Skip to documentation
GAME_ALLIGATOR
ProductsGamificationIntegrationDemos
Let’s talk
ProductsGamificationIntegrationDemos
Let’s talk
Integration
OverviewGuidesAPI referenceResources
Integration overview
Integration architectureFundamentalsGetting startedCertification
Products
Aggregation
Part I · Fundamentals
Core flowRequest & signingEnvelope, money and data formatsErrors: one modelIdempotency & retriesRate limits, pagination, networkMoney Path Rules
Part II · Operator API
Getting startedGames APIWallet APIFree rounds APIReports APIFeatures APIEvent stream
Part III · Certification
Run the checks from the Operator PortalThe command-line tool (for your CI)The checklistCertification checklist
Part IV · Changelog and status
ChangelogDocument ControlChangelog & migration guide: Operator API v2
Appendix
Numbers to rememberWhole guide on one page
API reference
Get player balanceAuthenticate player sessionDebit player balance (bet)Credit player balance (win/bonus)Atomic debit and creditRollback transactionClose game roundSettle free-round grantReconcile uncertain transactionNon-financial notificationgetCapabilitieslistGamesupdateGamelaunchGamelaunchDemocloseSessionlistSessionslistRoundsexportRoundsgetAggregatesissueGrantlistGrantscancelGrantsubscribeackgetOperatorCapabilitiesgetGameFeatureslistBonusBuyTypesissueBonusBuycancelBonusBuygetJackpotsgetBetRangesgetRoundReplaygetRoundDetailslistCampaignscancelCampaignqueryProviderTransactionslistTournamentsgetTournamentgetLeaderboard
Gamification
Integration
Quick startWidgets on your siteSigned-in playersLaunching gamesGameplay eventsTransportsOutcomes and your obligationsGame cataloguesRewardsOnboarding and go-liveReasons, numbers, currencies
Poker
Integration
OverviewEmbed the poker clientServer APIEvents and webhooks
llms-full.txt
Start here
Aggregation / Part I · FundamentalsCore flow

Game Alligators (GA) puts game studios' games into your casino. Traffic runs in two directions, each with its own key pair. Don't mix them. Direction Who calls whom What it's for Key you use Chapter You → GA You call https://api.rexplay.sit

Aggregation / Part I · FundamentalsRequest & signing

Every call GA sends to your wallet looks like this: http POST /v2/wallet/debit HTTP/1.1 Host: wallet.operator.example Content Type: application/json X API Key Id: key live 01 X Request Id: 0198a1d0 9a30 7f08 a7dd 713e4fd33db0 Idempotency Ke

Aggregation / Part I · FundamentalsEnvelope, money and data formats

Every wallet request has the same outer shape. payload is the action specific part and the per call ids live in payload.meta . json { "request id": "0198a1d0 9a30 7f08 a7dd 713e4fd33db0", "ts": "2026 09 13T12:00:00Z", "operator id": "0197aa

Aggregation / Part I · FundamentalsErrors: one model

Your wallet's codes are Appendix A.1. What GA returns to you is Appendix A.2. Every error from /v2/aggregator/ and /v2/features/ has a non 200 HTTP status and one JSON body, Content Type: application/json : json { "code": "ERROR CODE MAINTE

Aggregation / Part I · FundamentalsIdempotency & retries

Certification tests these hardest. Build them in from day one. The full normative text is in Money Path Rules. Keep every op id with its stored answer for at least 4 months . GA resends for 72 hours, and the margin covers reconciliation dis

Aggregation / Part I · FundamentalsRate limits, pagination, network

Your wallet must answer within 5 seconds per call (§2.7). Aim for well under 1 second. GA doesn't filter your source IP on the Operator API. If you restrict inbound traffic to your wallet, allow GA's outbound addresses: 49.13.169.177 and 46

Aggregation / Part I · FundamentalsMoney Path Rules

The rules below govern the v2 wallet contract when a call goes wrong. The cases are a timeout, a duplicate, a rollback of an operation you never saw, and a win that arrives after the session closed. They're additive: GA removes or renames n

Aggregation / Part II · Operator APIGetting started

1. Get sandbox credentials. Email [integration@gamealligator.com](mailto:integration@gamealligator.com). You receive an operator profile with operator id , the Operator API key pair, and a login to https://operator.rexplay.site . There you

↑ ↓ navigate↵ openesc close
  1. Home
  2. /Integration
  3. /Gamification
  4. /Rewards
Gamification

Rewards

MarkdownSource

When a player wins a reward that you pay out — cash, free spins, a jackpot — GA Promo tells your backend with a signed POST. Items, points and other in-promotion prizes stay inside GA Promo and need nothing from you.

