Signed and once
Timestamp, nonce, and signature on every callback. Idempotent by transaction id. Common errors: PLAYER_NOT_LINKED, INSUFFICIENT_FUNDS, INSUFFICIENT_AGENT_WALLET.
Solutions · Wallet callbacks
Player balances stay on your side. Sign the path, check the timestamp, and treat each transaction id as idempotent. Quote a traceId when you write in.
Timestamp, nonce, and signature on every callback. Idempotent by transaction id. Common errors: PLAYER_NOT_LINKED, INSUFFICIENT_FUNDS, INSUFFICIENT_AGENT_WALLET.
Player wallet
Bet and win only settle the game. GameXora does not take an extra GGR cut from the player.
Follow desk → GameXora → supply on one request. HMAC and IP allow-lists sit on the sell API.
Open the game in a new tab. Do not iframe it. Keys never sit in a browser.
Headers, four launch calls, and the same callback list with a sandbox desk.