Skip to documentation
GAME_ALLIGATOR
ProductsGamificationIntegrationDemos
Let’s talk
ProductsGamificationIntegrationDemos
Let’s talk
Integration
OverviewGuidesAPI referenceResources
Integration overview
Integration architectureFundamentalsGetting startedCertification
Products
Aggregation
Part I · Fundamentals
Core flowRequest & signingEnvelope, money and data formatsErrors: one modelIdempotency & retriesRate limits, pagination, networkMoney Path Rules
Part II · Operator API
Getting startedGames APIWallet APIFree rounds APIReports APIFeatures APIEvent stream
Part III · Certification
Run the checks from the Operator PortalThe command-line tool (for your CI)The checklistCertification checklist
Part IV · Changelog and status
ChangelogDocument ControlChangelog & migration guide: Operator API v2
Appendix
Numbers to rememberWhole guide on one page
API reference
Get player balanceAuthenticate player sessionDebit player balance (bet)Credit player balance (win/bonus)Atomic debit and creditRollback transactionClose game roundSettle free-round grantReconcile uncertain transactionNon-financial notificationgetCapabilitieslistGamesupdateGamelaunchGamelaunchDemocloseSessionlistSessionslistRoundsexportRoundsgetAggregatesissueGrantlistGrantscancelGrantsubscribeackgetOperatorCapabilitiesgetGameFeatureslistBonusBuyTypesissueBonusBuycancelBonusBuygetJackpotsgetBetRangesgetRoundReplaygetRoundDetailslistCampaignscancelCampaignqueryProviderTransactionslistTournamentsgetTournamentgetLeaderboard
Gamification
Integration
Quick startWidgets on your siteSigned-in playersLaunching gamesGameplay eventsTransportsOutcomes and your obligationsGame cataloguesRewardsOnboarding and go-liveReasons, numbers, currencies
Poker
Integration
OverviewEmbed the poker clientServer APIEvents and webhooks
llms-full.txt
Start here
Aggregation / Part I · FundamentalsCore flow

Game Alligators (GA) puts game studios' games into your casino. Traffic runs in two directions, each with its own key pair. Don't mix them. Direction Who calls whom What it's for Key you use Chapter You → GA You call https://api.rexplay.sit

Aggregation / Part I · FundamentalsRequest & signing

Every call GA sends to your wallet looks like this: http POST /v2/wallet/debit HTTP/1.1 Host: wallet.operator.example Content Type: application/json X API Key Id: key live 01 X Request Id: 0198a1d0 9a30 7f08 a7dd 713e4fd33db0 Idempotency Ke

Aggregation / Part I · FundamentalsEnvelope, money and data formats

Every wallet request has the same outer shape. payload is the action specific part and the per call ids live in payload.meta . json { "request id": "0198a1d0 9a30 7f08 a7dd 713e4fd33db0", "ts": "2026 09 13T12:00:00Z", "operator id": "0197aa

Aggregation / Part I · FundamentalsErrors: one model

Your wallet's codes are Appendix A.1. What GA returns to you is Appendix A.2. Every error from /v2/aggregator/ and /v2/features/ has a non 200 HTTP status and one JSON body, Content Type: application/json : json { "code": "ERROR CODE MAINTE

Aggregation / Part I · FundamentalsIdempotency & retries

Certification tests these hardest. Build them in from day one. The full normative text is in Money Path Rules. Keep every op id with its stored answer for at least 4 months . GA resends for 72 hours, and the margin covers reconciliation dis

Aggregation / Part I · FundamentalsRate limits, pagination, network

Your wallet must answer within 5 seconds per call (§2.7). Aim for well under 1 second. GA doesn't filter your source IP on the Operator API. If you restrict inbound traffic to your wallet, allow GA's outbound addresses: 49.13.169.177 and 46

Aggregation / Part I · FundamentalsMoney Path Rules

The rules below govern the v2 wallet contract when a call goes wrong. The cases are a timeout, a duplicate, a rollback of an operation you never saw, and a win that arrives after the session closed. They're additive: GA removes or renames n

Aggregation / Part II · Operator APIGetting started

1. Get sandbox credentials. Email [integration@gamealligator.com](mailto:integration@gamealligator.com). You receive an operator profile with operator id , the Operator API key pair, and a login to https://operator.rexplay.site . There you

↑ ↓ navigate↵ openesc close
  1. Home
  2. /Integration
  3. /Aggregation
  4. /Idempotency & retries
Aggregation

Idempotency & retries

MarkdownSource

Idempotency: the four rules that protect money

Certification tests these hardest. Build them in from day one. The full normative text is in Money Path Rules.

