• Home
  • Blog
  • What’s New in AGS: September 2026 Product Updates

What’s New in AGS: September 2026 Product Updates

Banning a cheater is the easy part. Keeping them banned is where it gets expensive. On a free-to-play PC game a new Steam or Epic account costs nothing, so an account ban can buy you an hour before the same player is back on the same machine under a new name. And while they’re gone, the score they cheated their way to can keep sitting on your leaderboard, pushing honest players down a rank.

Both of those got fixed this cycle. Device bans in AccelByte Gaming Services (AGS) now cover Steam and Epic Games, and leaderboards can drop hidden players on the server. After that you’ll find the rest of what shipped between AGS 2026.3 and 2026.5.1, a new AGS CLI release, and our AI plugins.

Device Bans Now Cover Steam and Epic

Why Account Bans Leak on PC

Console already had this covered. AGS tracks Xbox and PlayStation devices automatically, so a device ban there stops a player at the hardware, not the account. PC didn’t have an equivalent, and PC is where alt accounts are cheapest.

Say you ban a player at 9pm for running an aimbot. At 10pm a fresh Steam account signs in from the same PC, goes through your login flow like any new player, and lands in matchmaking. Nothing on the backend connects the two, because the only thing you banned was an account ID. Your support team hears about it the next day from a player report, bans the new account, and the loop starts again.

How PC Device Bans Work

Device tracking is now available for Steam and Epic Games. You switch it on per platform in the Admin Portal under Foundations → Banned Devices → Settings. Once tracking is on, new sign-ins on that platform record the device they came from, and device bans start being enforced against it.

image1-3From there, a ban follows the machine rather than the account. Ban a device and it’s blocked on every PC platform you track for that game, so the player who gives up on Steam and tries Epic runs into the same wall.

Account ban vs. device ban on PC
An account ban stops one login. A device ban stops the machine.
 
Account ban only
What PC looked like before
Player’s PC (not tracked)
Steam account ABanned
Steam account B (new)Signs in
Epic account C (new)Signs in
Every new account is a fresh start.
 
Device ban
Tracking on for Steam and Epic
Player’s PC: device banned
Steam account ABlocked
Steam account B (new)Blocked
Epic account C (new)Blocked
The ban follows the machine across tracked platforms.

Games on the AGS SDK send the device ID at login automatically, so most teams won’t write new integration code for this. You can also require a device ID to sign in on each platform, which closes the gap where a login simply doesn’t send one.

image2

Before You Turn It On

A few things worth knowing first:

  • Keep banning accounts too.
    Device bans back up account bans, they don’t replace them. A player on a second machine is only covered by the account ban.

  • Check your SDK version.
    Device bans need a supported SDK that sends the device ID at login. Confirm that before you switch tracking on.

  • Don’t require a device ID too early.
    Turn on Require device ID to sign in only once every live build sends one, or players on older builds may not be able to sign in.

  • Give it a few minutes.
    Settings changes can take up to five minutes to apply across all servers.

It’s also worth being honest about what this does and doesn’t buy you. No device identifier lasts forever. New hardware, a second PC, or a determined enough cheater will get around it eventually. What changes is the cost of coming back: it goes from “make a free account” to “find another machine,” and that’s a much bigger ask.

Availability

Private Cloud, from AGS 2026.5. Not yet available on Shared Cloud. Read the release notes.

Hidden Players Drop Off the Leaderboard

Hiding a player from a leaderboard used to be half a fix. The flag was set on the backend, but each game client had to filter that player out of what it received. Miss it in one client build and the hidden player shows up again. Filter them out but forget to renumber, and the player who should now be 4th still reads 5th.

With Hidden Player Filtering on, AGS does that work on the server. A hidden or moderated player’s score stops holding a rank before the response reaches the game, and everyone below them moves up.

image5

It’s a per-leaderboard setting and it’s off by default for new and existing leaderboards, so nothing changes until you flip it. Open a leaderboard in the Admin Portal under Online → Leaderboards and turn on Hidden Player Filtering.

image4-1If your client already filters hidden players, turning this on doesn’t break anything. The client-side filter just stops finding anyone to remove, and you can delete that code whenever it suits you.

Availability

Shared Cloud and Private Cloud, from AGS 2026.4. Read the release notes.

Also Shipped Recently

The rest of what landed between AGS 2026.3 and 2026.5.1. Each item links to its entry in the release notes.

