Skip to documentation
GAME_ALLIGATOR
ProductsGamificationIntegrationDemos
Let’s talk
ProductsGamificationIntegrationDemos
Let’s talk
Integration
OverviewGuidesAPI referenceResources
Integration overview
Integration architectureFundamentalsGetting startedCertification
Products
Aggregation
Part I · Fundamentals
Core flowRequest & signingEnvelope, money and data formatsErrors: one modelIdempotency & retriesRate limits, pagination, networkMoney Path Rules
Part II · Operator API
Getting startedGames APIWallet APIFree rounds APIReports APIFeatures APIEvent stream
Part III · Certification
Run the checks from the Operator PortalThe command-line tool (for your CI)The checklistCertification checklist
Part IV · Changelog and status
ChangelogDocument ControlChangelog & migration guide: Operator API v2
Appendix
Numbers to rememberWhole guide on one page
API reference
Get player balanceAuthenticate player sessionDebit player balance (bet)Credit player balance (win/bonus)Atomic debit and creditRollback transactionClose game roundSettle free-round grantReconcile uncertain transactionNon-financial notificationgetCapabilitieslistGamesupdateGamelaunchGamelaunchDemocloseSessionlistSessionslistRoundsexportRoundsgetAggregatesissueGrantlistGrantscancelGrantsubscribeackgetOperatorCapabilitiesgetGameFeatureslistBonusBuyTypesissueBonusBuycancelBonusBuygetJackpotsgetBetRangesgetRoundReplaygetRoundDetailslistCampaignscancelCampaignqueryProviderTransactionslistTournamentsgetTournamentgetLeaderboard
Gamification
Integration
Quick startWidgets on your siteSigned-in playersLaunching gamesGameplay eventsTransportsOutcomes and your obligationsGame cataloguesRewardsOnboarding and go-liveReasons, numbers, currencies
Poker
Integration
OverviewEmbed the poker clientServer APIEvents and webhooks
llms-full.txt
Start here
Aggregation / Part I · FundamentalsCore flow

Game Alligators (GA) puts game studios' games into your casino. Traffic runs in two directions, each with its own key pair. Don't mix them. Direction Who calls whom What it's for Key you use Chapter You → GA You call https://api.rexplay.sit

Aggregation / Part I · FundamentalsRequest & signing

Every call GA sends to your wallet looks like this: http POST /v2/wallet/debit HTTP/1.1 Host: wallet.operator.example Content Type: application/json X API Key Id: key live 01 X Request Id: 0198a1d0 9a30 7f08 a7dd 713e4fd33db0 Idempotency Ke

Aggregation / Part I · FundamentalsEnvelope, money and data formats

Every wallet request has the same outer shape. payload is the action specific part and the per call ids live in payload.meta . json { "request id": "0198a1d0 9a30 7f08 a7dd 713e4fd33db0", "ts": "2026 09 13T12:00:00Z", "operator id": "0197aa

Aggregation / Part I · FundamentalsErrors: one model

Your wallet's codes are Appendix A.1. What GA returns to you is Appendix A.2. Every error from /v2/aggregator/ and /v2/features/ has a non 200 HTTP status and one JSON body, Content Type: application/json : json { "code": "ERROR CODE MAINTE

Aggregation / Part I · FundamentalsIdempotency & retries

Certification tests these hardest. Build them in from day one. The full normative text is in Money Path Rules. Keep every op id with its stored answer for at least 4 months . GA resends for 72 hours, and the margin covers reconciliation dis

Aggregation / Part I · FundamentalsRate limits, pagination, network

Your wallet must answer within 5 seconds per call (§2.7). Aim for well under 1 second. GA doesn't filter your source IP on the Operator API. If you restrict inbound traffic to your wallet, allow GA's outbound addresses: 49.13.169.177 and 46

Aggregation / Part I · FundamentalsMoney Path Rules

The rules below govern the v2 wallet contract when a call goes wrong. The cases are a timeout, a duplicate, a rollback of an operation you never saw, and a win that arrives after the session closed. They're additive: GA removes or renames n

Aggregation / Part II · Operator APIGetting started

1. Get sandbox credentials. Email [integration@gamealligator.com](mailto:integration@gamealligator.com). You receive an operator profile with operator id , the Operator API key pair, and a login to https://operator.rexplay.site . There you

↑ ↓ navigate↵ openesc close
  1. Home
  2. /Integration
  3. /Gamification
  4. /Transports
Gamification

Transports

MarkdownSource

Pick one or more. Each transport is its own connection with its own source_id.