Rule 1. A repeated op_id gets the same answer

Keep every op_id with its stored answer for at least 4 months. GA resends for 72 hours, and the margin covers reconciliation disputes.

  • Same op_id, same content: return the stored answer, move no money. Even if the balance is now too low or the session expired.
  • Same op_id, different content (player, operation type, currency, amount with exponent, round, original, grant): refuse with ERROR_CODE_IDEMPOTENCY_CONFLICT, move no money.
  • Two identical requests at the same moment: the second waits for the first and gets the same answer. Never apply twice.

Rule 2. Check things in this order

signature -> schema -> op_id lookup -> player + currency/exponent
  -> [bets only: session, player status, limits, balance]
  -> round state -> apply and store the answer in one atomic step

The op_id lookup comes before session, player, and balance checks. Otherwise a repeated bet answers “insufficient funds” or “session expired” where it must answer the stored success, and you and GA disagree about whether the bet exists.

Rule 3. Never refuse a win, a rollback, or a grant settlement for session, block, or limits

A win can arrive hours after the session ended, for a blocked player, or past a deposit limit. Accept it. The only final refusals for a credit are: player not found, currency mismatch, invalid request, idempotency conflict, unknown original, already rolled back. After any other refusal, GA resends the credit for 72 hours, and then it lands in manual review.

A promo, bonus, jackpot, or tournament payout may arrive with no bet in the round and with no session. Don’t require either.

Rule 4. A rollback of something you never saw is a success, and you remember it

If a rollback names an original_op_id you don’t have:

  1. Return status: ok with "original_found": false. Move no money.
  2. Store that original_op_id as “rolled back”.
  3. If the original debit or credit arrives later, refuse it with ERROR_CODE_ALREADY_ROLLED_BACK.

Never return ERROR_CODE_UNKNOWN_ORIGINAL to a rollback. Step 2 is what stops you from charging a player for a bet GA already cancelled.

Timeouts and retries

The most important number: GA waits 5 seconds for each wallet call. Answer faster than that, or GA treats the call as lost.

GA sees only two kinds of outcome:

  • Refused. A valid envelope with a non-retryable code, such as INSUFFICIENT_FUNDS. Final: GA doesn’t resend that op_id.
  • No answer. A timeout, a dropped connection, a bare HTTP status with no envelope, or a valid envelope with a retryable code (RATE_LIMITED, MAINTENANCE, INTERNAL). GA doesn’t know whether you applied the operation and retries with the same op_id and a new request_id.
OperationOn “no answer” GA does
debit, debit_creditUp to 4 attempts, 100 ms, 500 ms, and 2 s apart, all inside one 8-second budget for the bet. Each attempt waits at most 5 s or what’s left of the budget, whichever is shorter. GA starts a retry only if the budget still holds the pause before it. So a wallet that doesn’t answer at all gets 2 attempts (5 s, then the rest of the 8 s). All 4 happen only when your wallet answers fast with a retryable code. Still nothing: the bet fails towards the game and GA sends one rollback for that op_id.
credit, settle_grantThe same quick attempts, then a background resend with the same op_id for up to 72 hours. Backoff starts at 1 second and doubles up to a cap of 10 minutes. The limit is the 72 hours, not a number of attempts. GA never rolls back a win.
rollbackThe same quick attempts, then the same 72-hour resend. Stops at the first valid envelope: success or refusal.
notifyOne attempt, no retry on HTTP/JSON. On gRPC it gets the same quick attempts as every other call.

GA honours a Retry-After header or retry_after field, capped at 10 seconds inside the quick attempts. When the 72 hours are over, GA flags the operation for manual review and alerts its team. GA never drops anything silently.

What this means for your wallet:

  1. A bet can reach you after GA already rolled it back. Rule 4 (chapter 3) handles it.
  2. A win can reach you days later, after the session ended. Rule 3 handles it.
  3. Every retry carries the same op_id, so Rule 1 makes retries harmless.
PreviousErrors: one modelNextRate limits, pagination, network
Integration support: integration@gamealligator.comIntegration center
On this page
Idempotency: the four rules that protect moneyRule 1. A repeated op_id gets the same answerRule 2. Check things in this orderRule 3. Never refuse a win, a rollback, or a grant settlement for session, block, or limitsRule 4. A rollback of something you never saw is a success, and you remember itTimeouts and retries
↑ Back to top