9.1 The notification

POST <your reward endpoint>
Content-Type: application/json
X-Promo-Timestamp: <unix seconds>
X-Promo-Signature: <signature>
{
  "delivery_id": "0199a7f2-5c1e-7c3a-9d41-2b7e8f0a1c55",
  "player_ref": "u-123",
  "player_id": "0198a1cb-4f37-7ee8-8e7d-08d39925aec0",
  "operator_id": "<the GA operator id of the player's brand>",
  "reward_type": "freespins",
  "reward_value": "20",
  "currency": "EUR",
  "reference_id": "<campaign id>",
  "timestamp": "2026-09-24T12:00:00Z"
}
FieldMeaning
delivery_idthis one grant; credit once per delivery_id
player_refyour id of the player — the value your events carry as player_ref (§5.1); present for every player your events have named, absent otherwise
player_idthe same player’s id in GA
operator_idthe GA operator id of the player’s brand
reward_typecash, freespins or jackpot
reward_valuea decimal string: the amount in currency for cash and jackpot, the number of spins for freespins
currencythe currency of the amount
reference_idthe campaign that granted it; the same for every grant of that campaign — not a key
timestampwhen the notification was built

9.2 Checking it

expected = lowercase_hex( HMAC-SHA256( secret, X-Promo-Timestamp + "." + raw_body ) )

Compare expected with X-Promo-Signature in constant time, over the exact bytes you received. Refuse a timestamp more than 5 minutes away from your clock. The secret is the one we send you when we connect your reward endpoint (§9.3, §10.2). A request also carries X-Promo-Signature-Raw, an older signature over the body alone; do not rely on it.

9.3 Answering and retries

  • Answer 200, 202 or 204 once the reward is credited or recorded to credit. Anything else, or no answer within 10 seconds, is a failure.
  • A failed notification is sent again with the same delivery_id and body: 8 attempts in all, the pause growing from 10 seconds to at most 10 minutes. After the eighth failure we stop and resolve it with you by hand.
  • A repeat of a delivery_id you already credited must answer 200 and credit nothing.

You tell us the endpoint URL in the form (rewards.endpoint_url); each environment has its own URL and its own secret. The secret belongs to that URL: we generate it when we connect the endpoint and send it to you then, over the channel of §10.2 — so it comes only after you have given us a URL that GA can reach (a public https:// address; plain http:// only in the sandbox), not with your other credentials. Until the endpoint is connected, no reward notification is sent to you.

9.4 Delivery via Kafka

Instead of a webhook we can write each reward notification to a topic on your own Kafka cluster. You give us, in place of rewards.endpoint_url: the broker addresses (host:port, TLS required), the topic, the SASL mechanism (SCRAM-SHA-512 or SCRAM-SHA-256) and a user with its password, sent over the channel of §10.2. If you want to verify messages as in §9.2, say so and we send you a secret.

  • Topic. You create it. We suggest <env>.promo.rewards, for example ga-dev.promo.rewards. We never create topics.
  • Access. Grant our user WRITE and DESCRIBE on that topic.
  • Message. The value is the JSON of §9.1, byte for byte. The key is delivery_id. With a secret, the headers X-Promo-Timestamp and X-Promo-Signature are the ones of §9.2, computed over the record value.
  • Delivery. At least once: we write with acks=all and count a notification delivered when the cluster acknowledges it. A failed write is repeated on the schedule of §9.3 (8 attempts, 10 seconds to 10 minutes). The same delivery_id can arrive more than once: credit once per delivery_id.
  • Order. The key is delivery_id, so records of one grant share a partition; order across grants is not guaranteed.
PreviousGame cataloguesNextOnboarding and go-live
Integration support: integration@gamealligator.comIntegration center
On this page
9.1 The notification9.2 Checking it9.3 Answering and retries9.4 Delivery via Kafka
↑ Back to top