Players
Launch, log out, read and update players. A player is created automatically on the first launch (or first deposit); there is no separate sign-up call.
Guide: read the integration guide for this area
TIP
Examples are signed with the example key and timestamp from "Authentication & signing", so you can re-check them in the Signature debugger.
Launch a player
POST /api/tenant/v1/player/launch
Returns a one-time URL that takes the player into the game (valid for 60 seconds, usable once). The player is created if it does not exist.
- Single session: calling launch immediately invalidates and kicks the player's open sessions (reason
SESSION_REPLACED), and the same happens again when the player opens the URL. If several URLs were issued, the one opened last wins and earlier sessions are kicked. - Send the player's browser to the URL (or open it in an iframe). An expired or used URL shows "link expired" (HTTP 410).
nicknameandcurrencyare only used when the player is created. UsePOST /player/updateto change the nickname later; the currency cannot change.currencymust be one the operator has enabled in Console (Bet limits → Currencies); leave it out for the primary currency. OtherwiseCURRENCY_NOT_ENABLED.limitProfileIdis saved as the player's bet-limit profile (same asPOST /player/update), so later launches without it keep it.- A
lockedplayer getsPLAYER_LOCKED; ano_betplayer can enter but cannot bet.
Request body (application/json)
| Field | Type | Required | Description |
|---|---|---|---|
username | string | yes | Player username, 1–32 characters (letters, digits and _ . @ -). Case-insensitive (Alice and alice are the same player).Format: ^[A-Za-z0-9_.@-]{1,32}$ |
nickname | string | no | Display name (optional). Only used when the player is created. |
currency | string | no | Currency (optional), only used when the player is created. Defaults to your tenant currency. Format: ^[A-Za-z]{3,5}$ |
lang | string | no | Game language (optional). Defaults to the first language set in your Console, or CHT.Values: CHT, CHS, ENG, JPN, KOR, THAI, VIET, HIND, PHP |
device | string | no | mobile opens the mobile layout; any other value means the desktop layout pc.Values: pc, mobileDefault: pc |
table | string | no | Go straight into this table (optional); without it the player lands in the lobby. It must be a table you have enabled. Length: 1–… |
variant | string | no | Preferred baccarat variant (optional, classic / nocomm). Currently stored only; the player still picks the variant at the table. |
lobbyUrl | string (uri) | no | Your site's URL (optional, http or https). In the current version the "Back to site" button uses the Console setting "Branding & login → Return-to-lobby URL"; this parameter is stored for per-launch overrides in a later version. Format: ^https?:// |
limitProfileId | integer | null | no | Bet-limit profile ID: one of your own profiles (Console "Bet-limit profiles") or a platform template, in the player's currency, otherwise INVALID_PARAMETER. null goes back to the default. Profiles are per game: a profile only applies to tables of its game, and other games use the default.Range: 1–… |
Example request
POST /api/tenant/v1/player/launch HTTP/1.1
Host: elite.ewin888.com
X-Api-Key: ek_s_1a_XXXXXXXXXXXXXXXX
X-Timestamp: 1790218800
X-Nonce: ex2a3b659ce54a7c197e7bd7
X-Signature: 984cf8a6c0afeb4b7baf4bb7c800ced833ef6265d8c8e8234d89375c4377e4bf
Content-Type: application/json
{"username":"alice","lang":"ENG","device":"mobile","table":"S01"}Response data
| Field | Type | Description |
|---|---|---|
url | string (uri) | One-time game URL (https://<host>/Launch?t=…), valid for 60 seconds and usable once. |
expiresIn | integer | Seconds until the URL expires. Always: 60 |
Example response
{
"ok": true,
"data": {
"url": "https://elite.ewin888.com/Launch?t=k1.eyJ0aWQiOjQ2fQ.3xAmPlE-TiCkEt",
"expiresIn": 60
}
}Error codes
| Code | HTTP | Meaning |
|---|---|---|
INVALID_PARAMETER | 400 | A required field is missing, or a field has the wrong format or value; message names the field. |
INVALID_USERNAME | 400 | The username breaks the rules (1–32 characters of letters, digits and _ . @ -), or username is missing from a query. |
INVALID_CURRENCY | 400 | The currency code given for a new player is invalid (3–5 letters required). |
CURRENCY_NOT_ENABLED | 400 | The currency given for a new player is not enabled for the operator (Console → Bet limits → Currencies). Existing players are not affected. |
PLAYER_LOCKED | 403 | The player is locked and cannot be launched. |
PLAYER_LIMIT | 403 | The plan's player limit is reached (50 by default on the free demo plan, 500 in the sandbox). |
Every endpoint can also return the common errors (UNAUTHORIZED, IP_NOT_ALLOWED, TENANT_SUSPENDED, RATE_LIMITED, INTERNAL_ERROR…).
