Skip to documentation
GAME_ALLIGATOR
ProductsGamificationIntegrationDemos
Let’s talk
ProductsGamificationIntegrationDemos
Let’s talk
Integration
OverviewGuidesAPI referenceResources
Integration overview
Integration architectureFundamentalsGetting startedCertification
Products
Aggregation
Part I · Fundamentals
Core flowRequest & signingEnvelope, money and data formatsErrors: one modelIdempotency & retriesRate limits, pagination, networkMoney Path Rules
Part II · Operator API
Getting startedGames APIWallet APIFree rounds APIReports APIFeatures APIEvent stream
Part III · Certification
Run the checks from the Operator PortalThe command-line tool (for your CI)The checklistCertification checklist
Part IV · Changelog and status
ChangelogDocument ControlChangelog & migration guide: Operator API v2
Appendix
Numbers to rememberWhole guide on one page
API reference
Get player balanceAuthenticate player sessionDebit player balance (bet)Credit player balance (win/bonus)Atomic debit and creditRollback transactionClose game roundSettle free-round grantReconcile uncertain transactionNon-financial notificationgetCapabilitieslistGamesupdateGamelaunchGamelaunchDemocloseSessionlistSessionslistRoundsexportRoundsgetAggregatesissueGrantlistGrantscancelGrantsubscribeackgetOperatorCapabilitiesgetGameFeatureslistBonusBuyTypesissueBonusBuycancelBonusBuygetJackpotsgetBetRangesgetRoundReplaygetRoundDetailslistCampaignscancelCampaignqueryProviderTransactionslistTournamentsgetTournamentgetLeaderboard
Gamification
Integration
Quick startWidgets on your siteSigned-in playersLaunching gamesGameplay eventsTransportsOutcomes and your obligationsGame cataloguesRewardsOnboarding and go-liveReasons, numbers, currencies
Poker
Integration
OverviewEmbed the poker clientServer APIEvents and webhooks
llms-full.txt
Start here
Aggregation / Part I · FundamentalsCore flow

Game Alligators (GA) puts game studios' games into your casino. Traffic runs in two directions, each with its own key pair. Don't mix them. Direction Who calls whom What it's for Key you use Chapter You → GA You call https://api.rexplay.sit

Aggregation / Part I · FundamentalsRequest & signing

Every call GA sends to your wallet looks like this: http POST /v2/wallet/debit HTTP/1.1 Host: wallet.operator.example Content Type: application/json X API Key Id: key live 01 X Request Id: 0198a1d0 9a30 7f08 a7dd 713e4fd33db0 Idempotency Ke

Aggregation / Part I · FundamentalsEnvelope, money and data formats

Every wallet request has the same outer shape. payload is the action specific part and the per call ids live in payload.meta . json { "request id": "0198a1d0 9a30 7f08 a7dd 713e4fd33db0", "ts": "2026 09 13T12:00:00Z", "operator id": "0197aa

Aggregation / Part I · FundamentalsErrors: one model

Your wallet's codes are Appendix A.1. What GA returns to you is Appendix A.2. Every error from /v2/aggregator/ and /v2/features/ has a non 200 HTTP status and one JSON body, Content Type: application/json : json { "code": "ERROR CODE MAINTE

Aggregation / Part I · FundamentalsIdempotency & retries

Certification tests these hardest. Build them in from day one. The full normative text is in Money Path Rules. Keep every op id with its stored answer for at least 4 months . GA resends for 72 hours, and the margin covers reconciliation dis

Aggregation / Part I · FundamentalsRate limits, pagination, network

Your wallet must answer within 5 seconds per call (§2.7). Aim for well under 1 second. GA doesn't filter your source IP on the Operator API. If you restrict inbound traffic to your wallet, allow GA's outbound addresses: 49.13.169.177 and 46

Aggregation / Part I · FundamentalsMoney Path Rules

The rules below govern the v2 wallet contract when a call goes wrong. The cases are a timeout, a duplicate, a rollback of an operation you never saw, and a win that arrives after the session closed. They're additive: GA removes or renames n

Aggregation / Part II · Operator APIGetting started

1. Get sandbox credentials. Email [integration@gamealligator.com](mailto:integration@gamealligator.com). You receive an operator profile with operator id , the Operator API key pair, and a login to https://operator.rexplay.site . There you

↑ ↓ navigate↵ openesc close
  1. Home
  2. /Integration
  3. /Gamification
  4. /Game catalogues
Gamification

Game catalogues

MarkdownSource

8.1 Your catalogue → GA Promo

If your games are not on GA, GA Promo learns them from you: promotions are set up on your games and an event is checked against them. It holds only games that do not run through GA: GA’s games reach GA Promo with GA’s own rounds, and a copy of GA’s catalogue (§8.2) is not sent here.

Sending it

POST https://<api host>/promo/v1/catalog/<source_id>
Content-Type: application/json
X-Promo-Timestamp: <unix seconds>
X-Promo-Signature: <signature>

The URL takes the source_id of your webhook transport, and the request is signed exactly like its events (§6.1): the same secret, the same ±300 s window. A catalogue cannot be sent over Kafka or RabbitMQ.

