10.1 The form — once
GA_Promo_Onboarding_Form_v1.yaml holds everything we need to
connect you: contacts, brands, your site’s origins, the widgets you place and how games launch, your
token endpoint, your reward endpoint, what player_ref is, and — if your games are not on GA — the
volumes and per transport its addresses and options. Fill it in once; we connect you from it.
Changes later — a new broker, a new brand — are a new version of the same form.
10.2 Credentials and allow-lists — once
One exchange, over the channel your manager names; never in the form, e-mail or tickets.
| From you | From us |
|---|---|
| Kafka: SASL user and password; the CA; the client certificate and key for mutual TLS | your client_id for the widgets |
| RabbitMQ: user and password | nothing new — player tokens (§3.2) are signed with the operator signing key you already hold for Operator API v2; ask your manager to rotate it if you need a fresh one |
| the IP of every broker (in the form) — we allow our outbound traffic to exactly these | your source_id and signing secret per transport (§6, §8.1) |
the secret we sign reward notifications with (§9) — after you have given us your reward endpoint URL (rewards.endpoint_url, §9.3); it is issued for that URL | |
a public API key with read:catalog, if you copy GA’s catalogue (§8.2) | |
| our outbound IP addresses, if your broker or reward endpoint admits listed addresses only |
Production gets its own credentials and its own secrets.
10.3 Sandbox and reconciliation
Put the widgets on a test page, sign in a test player, and — if your games are not on GA — send your test catalogue and events of test players of your brands to the sandbox. Then check with us:
- every placeholder shows its widget, including after your page navigates away and back;
- a signed-in test player sees their own progress, and a signed-out visitor sees the guest view;
- a click on a game launches exactly that game (with
sdk-modalthe game opens in the SDK modal; withhost-handledig:game-launchreaches your page); - with your Content-Security-Policy on, the browser console shows no blocked widget resource;
- a test reward reaches your reward endpoint, and the same delivery sent again is credited once;
- your catalogue is in GA Promo, and every
game.idof your feed is in it; - a webhook batch answers
200withaccepted, and the same batch again answersduplicate; - a broker event appears in our counts;
- every round has its bets and exactly one
settledwhoseamountis the sum of the bets; - a refund carries the
round_idof its bet; - no
rejectedevents, or each one explained; - per brand and day, your counts of bets and settled rounds equal ours;
- the games in the feed are only the ones that run through you.
Then we switch production on and repeat the count check after the first day.