Log a player out
POST /api/tenant/v1/player/logout
Invalidates all of the player's sessions and kicks them out of the game (reason LOGGED_OUT), and sends the webhook player.kicked (reason is logged_out). The player needs a new launch to come back.
Request body (application/json)
| Field | Type | Required | Description |
|---|---|---|---|
username | string | yes | Player username, 1–32 characters (letters, digits and _ . @ -). Case-insensitive (Alice and alice are the same player).Format: ^[A-Za-z0-9_.@-]{1,32}$ |
Example request
POST /api/tenant/v1/player/logout HTTP/1.1
Host: elite.ewin888.com
X-Api-Key: ek_s_1a_XXXXXXXXXXXXXXXX
X-Timestamp: 1790218800
X-Nonce: ex30c4dc0d6184b121569ed8
X-Signature: 03d4b8a3fae4c5d4198c434b0a7d00651ae514c76c3c92697fabf327265a2313
Content-Type: application/json
{"username":"alice"}Response data
| Field | Type | Description |
|---|---|---|
kicked | boolean | Always true. |
Example response
{
"ok": true,
"data": {
"kicked": true
}
}Error codes
| Code | HTTP | Meaning |
|---|---|---|
INVALID_PARAMETER | 400 | A required field is missing, or a field has the wrong format or value; message names the field. |
INVALID_USERNAME | 400 | The username breaks the rules (1–32 characters of letters, digits and _ . @ -), or username is missing from a query. |
PLAYER_NOT_FOUND | 404 | No player with this username. |
Every endpoint can also return the common errors (UNAUTHORIZED, IP_NOT_ALLOWED, TENANT_SUSPENDED, RATE_LIMITED, INTERNAL_ERROR…).
Get a player
GET /api/tenant/v1/player
Player details, status, current balance and whether the player is online.
Parameter
| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
username | query | string | yes | Player username. Format: ^[A-Za-z0-9_.@-]{1,32}$ |
Example request
GET /api/tenant/v1/player?username=alice HTTP/1.1
Host: elite.ewin888.com
X-Api-Key: ek_s_1a_XXXXXXXXXXXXXXXX
X-Timestamp: 1790218800
X-Nonce: ex0f4c27405f79ad431f805c
X-Signature: 01202dea8bd6b3ee60804a309c91cd4a71a2a7089243887bdccb9d43b13896e5Response data
| Field | Type | Description |
|---|---|---|
username | string | Username (with the letter case used when it was created). |
nickname | string | null | Display name. |
status | string | active normal; locked cannot enter the game; no_bet can enter and watch but not bet.Values: active, locked, no_bet |
currency | string | Currency. |
balance | string | Current available balance. Format: ^-?\d{1,15}(\.\d{1,4})?$ |
online | boolean | Whether the player is in the game right now (lobby or a table). |
createdAt | string (date-time) | UTC time, ISO-8601 with milliseconds. |
lastLoginAt | string (date-time) | null | When the player last entered the game. |
Example response
{
"ok": true,
"data": {
"username": "alice",
"nickname": "Alice",
"status": "active",
"currency": "TWD",
"balance": "1500.5",
"online": true,
"createdAt": "2026-09-20T08:15:30.120Z",
"lastLoginAt": "2026-09-24T02:59:40.004Z"
}
}Error codes
| Code | HTTP | Meaning |
|---|---|---|
INVALID_USERNAME | 400 | The username breaks the rules (1–32 characters of letters, digits and _ . @ -), or username is missing from a query. |
PLAYER_NOT_FOUND | 404 | No player with this username. |
Every endpoint can also return the common errors (UNAUTHORIZED, IP_NOT_ALLOWED, TENANT_SUSPENDED, RATE_LIMITED, INTERNAL_ERROR…).