6.1 Webhook

POST https://<api host>/promo/v1/ingest/<source_id>
Content-Type: application/json
X-Promo-Timestamp: <unix seconds>
X-Promo-Signature: <signature>
signature = lowercase_hex( HMAC-SHA256( secret, X-Promo-Timestamp + "." + raw_body ) )
  • Sign the exact bytes you send. Serialising the body again after signing (another key order, spaces) breaks the signature.
  • X-Promo-Timestamp must be within ±300 s of our clock.
  • Rotation. During a rotation we accept both the current and the next secret: we give you the next one, you switch to it, we retire the old one.
  • Body. One event, or {"events": [ … ]} with up to 500 events; at most 1 MiB. Other limits can be agreed in the form.
  • Concurrency. The number of requests in flight is agreed in the form; a request that finds no free slot within 0.5 s is answered 503.
StatusBodyMeaningResend?
200{"source":"<source_id>","results":[{"index":0,"event_id":"…","verdict":"accepted"}, …]}every event is decided; verdict is accepted, skipped, rejected or duplicate; skipped and rejected carry a reason (Appendix A). A duplicate may carry one too — ignore it, the event was decided earlierno
503 + Retry-After: 1{"source":"<source_id>","error":"undecided","results":[ …decided so far… ]}we could not decide an event right now; events after it were not triedyes — the same batch, the same event_ids
401{"error":"unauthorized","results":[]}missing or stale timestamp, missing signature, or a signature that matches no secretafter fixing the request
413{"error":"body_too_large","results":[]} / {"error":"batch_too_large","results":[]}over 1 MiB, or more events than the batch limitafter splitting
400{"error":"malformed","results":[]}signed, but not a JSON object, or events is not an arrayafter fixing
404{"error":"unknown_source","results":[]}no active connection with this source_idcontact us

On 503, any other 5xx or a network error, resend the same batch: events already decided answer duplicate, the rest are decided. {"events": []} answers 200 with empty results. If a connection keeps answering 503, contact us.

Examples (standard library only), each sends one file from examples/events/:

export PROMO_INGEST_URL=https://api.rexplay.site/promo/v1/ingest/<source_id>
read -rs PROMO_SOURCE_SECRET && export PROMO_SOURCE_SECRET
cd examples/webhook
go run . ../events/bet.json
python3 send.py ../events/settled.json
200  {"source":"<source_id>","results":[{"index":0,"event_id":"01J8Z3K9T6-bet-778812","verdict":"accepted"}]}

6.2 Kafka (your cluster)

We connect to your cluster as a consumer.

  • You give us (form, and credentials once — §10.2): the bootstrap brokers, every broker address the cluster advertises with its IP, the topics, TLS — the CA, and the client certificate with its key for mutual TLS, plus the TLS server name — and SASL (PLAIN, SCRAM-SHA-256 or SCRAM-SHA-512) with a user that may read the topics and use our consumer group. We send you the group name for your ACLs.
  • TLS is required in production.
  • Message. The record value is one event (§5.2), JSON in UTF-8. The key and the headers are not read: key the topic as your own ordering needs.
  • Start. We read from the moment we connect; tell us in the form if we should also read what the topic already retains.
  • Delivery. We commit an offset only after its event is decided. An event we could not decide is read again, so delivery is at least once; event_id absorbs the repeats.

6.3 RabbitMQ (your broker)

AMQP 0-9-1 over TLS (amqps://, required in production). You give us the host, port, vhost, user and password, and one of:

  • an exchange and routing keys — we declare our own durable queue and bind it to your exchange. You declare the exchange; our user needs the right to declare and bind that queue. The queue holds only what arrives after we create it; or

  • a queue you created for us — our user needs the right to consume it.

  • Message. The body is one event (§5.2). Headers and properties are not read. Publish persistently so an event survives a broker restart.

  • Delivery. We acknowledge a message only after its event is decided. One we could not decide stays unacknowledged and we retry it after 1 s, doubling up to 30 s; we never requeue it. If our connection drops, the broker redelivers what we had not acknowledged, and a decided event answers duplicate. Several of our consumers may read one queue; order is not required.

PreviousGameplay eventsNextOutcomes and your obligations
Integration support: integration@gamealligator.comIntegration center
On this page
6.1 Webhook6.2 Kafka (your cluster)6.3 RabbitMQ (your broker)
↑ Back to top