Launching the game
When a player enters the game from your site, your back end calls POST /player/launch for a one-time URL and sends the player there (or opens it in an iframe). Players never register with the platform and never need a password here.
Flow
Player browser Your back end elite
│ clicks "Play" │ │
│────────────────────▶│ POST /api/tenant/v1/player/launch │
│ │─────────────────────────────────▶│ creates the player (first time), kicks old sessions
│ │◀─────────────────────────────────│ { url, expiresIn: 60 }
│ 302 or iframe src │ │
│◀────────────────────│ │
│ GET /Launch?t=… (within 60 s, once) │
│──────────────────────────────────────────────────────▶│ checks the ticket, issues a player session
│◀──────────────────────────────────────────────────────│ goes to /Game/ (desktop) or /Game/m/ (mobile)- The player clicks "Play" on your site.
- Your back end calls
POST /player/launchwith the player's username. Call it every time the player enters; do not create URLs in advance or cache them. - Redirect the player to the returned
url, or use it as an iframesrc. - The game checks the ticket, keeps the player session in that browser tab's
sessionStorage, removes the ticket from the address bar and opens the lobby (or the requested table).
Parameters
| Field | Required | Notes |
|---|---|---|
username | yes | Player username, 1–32 characters (letters, digits and _ . @ -), case-insensitive. Created automatically if new |
nickname | Display name, only used when the player is created; use POST /player/update to change it later | |
currency | Currency, only used when the player is created; defaults to your tenant currency. A player's currency cannot change | |
lang | Game language: CHT, CHS, ENG, JPN, KOR, THAI, VIET, HIND, PHP (case-insensitive). Defaults to the first language set under "Branding & login" in the Console, or CHT | |
device | mobile opens the mobile layout (/Game/m/); anything else, or no value, opens the desktop layout (/Game/) | |
table | Go straight into this table (IDs from GET /tables; it must be a table you have enabled); otherwise the player lands in the lobby | |
variant | Preferred baccarat variant, classic or nocomm. Currently only stored; the player still chooses at the table | |
lobbyUrl | Your site's URL (http:// or https://). Currently only stored; the "Back to site" button uses the Console setting, see Back to your site | |
limitProfileId | Bet-limit profile ID: one of your profiles from the Console "Bet-limit profiles" page or a platform template, in the player's currency; null goes back to the default. It is saved on the player, so later launches without it keep it. See Bet-limit profiles |
Response:
{ "ok": true, "data": { "url": "https://elite.ewin888.com/Launch?t=k1.eyJ0aWQiOjQ2fQ.3xAmPlE-TiCkEt", "expiresIn": 60 } }- The host of
urlis the host you called the API on. - The ticket is valid for 60 seconds and works once. An expired or used URL shows a "link expired" page (HTTP 410); send the player back to your site so your back end can launch again.
- A
lockedplayer gets403 PLAYER_LOCKED; ano_betplayer can enter and watch but cannot bet. - Player accounts are capped: 50 on the free demo plan and 500 in the sandbox; creating another one returns
403 PLAYER_LIMIT.
Embedding in an iframe
<iframe
src="LAUNCH_URL"
allow="autoplay; fullscreen"
allowfullscreen
style="width: 100%; height: 100%; border: 0"
></iframe>- The game keeps the player signed in with
Authorization: BearerandsessionStorage, not cookies, so it works in a third-party iframe (blocked third-party cookies do not matter). - If the browser blocks site storage completely, the game asks the player to allow
sessionStorageand try again. - The game plays video and sound: keep
allow="autoplay"and allow full screen. - Do not add a restrictive
sandboxattribute (the game must run scripts, reach its own origin, and the "Back to site" button navigates the top-level page). - On phones, a full-page redirect to
urlusually works better than an iframe.
Device and language
device: "mobile"opens the mobile layout. Withoutdevicethe desktop layout is always used, so pass the right value for the player's device (for example from the User-Agent or the viewport width on your site).langsets the game UI language; players can also switch it in the game.- The available and default languages are set in the Console under Branding & login.
Back to your site
Set your site's URL (https://) in the Console under Branding & login → Return-to-lobby URL. When a player's session ends (replaced by a login elsewhere, logged out, idle timeout, account disabled), the game shows an explanation with a "Back to site" button. The button opens this URL with target="_top", so it leaves the iframe and returns to your site.
The lobbyUrl launch parameter is stored today and reserved for per-launch overrides in a later version.
Single session
A player has at most one valid game session:
- Calling launch immediately invalidates older sessions: older tabs are kicked with "Your account was signed in elsewhere" (reason
SESSION_REPLACED), and bets from an old session are rejected. - The URL opened last wins: the same happens again when the player opens a launch URL. If several URLs were issued, only the one opened last stays valid and earlier sessions are kicked.
POST /player/logoutinvalidates all sessions and kicks the player (reasonLOGGED_OUT).POST /player/updatewithstatus: lockedkicks the player at once (reasonLOCKED).- Logging out and locking send the webhook
player.kicked; a new launch replacing an older session does not. - A player session lasts at most 12 hours. After 30 minutes without activity the player is warned, and after 60 minutes signed out. After that the player must enter again from your site (a new launch).
- Stakes are deducted when bets are accepted, so kicking a player never affects accepted bets; they settle and pay out as usual.
Several tabs in one browser
The session lives in each tab's own sessionStorage. If the player enters again from your site in a new tab, the new launch invalidates the old tab. This is expected.
Player accounts
- Usernames are case-insensitive:
Aliceandaliceare the same player (responses keep the case used when the player was created). - Derive usernames from a member ID that never changes in your system, for example
m10023, rather than from an editable display name. - Use separate usernames when the same person needs different currencies.
- Read and manage players with
GET /player,POST /player/updateandPOST /player/logout; see the API reference: Players.
Bet-limit profiles
- Launch and
POST /player/updateacceptlimitProfileIdto choose the player's bet-limit profile. It must be a profile you created in the Console under Table → Bet-limit profiles or a platform template, in the player's currency; otherwise you get400 INVALID_PARAMETER. - The choice is saved on the player;
nullgoes back to the default profile. - Profiles are per game: a profile only applies to tables of its game, and other games use the default.
- The free demo plan (sandbox included) always uses the platform's "demo" limits.
Error codes
| Code | HTTP | Cause |
|---|---|---|
INVALID_PARAMETER | 400 | username missing, unsupported lang, lobbyUrl not an http(s) URL, limitProfileId unknown or in another currency |
INVALID_USERNAME | 400 | Username breaks the rules |
INVALID_CURRENCY | 400 | Invalid currency for a new player |
PLAYER_LOCKED | 403 | The player is locked |
PLAYER_LIMIT | 403 | The plan's player limit is reached (50 on the free demo plan, 500 in the sandbox) |
Common errors are listed in Error codes.