Update a player
POST /api/tenant/v1/player/update
Updates only the fields you send and returns the updated player (same shape as GET /player).
status: lockedlocks the player and kicks them out immediately (reasonLOCKED) and sends the webhookplayer.kicked(reasonislocked); later launches returnPLAYER_LOCKED.status: no_betlets the player enter and watch but not bet.activerestores normal play.limitProfileIdmust be one of your own bet-limit profiles or a platform template, in the player's currency, otherwiseINVALID_PARAMETER;nullgoes back to the default.passwordis only needed by operators that use the platform's public login page (/Login). If you launch players through the API you do not need player passwords.
Request body (application/json)
| Field | Type | Required | Description |
|---|---|---|---|
username | string | yes | Player username, 1–32 characters (letters, digits and _ . @ -). Case-insensitive (Alice and alice are the same player).Format: ^[A-Za-z0-9_.@-]{1,32}$ |
status | string | no | active normal; locked cannot enter the game; no_bet can enter and watch but not bet.Values: active, locked, no_bet |
nickname | string | null | no | New display name; null or an empty string clears it. |
limitProfileId | integer | null | no | Bet-limit profile ID: one of your own profiles (Console "Bet-limit profiles") or a platform template, in the player's currency, otherwise INVALID_PARAMETER. null goes back to the default. Profiles are per game: a profile only applies to tables of its game, and other games use the default.Range: 1–… |
password | string | no | Password for the public login page (/Login), 6–64 characters.Length: 6–64 |
Example request
POST /api/tenant/v1/player/update HTTP/1.1
Host: elite.ewin888.com
X-Api-Key: ek_s_1a_XXXXXXXXXXXXXXXX
X-Timestamp: 1790218800
X-Nonce: ex31022a88145bbea84a3c01
X-Signature: fec8572e397e037df9aa8d207d142f38296d10890f96528a68cb66cd6778accc
Content-Type: application/json
{"username":"alice","status":"locked"}Response data
| Field | Type | Description |
|---|---|---|
username | string | Username (with the letter case used when it was created). |
nickname | string | null | Display name. |
status | string | active normal; locked cannot enter the game; no_bet can enter and watch but not bet.Values: active, locked, no_bet |
currency | string | Currency. |
balance | string | Current available balance. Format: ^-?\d{1,15}(\.\d{1,4})?$ |
online | boolean | Whether the player is in the game right now (lobby or a table). |
createdAt | string (date-time) | UTC time, ISO-8601 with milliseconds. |
lastLoginAt | string (date-time) | null | When the player last entered the game. |
Example response
{
"ok": true,
"data": {
"username": "alice",
"nickname": "Alice",
"status": "locked",
"currency": "TWD",
"balance": "1500.5",
"online": false,
"createdAt": "2026-09-20T08:15:30.120Z",
"lastLoginAt": "2026-09-24T02:59:40.004Z"
}
}Error codes
| Code | HTTP | Meaning |
|---|---|---|
INVALID_PARAMETER | 400 | A required field is missing, or a field has the wrong format or value; message names the field. |
INVALID_USERNAME | 400 | The username breaks the rules (1–32 characters of letters, digits and _ . @ -), or username is missing from a query. |
PLAYER_NOT_FOUND | 404 | No player with this username. |
Every endpoint can also return the common errors (UNAUTHORIZED, IP_NOT_ALLOWED, TENANT_SUSPENDED, RATE_LIMITED, INTERNAL_ERROR…).