{
  "mode": "snapshot",
  "games": [
    {
      "id": "book-of-x",
      "name": "Book of X",
      "provider": "Acme Studio",
      "category": "Slots",
      "image_url": "https://cdn.acme.example/book-of-x.png"
    },
    {
      "id": "crash-9",
      "name": "Crash 9",
      "category": "Crash",
      "is_active": false
    }
  ]
}
modeListEffect
snapshotgamesyour catalogue becomes exactly games, at once; a game not listed is removed; [] clears it
upsertgamesthe listed games are added or updated; the others stay
deletegame_idsthe listed games are removed; unknown ids are ignored
Game fieldRequiredRule
idyesup to 255 bytes; the same string your events carry as game.id
nameyesnot blank, up to 255 bytes
providernoup to 255 bytes
categorynoup to 255 bytes; the category of the game
image_urlnoan absolute https URL, up to 2048 bytes
is_activenotrue by default; an inactive game is kept but not shown and not counted

One request carries up to 10 000 games or ids and 8 MiB. Fields you add beyond these are ignored; an id twice in one request is an error. JSON Schema: schema/promo-catalogue-v1.schema.json; a snapshot to try is examples/catalogue/snapshot.json, sent with the webhook examples of §6.1 by pointing PROMO_INGEST_URL at the catalogue URL.

StatusBodyMeaning
200{"source":"<source_id>","mode":"snapshot","upserted":2,"deleted":0,"total":2}applied; the same request again changes nothing and answers upserted: 0, deleted: 0
400{"error":"invalid","details":[{"index":0,"field":"name","reason":"required"}]}a game breaks a rule; nothing is written. reason: required, too_long, not_a_string, not_a_boolean, not_https_url, duplicate, not_an_object
400{"error":"malformed"}not a JSON object, an unknown mode, or the list missing
401{"error":"unauthorized"}missing or stale timestamp, missing signature, or a signature that matches no secret (§6.1)
404{"error":"unknown_source"}no active webhook connection with this source_id
413{"error":"body_too_large"} / {"source":"<source_id>","error":"batch_too_large"}over 8 MiB, or more than 10 000 games or ids
503 + Retry-After: 1{"error":"unavailable"}not applied; send the same request again

What it changes

  • Your events are held to it. Once your catalogue holds a game, a bet or settled whose game.id is not an active game of it is set aside as skipped/game_unknown. win and refund are never held back, so a refund still reverses its round. Send the catalogue before a game appears in your feed: an event set aside stays set aside when the game arrives later.
  • Promotions are set up on your games. We pick them from your catalogue for a promotion’s game lists.
  • The game widgets do not show it. game-sections and game-section show GA’s catalogue for your operator, never the one you send us.

The catalogue is one per client connection: every brand of a group shares it.

8.2 GA’s catalogue → you

If your games run through GA’s aggregation, you can keep a copy of GA’s catalogue on your side — a full snapshot once, then the changes. This is optional: the widgets read the catalogue themselves, and GA Promo needs no copy of it (§8.1).

GET https://<api host>/v1/catalog/snapshot
GET https://<api host>/v1/catalog/diff?cursor=<catalog_version or next_cursor>&limit=200
X-Public-API-Key: <your public API key>
X-Public-Timestamp: <unix seconds>
X-Public-Signature: <signature>
signature = lowercase_hex( HMAC-SHA256( secret, METHOD + path_with_query + body + X-Public-Timestamp ) )
  • path_with_query is the full request path with its query string, e.g. /v1/catalog/diff?cursor=…&limit=200; body is empty for these GETs.
  • The timestamp may be up to 5 minutes old and up to 30 seconds ahead of our clock.
  • The key needs the read:catalog scope; we issue it with your credentials (§10.2).

Snapshot — one consistent read: catalog_version (the cursor to store once you have saved the snapshot), generated_at, providers[], categories[], games[] and category_games[] (category_id, game_id, display_order).

A game’s image_url is an absolute URL of its cover for your operator, https://<api host>/public/v1/assets/games/<game id>/image?operator_id=<your GA operator id>. Every game has one: the address answers 200 with the cover, or with a placeholder marked by the response header X-Image-Fallback: true when the game has no cover yet. The same holds for payload.image_url of a game in the diff.

Diff — changes[] in order, each entity_type, entity_id, operation, updated_at, payload; upsert carries the whole current object, disable and delete are tombstones. Continue with next_cursor while has_more is true. limit is 1–1000, 200 by default. A cursor too old to serve answers 410 cursor_expired: take a new snapshot. A cursor works only with the key that received it.

PreviousOutcomes and your obligationsNextRewards
Integration support: integration@gamealligator.comIntegration center
On this page
8.1 Your catalogue → GA PromoSending itWhat it changes8.2 GA’s catalogue → you
↑ Back to top