Home · Solutions · Casino API

Launch in four calls

One sell API for the titles house assigned to a Client ID. Your backend lists providers, lists games, links a player, and starts the session. Keys never sit in a browser.

GameXora desk with catalog, sessions, wallets, and the commercial ledger

What it connects

Launch, the wallet, and the books

The API does not open a second casino site. It starts an assigned game and talks back to the operator wallet.

One sell API

Providers, games, link, and start share one desk key. You do not wire each studio yourself.

Assigned launch

The games call returns only the slice on this Client ID. A title that is not assigned does not start.

Wallet callbacks

Session check, player details, balance, and move funds. Bet and win settle on the operator wallet.

Desk keys

Client ID, API key, and API secret on every call. Optional HMAC. An IP allow-list. A traceId on the response.

Chargeable GGR

max(0, bets − wins) lands on the desk ledger after move funds. Players are not charged an extra cut.

Campaigns

Tournaments, prize drops, free spins, and cashback are visible to the desk only after house assigns them.

01
ProvidersGET
/api/v1/casino/providers

Confirms the desk key and lists supply assigned to this Client ID.

02
GamesGET
/api/v1/casino/games

Copy gameId from id or externalId.

03
Link playerPOST
/api/v1/casino/players/link

Map one userId to one live player wallet, then fund it.

04
Start gameGET
/api/v1/casino/games/start

Open location in a new tab. The session stays on GameXora.

Quote the traceId

Staff can follow desk → GameXora → supply on one request. Common errors: PLAYER_NOT_LINKED, INSUFFICIENT_FUNDS, INSUFFICIENT_AGENT_WALLET, GAME_UNAVAILABLE, PROVIDER_NOT_ASSIGNED.

Go live

From a sandbox key to a live session

01

Take the desk key

House issues a Client ID, API key, and API secret. A sandbox key can link and start without touching live books. The secret is shown once.

02

Call the four routes

List providers, copy a game id, link one userId to one player wallet, then start. Open location in a new tab. Do not iframe it.

03

Answer the callbacks

Sign the path, check the timestamp, and treat each transaction id as idempotent. Quote traceId if a call fails.

Common replies: PLAYER_NOT_LINKED, INSUFFICIENT_FUNDS, INSUFFICIENT_AGENT_WALLET, GAME_UNAVAILABLE, PROVIDER_NOT_ASSIGNED.

FAQ

Calls, keys, and the wallet

What does the Casino API do?

It lets your backend launch games house assigned to a Client ID. Four calls: providers, games, link player, start game. The player site stays yours.

Do I integrate each studio?

No. House holds the supply connection. The providers call lists only what this desk was assigned. A studio that is not on the Client ID does not appear.

Where does the balance live?

On the operator wallet. GameXora calls sessionCheck, playerDetails, getBalance, and moveFunds. Bet, win, and rollback settle there.

Which headers go on a call?

X-Client-Id, X-Api-Key, and X-Api-Secret. HMAC with a timestamp, nonce, and signature is optional. Responses include a traceId. Keys stay on the backend.

Need a sandbox key?

Open the desk playground after sign-in, or request access from house staff.