API reference
elite Tenant Integration API · v1.0.0
The API your (the operator's) back end calls to launch players into the game, move money in and out of the transfer wallet, sync bets, read tables and round results, and check your account.
- Server-to-server only: every request is signed with HMAC-SHA256 using your API key's secret. Never ship the secret to a browser or app.
- Response envelope: success
{"ok": true, "data": {…}}; failure{"ok": false, "error": {"code": "…", "message": "…"}}. HTTP status codes are meaningful. - Amounts are decimal strings: player amounts have at most 4 decimals (for example
"100","0.95"); account (USD) amounts have at most 6 decimals. - Times in responses are UTC ISO-8601 (for example
2026-09-24T03:00:00.000Z). - Sandbox and live: a sandbox key (
ek_s_…) belongs to your paired sandbox tenant (test coins, simulator tables); a live key (ek_l_…) belongs to your live tenant. Both use the same host and the same API.
Servers
| Environment | Base URL |
|---|---|
| Production (both sandbox and live keys use this host) | https://elite.ewin888.com/api/tenant/v1 |
| Test environment (separate deployment; accounts, keys and data are separate from production) | https://elite-dev.ewin888.com/api/tenant/v1 |
Authentication
Every request carries these headers. See Authentication & signing for the signing rules.
| Header | Description |
|---|---|
X-Api-Key | The key ID, format ek_<s|l>_<tenant>_<16 chars> (s sandbox, l live), for example ek_s_1a_XXXXXXXXXXXXXXXX. Get it in the Console under "Go-live & integration → API keys". |
X-Timestamp | Current Unix time in seconds (9–11 digits). Rejected when it differs from server time by more than ±300 seconds. |
X-Nonce | A random string that is different for every request, 16–64 letters and digits; it must not repeat within 10 minutes (retries need a new nonce too). |
X-Signature | hex(HMAC-SHA256(secret, METHOD + "\n" + PATH_AND_QUERY + "\n" + X-Timestamp + "\n" + X-Nonce + "\n" + hex(SHA256(body)))). PATH_AND_QUERY starts with /api/tenant/v1 and includes the query string. |
Response envelope
json
{ "ok": true, "data": { … } }json
{ "ok": false, "error": { "code": "INSUFFICIENT_BALANCE", "message": "insufficient available balance" } }Endpoints
Players
| Method | Path | Summary |
|---|---|---|
| POST | /player/launch | Launch a player |
| POST | /player/logout | Log a player out |
| GET | /player | Get a player |
| POST | /player/update | Update a player |
Wallet (transfer)
| Method | Path | Summary |
|---|---|---|
| POST | /wallet/deposit | Deposit (transfer in) |
| POST | /wallet/withdraw | Withdraw (transfer out) |
| GET | /wallet/transfer | Look up a transfer |
| GET | /wallet/balance | Get a balance |
Bets
| Method | Path | Summary |
|---|---|---|
| GET | /bets | Sync bets (cursor) |
| GET | /bets/summary | Daily per-player summary |
Tables and rounds
| Method | Path | Summary |
|---|---|---|
| GET | /rounds/{roundId} | Get a round result |
| GET | /tables | List tables |
| POST | /tables/enable | Enable a table |
| POST | /tables/disable | Disable a table |
Account
| Method | Path | Summary |
|---|---|---|
| GET | /account | Account summary |
| GET | /account/usage | Daily usage |
| GET | /account/statements | Monthly statements |
Webhook events
Events the platform sends to your server. Signatures, retries and idempotency are covered in Webhooks.
| Event | Summary | data |
|---|---|---|
bet.settled | Round settled | RoundEventData |
round.corrected | Round recalculated after a correction | RoundEventData |
round.voided | Round voided | RoundEventData |
player.kicked | Player kicked | PlayerKickedData |
account.grace | Grace period started | AccountStateData |
account.downgraded | Downgraded | AccountStateData |
account.restored | Restored | AccountStateData |
account.topup | Top-up credited | AccountTopupData |
account.low_balance | Low balance | AccountLowBalanceData |
test | Test event | TestEventData |
Downloads
- OpenAPI 3.1 spec (YAML)
- OpenAPI 3.1 spec (JSON)
- Postman collection (v2.1, with a built-in signing script)
After importing, fill in apiKey and apiSecret (a sandbox key) under the collection Variables; every request is signed automatically before it is sent.