Skip to documentation
GAME_ALLIGATOR
ProductsGamificationIntegrationDemos
Let’s talk
ProductsGamificationIntegrationDemos
Let’s talk
Integration
OverviewGuidesAPI referenceResources
Integration overview
Integration architectureFundamentalsGetting startedCertification
Products
Aggregation
Part I · Fundamentals
Core flowRequest & signingEnvelope, money and data formatsErrors: one modelIdempotency & retriesRate limits, pagination, networkMoney Path Rules
Part II · Operator API
Getting startedGames APIWallet APIFree rounds APIReports APIFeatures APIEvent stream
Part III · Certification
Run the checks from the Operator PortalThe command-line tool (for your CI)The checklistCertification checklist
Part IV · Changelog and status
ChangelogDocument ControlChangelog & migration guide: Operator API v2
Appendix
Numbers to rememberWhole guide on one page
API reference
Get player balanceAuthenticate player sessionDebit player balance (bet)Credit player balance (win/bonus)Atomic debit and creditRollback transactionClose game roundSettle free-round grantReconcile uncertain transactionNon-financial notificationgetCapabilitieslistGamesupdateGamelaunchGamelaunchDemocloseSessionlistSessionslistRoundsexportRoundsgetAggregatesissueGrantlistGrantscancelGrantsubscribeackgetOperatorCapabilitiesgetGameFeatureslistBonusBuyTypesissueBonusBuycancelBonusBuygetJackpotsgetBetRangesgetRoundReplaygetRoundDetailslistCampaignscancelCampaignqueryProviderTransactionslistTournamentsgetTournamentgetLeaderboard
Gamification
Integration
Quick startWidgets on your siteSigned-in playersLaunching gamesGameplay eventsTransportsOutcomes and your obligationsGame cataloguesRewardsOnboarding and go-liveReasons, numbers, currencies
Poker
Integration
OverviewEmbed the poker clientServer APIEvents and webhooks
llms-full.txt
Start here
Aggregation / Part I · FundamentalsCore flow

Game Alligators (GA) puts game studios' games into your casino. Traffic runs in two directions, each with its own key pair. Don't mix them. Direction Who calls whom What it's for Key you use Chapter You → GA You call https://api.rexplay.sit

Aggregation / Part I · FundamentalsRequest & signing

Every call GA sends to your wallet looks like this: http POST /v2/wallet/debit HTTP/1.1 Host: wallet.operator.example Content Type: application/json X API Key Id: key live 01 X Request Id: 0198a1d0 9a30 7f08 a7dd 713e4fd33db0 Idempotency Ke

Aggregation / Part I · FundamentalsEnvelope, money and data formats

Every wallet request has the same outer shape. payload is the action specific part and the per call ids live in payload.meta . json { "request id": "0198a1d0 9a30 7f08 a7dd 713e4fd33db0", "ts": "2026 09 13T12:00:00Z", "operator id": "0197aa

Aggregation / Part I · FundamentalsErrors: one model

Your wallet's codes are Appendix A.1. What GA returns to you is Appendix A.2. Every error from /v2/aggregator/ and /v2/features/ has a non 200 HTTP status and one JSON body, Content Type: application/json : json { "code": "ERROR CODE MAINTE

Aggregation / Part I · FundamentalsIdempotency & retries

Certification tests these hardest. Build them in from day one. The full normative text is in Money Path Rules. Keep every op id with its stored answer for at least 4 months . GA resends for 72 hours, and the margin covers reconciliation dis

Aggregation / Part I · FundamentalsRate limits, pagination, network

Your wallet must answer within 5 seconds per call (§2.7). Aim for well under 1 second. GA doesn't filter your source IP on the Operator API. If you restrict inbound traffic to your wallet, allow GA's outbound addresses: 49.13.169.177 and 46

Aggregation / Part I · FundamentalsMoney Path Rules

The rules below govern the v2 wallet contract when a call goes wrong. The cases are a timeout, a duplicate, a rollback of an operation you never saw, and a win that arrives after the session closed. They're additive: GA removes or renames n

Aggregation / Part II · Operator APIGetting started

1. Get sandbox credentials. Email [integration@gamealligator.com](mailto:integration@gamealligator.com). You receive an operator profile with operator id , the Operator API key pair, and a login to https://operator.rexplay.site . There you

↑ ↓ navigate↵ openesc close
  1. Home
  2. /Integration
  3. /Gamification
  4. /Onboarding and go-live
Gamification

Onboarding and go-live

MarkdownSource

10.1 The form — once

GA_Promo_Onboarding_Form_v1.yaml holds everything we need to connect you: contacts, brands, your site’s origins, the widgets you place and how games launch, your token endpoint, your reward endpoint, what player_ref is, and — if your games are not on GA — the volumes and per transport its addresses and options. Fill it in once; we connect you from it. Changes later — a new broker, a new brand — are a new version of the same form.

10.2 Credentials and allow-lists — once

One exchange, over the channel your manager names; never in the form, e-mail or tickets.

From youFrom us
Kafka: SASL user and password; the CA; the client certificate and key for mutual TLSyour client_id for the widgets
RabbitMQ: user and passwordnothing new — player tokens (§3.2) are signed with the operator signing key you already hold for Operator API v2; ask your manager to rotate it if you need a fresh one
the IP of every broker (in the form) — we allow our outbound traffic to exactly theseyour source_id and signing secret per transport (§6, §8.1)
the secret we sign reward notifications with (§9) — after you have given us your reward endpoint URL (rewards.endpoint_url, §9.3); it is issued for that URL
a public API key with read:catalog, if you copy GA’s catalogue (§8.2)
our outbound IP addresses, if your broker or reward endpoint admits listed addresses only

Production gets its own credentials and its own secrets.

10.3 Sandbox and reconciliation

Put the widgets on a test page, sign in a test player, and — if your games are not on GA — send your test catalogue and events of test players of your brands to the sandbox. Then check with us:

  • every placeholder shows its widget, including after your page navigates away and back;
  • a signed-in test player sees their own progress, and a signed-out visitor sees the guest view;
  • a click on a game launches exactly that game (with sdk-modal the game opens in the SDK modal; with host-handled ig:game-launch reaches your page);
  • with your Content-Security-Policy on, the browser console shows no blocked widget resource;
  • a test reward reaches your reward endpoint, and the same delivery sent again is credited once;
  • your catalogue is in GA Promo, and every game.id of your feed is in it;
  • a webhook batch answers 200 with accepted, and the same batch again answers duplicate;
  • a broker event appears in our counts;
  • every round has its bets and exactly one settled whose amount is the sum of the bets;
  • a refund carries the round_id of its bet;
  • no rejected events, or each one explained;
  • per brand and day, your counts of bets and settled rounds equal ours;
  • the games in the feed are only the ones that run through you.

Then we switch production on and repeat the count check after the first day.

PreviousRewardsNextReasons, numbers, currencies
Integration support: integration@gamealligator.comIntegration center
On this page
10.1 The form — once10.2 Credentials and allow-lists — once10.3 Sandbox and reconciliation
↑ Back to top