← Questwell
DocumentationPrivacyEULASupport

Questwell docs

Questwell shows the PlayFab player behind a Zendesk ticket and lets the agents you choose grant make-goods, ban and lift bans, revoke items and send the recovery email, each one capped by role and logged on the ticket. It runs inside Zendesk; there is no Great Work server.

Setup

  1. Make a secret key for Zendesk. Game Manager > your title > gear icon > Title settings > Secret Keys > New Secret Key. Name it "Zendesk Questwell" and give it an expiration date.
  2. Install Questwell and fill in the PlayFab title id (the short code, for example A1B2C) and the secret key. The key is a Zendesk secure setting: agents never see it, and Zendesk only sends it to <title id>.playfabapi.com.
  3. Set the guard rails: currency caps, grantable items, who can moderate, the longest ban. Defaults are safe: agents can't grant any currency until you add a caps line, item grants are off until you list items, only admins moderate, statistic resets are off.
  4. Lock the key to Zendesk (recommended). Copy the egress ranges from https://<subdomain>.zendesk.com/ips into the key's IP allowlist in Game Manager (Edit secret key > Enable IP allowlist). Then refresh a ticket to check.

Finding the player

Questwell tries, in order:

  1. The PlayFab id ticket field, if you set one in the settings.
  2. Every email address on the requester's Zendesk profile (PlayFab's login email).
  3. PlayFab ids written in the ticket subject or description ("PlayFab ID: 8F3C2A91D04B7E65", or any 16-character id).
  4. Steam ids (SteamID64, 17 digits starting 7656119) in the ticket.

Ids found in text are only shown after PlayFab confirms the account. Agents can also type an email, PlayFab id, Steam id or in-game display name in the lookup box (user: followed by a name looks up a PlayFab username). Every lookup is exact: nothing lists or searches players in bulk.

Players who sign in with Steam, Xbox, PSN, Nintendo, Apple or a device usually have no PlayFab email. Ask them for their PlayFab id (most games show it in settings) or add a PlayFab id field to your contact form.

What agents see

  • Player card: display name, PlayFab id, login email, banned or not, last login, playing since, how they joined, and how Questwell found them.
  • Bans: bans in force first (reason, start, end or permanent), then lifted and expired bans. IP addresses on bans are never shown.
  • Currency: every virtual currency balance, with recharge limits.
  • Inventory: every item, newest first, with "Bought $19.99" or "Bought 1,200 GC" for purchases and "Granted" for grants, uses left, expiry, and the ticket number on items Questwell granted.
  • Purchases: lifetime spend in US dollars and per currency, the last paid items, and memberships with their store subscriptions. Store receipts stay in Steam, Apple, Google and Game Manager: PlayFab's Legacy Economy has no server API that lists a player's orders.
  • Linked accounts: Steam (name and id), Xbox, PSN (online id), Nintendo, Apple, Game Center, Google, Google Play Games, Facebook, Twitch, Battle.net, OpenID, device and custom ids.
  • Statistics and segments, and the player data keys you list (read-only).

Actions

Every action needs a ticket, shows exactly what will happen, and writes an internal note plus a tag on the ticket. Questwell re-reads the player and the ticket right before sending.

ActionWho (default)LimitsTag
Grant currencyWho can grant (agents)Per role and currency, per player per ticket, counting every grant on the ticketquestwell_currency_granted
Grant an itemWho can grantOnly items on your list; agents at most 3 per player per ticketquestwell_item_granted
Send recovery emailWho can grantOnly to the account's own PlayFab login emailquestwell_recovery_sent
BanWho can moderate (admins)Not while a ban is in force; non-admins up to the longest ban (30 days), never permanentquestwell_banned
Lift banWho can moderateLifts the bans in forcequestwell_unbanned
Revoke an itemWho can moderateOne item instance; does not refund the playerquestwell_item_revoked
Reset a statisticWho can moderateOff by default; only the statistics you list; sets one value to 0questwell_stat_reset

No double grants

PlayFab has no idempotency keys for grants, bans or revocations. So Questwell:

  • re-reads the player right before sending, and checks the action against PlayFab's current state;
  • sends each action once;
  • if the connection drops, reads the player again instead of resending: a currency grant counts as done only if the balance moved by exactly the amount, an item grant only if an item carries this action's marker (Questwell writes it into the item's annotation), a ban only if a new ban with this reason appeared;
  • only unbans, revocations and statistic resets, which set a state and cannot double, are resent once when a fresh read shows they did not happen;
  • refuses the same action from the same state once it is logged on the ticket (a double click, a second tab);
  • counts every grant on the ticket toward the caps, whoever made it.

If Questwell cannot tell whether an action went through, it says so, does not resend, and keeps Confirm off until you refresh.

What Questwell never does

Delete players or accounts, reset all statistics, wipe or edit player data, export anything, take currency away, refund purchases, ban IP addresses or device families, unlink platforms, change a display name or password, or read or change your title's API policy. Those calls are not in the app (the build fails if they appear).

Settings

SettingWhat it does
PlayFab title idThe short code of letters and digits. Anything else is refused and nothing is sent.
Title secret keySecure. A key made for Zendesk, with an expiry.
Title nameShown in the sidebar and notes.
Who can see players / grant / moderateagent, admin, custom role ids, group:<id>, comma separated. Admins can always do everything.
Currency capsOne line per role: agent: GC 500, GM 50, group:77: GM 200, * 100, admin: GC unlimited. Per player per ticket.
Grantable itemsOne item id per line, optional label: `starter_pack
Catalog versionEmpty uses the primary catalog.
Items per player per ticketFor non-admins (default 3; 0 = no limit).
Longest ban (days)For non-admin moderators (default 30; 0 = no limit, permanent included).
Allow ...Turn each action off. Statistic resets are off by default.
Recovery email template idOptional PlayFab email template.
Statistics that can be resetComma separated names.
Player data keys to showComma separated; read-only.
PlayFab id ticket fieldThe id of a ticket field holding a PlayFab id.

Your secret key

PlayFab title secret keys can call every Admin and Server API and cannot be limited to certain calls. Questwell keeps yours on Zendesk's servers (secure setting, header only, one address), and the guard rails above decide what agents can do with it. To limit the key itself:

  • a dedicated key you can disable alone (every change shows in PlayStream as a secret key changed event);
  • an expiration date, then rotate: new key, paste it into Questwell, disable the old one;
  • the key's IP allowlist set to Zendesk's egress ranges, so a copy of the key fails anywhere else;
  • optionally, your title's API Access Policy can deny calls such as /Admin/DeletePlayer for every key, if your own servers never use them. That is a title-wide decision for your team.

Limits

  • Inventory and currency need PlayFab's Legacy Economy. Economy v2 titles see everything else.
  • Statistics show current values, not leaderboard positions or older versions.
  • One PlayFab title per installation.
  • PlayFab's Admin API rate limits apply to the title; Questwell makes about a dozen reads when a sidebar opens and one write per action.

Questions: hello@greatwork.company, reply within 1 business day.