Real-name verification in China — apps and games gate
Real-name verification is a Mainland China launch and ops gate for apps and games — map entity path, verification level, and anti-addiction rails before store submission.
Real-name verification is a Mainland China launch and ops gate for apps and games — not an optional signup polish. Before you promise China store dates, map three decisions: whether your product triggers real-identity duties, which verification level clears that risk, and whether games must connect the National Anti-Addiction Real Name Verification System. Entity path and approved China identity APIs come before SDK work.

What real-name verification means for apps and games
Hard names your launch program will use:
- Real-name verification (实名认证) — Platforms must collect, verify, and retain authentic end-user identity before granting covered services. This is user identity, not only company KYC for your developer account.
- Cybersecurity Law baseline — Network operators must require real identity when providing covered services (including information publication and instant messaging); without it, they must not provide the service (CAC text).
- PIPL processing rules — Identity data is personal information. Collection must stay lawful, necessary, and secure under the Personal Information Protection Law.
- Games hard gate — Online games must connect the National Press and Publication Administration (NPPA) anti-addiction real-name verification system, require real identity for all users, and must not serve unverified users — including guest modes (NPPA notice; operator portal: wlc.nppa.gov.cn).
- Factor tiers (industry practice) — Two-factor (name + ID), three-factor (+ phone), four-factor (+ bank), plus biometric / liveness for higher-risk surfaces. Choose the minimum that clears your category.
- Organizing path — Approved China cloud identity APIs and NPPA game access typically need a Chinese entity or contracted landing partner. A global developer account alone is not an implementation plan.
- Common myth — “Global OAuth / email signup is enough for China stores.” Store review and live enforcement look for China-grade real-identity rails, especially for games.
Vocabulary first. Next: what must exist before identity APIs are executable.
What must exist before you wire identity APIs
Missing any of these stops your product team before a real identity integration — not after SDKs are already in the China build.
| Precondition | Why your process stalls |
|---|---|
| Product class locked — utility app vs game (and which surfaces need identity) | Wrong class → wrong rails (NPPA game system vs ordinary identity APIs) |
| Mainland China entity or China landing partner | Cloud identity contracts, NPPA access, and store accountability need a China organizing path |
| Verification level decision — 2 / 3 / 4 factor ± biometric | Under-verify fails review; over-collect creates PIPL and UX failure |
| China-reachable identity stack — approved Mainland China cloud identity APIs | Overseas KYC vendors usually cannot clear China real-name duties |
| Data + privacy pack — purpose, retention, user notices in Chinese | PIPL and store questionnaires reject vague global privacy copy |
| For games: ISBN / publisher path + anti-addiction ops willingness | Real-name without license and live minor limits is not a durable game launch — see China game ISBN and Publish a game in China |
Chinese-language consoles, enterprise verification, and legal-person rails sit outside a global Auth0 / Firebase checklist. Filings that still apply (mobile app filing, store packages) belong in the same program — see Publish an app in China and China mobile app filing.
Gate map: classify, level, integrate, operate
Use this as a launch gate map. Stages are decisions, not console click-paths.
| Stage | Decision / outcome |
|---|---|
| 1. Classify the product | Utility / SaaS companion vs game; which features publish content, chat, payments, or UGC |
| 2. Map real-name triggers | Covered Cybersecurity Law services? Game distribution in China stores? Payment / livestream / creator surfaces? |
| 3. Lock organizing path | Chinese entity or contracted partner that can hold identity API contracts and (for games) NPPA access |
| 4. Choose verification level | Minimum factor tier + biometric only when the risk surface requires it |
| 5. Integrate China identity rails | Approved Mainland China identity APIs; for games, NPPA anti-addiction system connection and minor time / spend rules |
| 6. Align store + privacy story | Chinese metadata, privacy policy, and questionnaires match the real identity UX reviewers will hit |
| 7. Operate after listing | Failure handling, re-verification, age gates, audit logs — real-name is live ops, not a one-time SDK |
Channel context after identity rails: China app stores directory for store selection; paid acquisition claims stay under China advertising law.
Why a real-name gap blocks store and live ops
Unclassified game → utility identity only. A title that plays, monetizes, or markets as a game but ships ordinary email signup fails NPPA and store expectations even if mobile app filing looks complete.
Global OAuth → China real-identity reject. Store and regulator checks look for China-grade verification, not a mirrored Western login. Guest mode on games is a hard fail under the NPPA notice.
