Skip to documentation
GAME_ALLIGATOR
ProductsGamificationIntegrationDemos
Let’s talk
ProductsGamificationIntegrationDemos
Let’s talk
Integration
OverviewGuidesAPI referenceResources
Integration overview
Integration architectureFundamentalsGetting startedCertification
Products
Aggregation
Part I · Fundamentals
Core flowRequest & signingEnvelope, money and data formatsErrors: one modelIdempotency & retriesRate limits, pagination, networkMoney Path Rules
Part II · Operator API
Getting startedGames APIWallet APIFree rounds APIReports APIFeatures APIEvent stream
Part III · Certification
Run the checks from the Operator PortalThe command-line tool (for your CI)The checklistCertification checklist
Part IV · Changelog and status
ChangelogDocument ControlChangelog & migration guide: Operator API v2
Appendix
Numbers to rememberWhole guide on one page
API reference
Get player balanceAuthenticate player sessionDebit player balance (bet)Credit player balance (win/bonus)Atomic debit and creditRollback transactionClose game roundSettle free-round grantReconcile uncertain transactionNon-financial notificationgetCapabilitieslistGamesupdateGamelaunchGamelaunchDemocloseSessionlistSessionslistRoundsexportRoundsgetAggregatesissueGrantlistGrantscancelGrantsubscribeackgetOperatorCapabilitiesgetGameFeatureslistBonusBuyTypesissueBonusBuycancelBonusBuygetJackpotsgetBetRangesgetRoundReplaygetRoundDetailslistCampaignscancelCampaignqueryProviderTransactionslistTournamentsgetTournamentgetLeaderboard
Gamification
Integration
Quick startWidgets on your siteSigned-in playersLaunching gamesGameplay eventsTransportsOutcomes and your obligationsGame cataloguesRewardsOnboarding and go-liveReasons, numbers, currencies
Poker
Integration
OverviewEmbed the poker clientServer APIEvents and webhooks
llms-full.txt
Start here
Aggregation / Part I · FundamentalsCore flow

Game Alligators (GA) puts game studios' games into your casino. Traffic runs in two directions, each with its own key pair. Don't mix them. Direction Who calls whom What it's for Key you use Chapter You → GA You call https://api.rexplay.sit

Aggregation / Part I · FundamentalsRequest & signing

Every call GA sends to your wallet looks like this: http POST /v2/wallet/debit HTTP/1.1 Host: wallet.operator.example Content Type: application/json X API Key Id: key live 01 X Request Id: 0198a1d0 9a30 7f08 a7dd 713e4fd33db0 Idempotency Ke

Aggregation / Part I · FundamentalsEnvelope, money and data formats

Every wallet request has the same outer shape. payload is the action specific part and the per call ids live in payload.meta . json { "request id": "0198a1d0 9a30 7f08 a7dd 713e4fd33db0", "ts": "2026 09 13T12:00:00Z", "operator id": "0197aa

Aggregation / Part I · FundamentalsErrors: one model

Your wallet's codes are Appendix A.1. What GA returns to you is Appendix A.2. Every error from /v2/aggregator/ and /v2/features/ has a non 200 HTTP status and one JSON body, Content Type: application/json : json { "code": "ERROR CODE MAINTE

Aggregation / Part I · FundamentalsIdempotency & retries

Certification tests these hardest. Build them in from day one. The full normative text is in Money Path Rules. Keep every op id with its stored answer for at least 4 months . GA resends for 72 hours, and the margin covers reconciliation dis

Aggregation / Part I · FundamentalsRate limits, pagination, network

Your wallet must answer within 5 seconds per call (§2.7). Aim for well under 1 second. GA doesn't filter your source IP on the Operator API. If you restrict inbound traffic to your wallet, allow GA's outbound addresses: 49.13.169.177 and 46

Aggregation / Part I · FundamentalsMoney Path Rules

The rules below govern the v2 wallet contract when a call goes wrong. The cases are a timeout, a duplicate, a rollback of an operation you never saw, and a win that arrives after the session closed. They're additive: GA removes or renames n