Featured Updates

AGS CLI v0.5.1: Pen-Test Extend Apps from Terminal

The AGS CLI puts every AGS API behind one command shape, ags <service> <resource> <method>, and since v0.5.0 it covers Extend and AMS image uploads too. We wrote about why it exists in Beyond the Chat Box. The short version: the same command works from your terminal, a CI job, or an AI agent.

image6The headline in v0.5.1 is security assessments. Point the CLI at an Extend app and it finds the endpoints worth testing and the permission each one needs, then requests a pen-testing engagement and downloads the finished report as PDF or Markdown.

bash
ags extend security-assessment request --wait
ags extend security-assessment result

Two details matter if you plan to put this in a pipeline. Endpoints that accept PUT, PATCH, or DELETE are listed and confirmed before anything is sent, because the assessment may generate test cases that modify or delete data through them, so point it at a dev or staging app before production. And --wait polls every 10 seconds until the engagement completes or fails, capped at 30 minutes by default, so a CI job can block on it.

Also in this release:

  • ags update tells you when a newer release exists, and ags update --install upgrades your copy in place. Nothing updates unless you run it.

  • ags auth token prints the current session’s access token and nothing else, so another tool can reuse your login instead of running its own.

  • --wait on the Extend app lifecycle commands, which now call the CSM v5 API. Existing IAM roles keep working. A wait that times out exits with code 6 rather than 3, so CI can tell “still rolling out” from “failed.”

bash
# Reuse the CLI's login from another tool
curl -H "Authorization: Bearer $(ags auth token)" "$AGS_BASE_URL/iam/v3/public/users/me"

One change can break a script. ags ams upload now prints its result block, including the Image ID, to stdout and the “uploaded” banner to stderr. It used to be the other way round, so a redirect saved the banner and lost the Image ID. If you capture that output, read the Image ID from stdout. --format json is unchanged.

The ags extend and ags ams commands are still in early preview, so flags may change before you build automation on them.

To install fresh, or to upgrade from v0.5.0, run the installer. From v0.5.1 on, ags update --install does it for you.

 
# macOS and Linux
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/AccelByte/accelbyte-ags-cli/releases/latest/download/accelbyte-ags-cli-installer.sh | sh

# Windows (PowerShell)
powershell -ExecutionPolicy Bypass -c "irm https://github.com/AccelByte/accelbyte-ags-cli/releases/latest/download/accelbyte-ags-cli-installer.ps1 | iex"

The CLI sends anonymous usage telemetry. Set DO_NOT_TRACK=1 to turn it off. Full details are in the v0.5.1 release notes.

AI Plugins for Your Coding Agent

AccelByte AI Plugins are skills for Claude Code, Codex, Cursor, and other agents. They keep your agent working from real AGS references instead of guessing at API shapes that changed two SDK versions ago.

  • /ags init scans your project, detects the engine, and walks you through SDK, CLI, MCP server, and IAM client setup.

  • /ags-extend helps you pick an Extend pattern, then scaffold, test, and deploy the service.

  • /teammate health-check reviews your AGS integration for unfinished work, deprecated APIs, and unsafe token handling, and drops any finding it can’t back with a source. It’s in early access, and we wrote up how it works.

 
# Claude Code
/plugin marketplace add AccelByte/ai-plugins
/plugin install accelbyte-ai-plugins@accelbyte

# Any other agent
npx skills add AccelByte/ai-plugins

Try It, Then Tell Us

If you’re on Private Cloud, PC device bans are one Settings page away. If you’re on Shared Cloud, hidden player filtering is a toggle on any leaderboard you already have. Either way, the fastest way to shape the next one of these posts is to tell us what broke, what’s missing, or what you worked around. Find us on Discord.

Build on the latest AGS

Device bans, server-side leaderboard filtering, the CLI, and the AI plugins all run against the same AGS backend. It’s free on Shared Cloud until your game hits 30 concurrent users, so you can start building against it today, or talk to us about Private Cloud if PC device bans are the part you need now.

You're almost signed up!

Verify your account by following the instructions sent to .

If you still haven't received an email, please check your spam folder.

Please provide a valid name.

Please provide a valid email address.

Please provide a valid studio name.

You must agree to the policy to continue.

Talk to us

Table of Contents

Bring your first player online today.

Get started for free, and scale as your game grows.