Entity missing → API contract stall. China cloud identity and NPPA enterprise access stop before engineering when there is no Chinese applicant or partner path.
ISBN unfinished → anti-addiction without a publish vehicle. Games need the publisher / ISBN spine before durable paid listings; real-name alone does not replace ISBN.
Over-collection → PIPL and drop-off. Four-factor plus face for a low-risk utility creates consent, retention, and conversion failures that look like “China UX is hard” when the level choice was wrong.
Store pack ≠ live journey. Screenshots that show real-name while the China build still allows unverified play trigger removals after launch — the same failure mode as soft-launching games without approvals (Publish a game in China).
Where real-name programs stall product teams
- Treating real-name as a signup A/B test — it is a compliance and store gate, not a conversion experiment.
- Starting with SDK docs before entity and level decisions — the stall is usually contracting and classification, not REST syntax.
- Ignoring the game vs app fork — NPPA anti-addiction is not optional for China-distributed online games.
- Copying Western KYC vendors into the China build — approved Mainland China identity APIs and data residency expectations differ.
- Filing and store work without identity ops — mobile app filing and multi-store packages still fail when reviewers cannot complete a real-name journey.
- Broker promises of “real-name in a week” — diligence who holds the cloud contract, who accesses NPPA, what happens on reject, and who owns minor-protection live ops.
When you need a China landing partner for real-name rails
Most product teams exploring Mainland China entry need a China landing partner to turn real-name verification into an executable launch sequence — entity or publisher path, approved identity API contracting, game anti-addiction connection, Chinese privacy materials, and store-aligned identity UX — not a longer statute reading list. Your team still owns product classification and the minimum verification level; the partner path makes China identity rails and live ops workable when those rails are not already in-house.
What we can offer?
Real-name work is a gate map across product class, verification level, and game anti-addiction rails — not one SDK ticket. Chinaready helps your product team see which identity gates block the Mainland China launch and run them beside filing and distribution:
- China Readiness Assessment — Inventory which surfaces trigger real-name duties, flag game vs app forks, and sequence identity rails with ISBN, app filing, and store gates the board can fund.
- China Access Acceleration — Keep China review and identity test paths reachable from Mainland China so store checks match the journey users actually hit.
- China Product Hosting — Place China-critical identity and account stacks where Mainland China–approved APIs, data expectations, and launch evidence describe one coherent path.
- Mobile App Distribution — Align store packages, real-name UX, and (for games) anti-addiction proof so distribution and identity stories do not diverge after listing.
Contact us when you need a real-name verification gate map for the Mainland China app or game launch you plan to fund.
Frequently asked questions
What is real-name verification in China for apps and games?
Real-name verification (实名认证) requires platforms to collect and verify authentic user identity before granting service access in Mainland China. For many apps it is a launch and ops gate tied to Cybersecurity Law duties and PIPL processing rules; for games it also means connecting to the National Press and Publication Administration anti-addiction real-name system.
Do all apps need real-name verification in Mainland China?
Not every feature on every product. Network operators must require real identity for covered services such as information publication and instant messaging under the Cybersecurity Law. Games distributed through China stores must real-name all users and connect the anti-addiction system. Classify your product and risk surface before you pick an identity API tier.
How is game real-name verification different from a utility app?
Monetized games usually need ISBN / publishing approval first, then store packages that prove National Anti-Addiction Real Name Verification System access — no guest mode for unverified users, plus minor time and spend limits. Utility apps may need identity rails for chat, UGC, or payments without that NPPA game system, but still need a China organizing path for approved identity APIs.
Can we use global OAuth or email signup instead?
Usually no for China-facing apps and games that trigger real-name duties. Overseas identity providers and email-only signup do not clear Cybersecurity Law real-identity requirements or NPPA anti-addiction verification for games. Plan China-approved identity verification APIs under a Chinese entity or partner path.
What verification levels do product teams choose?
Common industry tiers are two-factor (name + ID number), three-factor (plus phone), four-factor (plus bank account), and biometric / liveness stacks on top. Games and higher-risk surfaces usually need stronger checks. Pick the minimum level that clears your category — over-collection creates PIPL and UX risk.
Can product teams finish real-name verification without Mainland China ops?
Usually no. You need a Mainland China entity or landing-partner path, approved China cloud identity APIs, Chinese-language consoles, and — for games — NPPA anti-addiction system access beside ISBN and store packages.


