# Server API

Base URL: `https://pokerpro.rexplay.site/api/s2s` (sandbox). Every call carries your key:

| Header | Value |
|---|---|
| `Authorization` | `ApiKey <your S2S API key>`. The key names your tenant. Without it, or with an unknown key: `401` |
| `Content-Type` | `application/json` |

Answers are wrapped: `{"success": true, "data": { … }}`. A failure is `{"success": false, "data": null, "error": "<CODE>: <message>"}`, for example `"UNAUTHORIZED: Missing or invalid Authorization header. Expected: ApiKey <key>"`. Codes: `VALIDATION_ERROR` (400), `UNAUTHORIZED` (401), `FORBIDDEN` (403), `NOT_FOUND` (404), `CONFLICT` (409).

Amounts are integers in minor units: `"amount": 150` is 1.50. Decimals and zero are refused (`400`). `currency` is `RUB` (default) or `USD`.

| Call | Body or query | `data` in the answer |
|---|---|---|
| `POST /players` | `externalId` (your player id, up to 255 chars), `username` (3–50 chars), optional `email` | `201`: `playerId`, `token` |
| `POST /players/{playerId}/deposit` | `amount`, `currency`, `referenceId` (your id of the transfer, up to 255 chars) | `transactionId`, `status: "completed"`, `newBalance` |
| `POST /players/{playerId}/withdraw` | Same as deposit | `transactionId`, `status: "pending"`, `amount`, `currency`. `400 Insufficient balance` when the poker balance is lower |
| `GET /players/{playerId}/balance` | — | `playerId`, `available`, `reserved`, `total`, `currency`, `lastUpdatedAt` |
| `GET /players/{playerId}/history?limit=50&offset=0` | `limit` 1–100 (default 50), `offset` | `transactions[]`: `transactionId`, `type`, `status`, `amount`, `currency`, `balanceAfter`, `referenceId`, `description`, `createdAt`; `totalCount` |

- `playerId` comes from `POST /players`. Keep it next to your own player id.
- `token` from `POST /players` logs the player into the poker client: put it into the client URL (see **Embed the poker client**).
- `referenceId` is the idempotency key of a deposit: a repeated `referenceId` does not credit twice.

```bash
curl -s -X POST https://pokerpro.rexplay.site/api/s2s/players \
  -H "Authorization: ApiKey $POKERPRO_API_KEY" -H 'Content-Type: application/json' \
  -d '{"externalId":"player-42","username":"player_42"}'
# 201 {"success":true,"data":{"playerId":"<playerId>","token":"<player token>"}}

curl -s -X POST https://pokerpro.rexplay.site/api/s2s/players/<playerId>/deposit \
  -H "Authorization: ApiKey $POKERPRO_API_KEY" -H 'Content-Type: application/json' \
  -d '{"amount":10000,"currency":"USD","referenceId":"dep-000123"}'
# {"success":true,"data":{"transactionId":"dep-000123","status":"completed","newBalance":10000}}
```

**Under construction.**