Aggregation / Part II · Operator APIGetting started

1. Get sandbox credentials. Email [integration@gamealligator.com](mailto:integration@gamealligator.com). You receive an operator profile with operator id , the Operator API key pair, and a login to https://operator.rexplay.site . There you

↑ ↓ navigate↵ openesc close
  1. Home
  2. /Integration
  3. /Aggregation
  4. /Games API
Aggregation

Games API

MarkdownSource

You call GA: launch, catalog, free rounds, reports

Base URL https://api.rexplay.site (sandbox) or https://api.game-alligator.com (production). Every call is POST with a JSON body and the signature of §2.3. Paths are /v2/aggregator/<call> in snake_case. The sandbox also accepts the proto method name (/v2/aggregator/LaunchGame, case-sensitive). Sign exactly the path you call. Success is 200 with the call’s own response. Amounts are strings in minor units (§2.6). Timestamps are Request for Comments (RFC) 3339. Paginated calls take page: {cursor, limit} and return page: {next_cursor, has_more, total_count}. limit defaults to 50, with a maximum of 500.

Start from Postman: import postman/GA_Aggregator_API_v2.postman_collection.json with postman/GA_Sandbox_v2.postman_environment.json, set ga_api_key_id and ga_hmac_secret, and send launch_game first. The pack with both files is /downloads/GA_Operator_Integration_Pack_v2.0.0.zip on the docs site.

Launch a game

POST /v2/aggregator/launch_game

FieldRequiredMeaning
player_refyesYour player id. Opaque to GA, returned unchanged in every wallet call.
game_idyesFrom the catalog (§4.3).
currencyyesThe currency of this session. Uppercase code. GA takes the exponent from your onboarding profile.
tokenyesYour launch token. GA stores it and sends it back as launch_token in every wallet call of this session. It’s how you tie a wallet call to a player session.
return_urlnoWhere the game’s “back to lobby” button leads.
attributesnoString map. attributes["language"] = two-letter lowercase code ("de"). Anything else falls back to "en".

Response: session_id, launch_url, expires_at (the session lives 24 hours), plus running total_bet, total_win, rounds.

launch_game is idempotent by token while the session is open. The same token with the same player, game, and currency returns the first response again: the same session_id, launch_url, and expires_at. So a page reload doesn’t open a second session, and GA doesn’t call the game provider again.

GA refuses the same token with 409 ERROR_CODE_IDEMPOTENCY_CONFLICT (session_token_conflict) in these cases:

  • the token comes with another player, game, or currency;
  • the session of that token is closed: by close_session, or by a newer launch of the same game for the same player, because a launch closes that player’s earlier sessions of the game;
  • the session of that token is past its expires_at.

GA never reopens a closed session. Don’t retry the 409: launch again with a fresh token. If the first launch with the token is still running, GA answers 503 ERROR_CODE_INTERNAL with retryable: true (launch_in_progress). Retry with the same token to get the first response. Use a fresh token for every new session.

Open launch_url in an iframe or by redirect. Both work. The URL is single-session: launch again for a new session. Device, IP, and country aren’t fields on this call.

If you embed launch_url in an iframe, set a sandbox attribute. Don’t omit it, and don’t use an unrestricted frame. launch_url always points to a real address that you load via src, never as inline HTML, so the minimal working set is:

<iframe
  src="https://play.rexplay.site/s/0198a1cb-4f37-7ee8-8e7d-08d39925aec0"
  sandbox="allow-scripts allow-same-origin allow-forms allow-popups"
  allow="autoplay; fullscreen"
  allowfullscreen>
</iframe>
  • allow-scripts—the game is a script-driven client. Without it, nothing runs.
  • allow-same-origin—the frame loads from src, so this keeps it same-origin with GA’s domain, not yours, which the game’s own websocket connection and storage need. It doesn’t weaken your page’s origin boundary.
  • allow-forms—some game and payment flows submit forms inside the frame.
  • allow-popups—rule and payment/cashier windows some games open are new browser contexts, not just navigation inside the frame.
  • allow="autoplay; fullscreen" and allowfullscreen—background/video-driven games and fullscreen mode need these. Playback or fullscreen silently fails without them.
{
  "player_ref": "player-10428",
  "game_id": "0198a2aa-1111-7000-a000-000000000077",
  "currency": "EUR",
  "token": "lt-abcdef123456",
  "return_url": "https://casino.example/lobby",
  "attributes": {
    "language": "de"
  }
}
{
  "session_id": "0198a1cb-4f37-7ee8-8e7d-08d39925aec0",
  "player_ref": "player-10428",
  "game_id": "0198a2aa-1111-7000-a000-000000000077",
  "currency": "EUR",
  "launch_url": "https://play.rexplay.site/s/0198a1cb-4f37-7ee8-8e7d-08d39925aec0",
  "expires_at": "2026-09-14T12:00:00Z",
  "total_bet": {
    "currency": "EUR",
    "amount": "0",
    "exponent": 2
  },
  "total_win": {
    "currency": "EUR",
    "amount": "0",
    "exponent": 2
  },
  "rounds": 0
}

Launch a demo

POST /v2/aggregator/launch_demo with game_id and optional return_url. No player, no token, no currency, no session: a demo never reaches your wallet. Response: launch_url, game_id. Games with demo_supported: false refuse with 412 (DEMO_NOT_SUPPORTED, Appendix A.2).

Catalog

POST /v2/aggregator/games with optional filters query, vertical, category, provider, tags[], updated_since, page.

Each Game carries: game_id, title, vertical, category, provider, enabled, demo_supported, wager_weight_bp, tags[], assets[], limits, fee_bp, fee_source, rtp, features[], updated_at. wager_weight_bp is how much a bet on this game contributes to bonus wagering and loyalty accrual, in basis points, 0 to 10000. 10000 bp = 100 %, 1000 bp = 10 %, 0 bp = 0 %. assets[] is {kind, url} with kinds banner, thumbnail, background, icon. limits is min_bet, max_bet, max_win. fee_bp is GA’s fee for this game on your brand, in basis points, 0 to 10000. It’s an optional field—present only once GA has resolved a fee for this game/brand pair, absent otherwise, so check presence rather than treating “absent” as 0. fee_source is which fee-ladder tier produced fee_bp: FEE_SOURCE_UNSPECIFIED, FEE_SOURCE_PROVIDER, FEE_SOURCE_GAME. rtp is the return to player (RTP) in percent, for example 96.5. The wire value is also 0 when GA has recorded no RTP for this game, so a 0 doesn’t mean “0 % RTP”.

features[] is always empty in this call. Call get_game_features (§6.1) to get a game’s actual features[].

Practical rules:

  • Poll with updated_since (the last updated_at you stored) rather than reloading the whole catalog. A daily full reload is enough.
  • Download assets[].url images to your own content delivery network (CDN) and serve them from there. Don’t hotlink them from your lobby.
  • Show only enabled: true games. A disabled game refuses to launch.

Other catalog calls are capabilities, operator_capabilities, and update_game. capabilities is what GA supports for you: currencies, settlement modes, streaming. operator_capabilities is what GA has on record for your wallet: wallet_capabilities with rpcs, credit_kinds, debit_modes, notify_kinds, authenticate, and supported_transports. update_game changes your own settings on a game, partial update with update_mask and a reason for audit.

Reference

  • POST /v2/aggregator/games — listGames: parameters, errors, code samples, try it
  • POST /v2/aggregator/launch_game — launchGame: parameters, errors, code samples, try it
  • POST /v2/aggregator/launch_demo — launchDemo: parameters, errors, code samples, try it
PreviousGetting startedNextWallet API
Integration support: integration@gamealligator.comIntegration center
On this page
You call GA: launch, catalog, free rounds, reportsLaunch a gameLaunch a demoCatalogReference
↑ Back to top