for Android. The protobuf schema compiles to typed classes. Streaming (server-side, client-side, bidirectional) is a native feature. Application threshold: high request frequency (trading, IoT) or critical latency. For regular CRUD, REST is simpler to debug and monitor.
Certificate Pinning and Security
A corporate proxy can intercept HTTPS by substituting the certificate. Certificate pinning prevents this: the app accepts only a specific certificate or public key. Alamofire: ServerTrustManager with PinnedCertificatesTrustEvaluator. OkHttp: CertificatePinner with SHA-256 hash. Apple's App Transport Security documentation recommends pinning certificates for sensitive data. Operational complexity: on certificate rotation, older app versions stop working. Solution — pinning to the CA public key or support multiple pins with a grace period.
What Is Included in the Work
| Stage |
Duration |
Result |
| API and requirements analysis |
1–2 days |
Endpoint specification, protocol selection, caching schema |
| Network layer implementation |
3–5 days |
Client library, error handling, retry, pinning |
| Offline mode and caching |
2–3 days |
Local storage, offline-first pattern |
| Integration and testing |
2–3 days |
Unit tests (URLProtocol/OkHttp MockWebServer), UI tests |
| Deployment and documentation |
1 day |
CI/CD, store access, team README |
We deliver: source code of the network layer, documentation on used libraries, certificate rotation instructions, 2 weeks post-delivery support. Our experience guarantees that the solution will be stable and maintainable.
Timeline and Cost
Implementation of a network layer with REST, retry, caching, and offline mode — 1–2 weeks. Adding GraphQL or WebSocket — another 1–2 weeks. gRPC — 2–3 weeks, including code generation. The cost is calculated individually after analyzing the API and offline behavior requirements. We will evaluate the project in 1 day — contact us for a consultation. Get a reliable API integration with guaranteed quality.