Skip to content

Quick start ​

Follow this page and in about 30 minutes you will have made your first signed call in the sandbox, launched a test player into the game, deposited test coins and read the bets back. The sandbox uses test coins and simulator tables and is never billed.

You need

  • A server (or your own computer) that can make HTTPS requests. The API is server-to-server only: never put the secret in a browser or app.
  • An email address you can read (your Console password is sent there).

1. Sign up ​

Open /signup and fill in:

FieldNotes
Company nameShown in the Console and on invoices
Company code3–16 letters or digits, upper-cased automatically (for example ACME); it cannot change later
EmailYour Console login and the billing contact
Time zoneDates in reports and the daily summary (GET /bets/summary) use this time zone
CurrencyDefault player currency: USD, TWD, CNY, HKD, THB, VND, PHP, MYR, JPY or KRW

The account is provisioned automatically and your Console password is emailed to you (valid for 72 hours). Your first login at /Console/ verifies the email address; sign-ups that never log in within 72 hours are disabled.

Provisioning creates:

  • A live tenant (company code ACME) on the free demo plan, with the sign-up credit.
  • A sandbox tenant (company code ACME-SBX) with test coins and all simulator tables enabled (S01, S02 baccarat, S03 dragon tiger and N01 Niu Niu). The simulator tables deal rounds 24 hours a day. It allows 500 test players and 20 API requests per second (see Rate limits & quotas).
  • Two API keys: a sandbox key (ek_s_…) and a live key (ek_l_…).

2. Get the sandbox key ​

  1. Log in to the Console and open Go-live & integration → API keys.
  2. Find the row with environment "Sandbox". The key ID looks like ek_s_1a_XXXXXXXXXXXXXXXX.
  3. Click "Show" or "Copy" to get the secret (es_ followed by 40 letters and digits). Showing a key requires two-factor verification (TOTP): set it up once under My account → Two-factor authentication (TOTP); after verifying you can show and copy keys for 30 minutes.
    • Alternatively click "New key" → "Sandbox" to create another sandbox key; its secret is shown right away.
  4. Store the key ID and secret as server environment variables, for example ELITE_KEY_ID and ELITE_SECRET.

Keep the secret safe

The secret belongs on your server only (environment variables or a secret manager) — never in your code repository, front end or app. If it leaks, "Rotate" it in the Console (the old key stops working after 24 hours) or "Disable" it (immediately).

3. Your first signed call ​

Every endpoint lives under https://elite.ewin888.com/api/tenant/v1. Sandbox and live keys use the same host; the key ID tells the platform which tenant you are.

Each request carries four headers, and the signature is:

text
X-Signature = hex( HMAC-SHA256( secret,
    METHOD + "\n" + PATH_AND_QUERY + "\n" + X-Timestamp + "\n" + X-Nonce + "\n" + hex(SHA-256(body)) ) )

Try GET /tables first (a GET has no body, so the body hash is always the SHA-256 of the empty string).

bash
KEY_ID="$ELITE_KEY_ID"; SECRET="$ELITE_SECRET"
BASE='https://elite.ewin888.com'
PATH_AND_QUERY='/api/tenant/v1/tables'
TS=$(date +%s)
NONCE=$(openssl rand -hex 16)
BODY_HASH=$(printf '' | openssl dgst -sha256 -hex | sed 's/^.* //')
SIG=$(printf 'GET\n%s\n%s\n%s\n%s' "$PATH_AND_QUERY" "$TS" "$NONCE" "$BODY_HASH" \
  | openssl dgst -sha256 -hmac "$SECRET" -hex | sed 's/^.* //')
curl -sS "$BASE$PATH_AND_QUERY" \
  -H "X-Api-Key: $KEY_ID" -H "X-Timestamp: $TS" -H "X-Nonce: $NONCE" -H "X-Signature: $SIG"
js
// Uses sign.js from "Authentication & signing" (call() signs for you)
import { call } from './sign.js';

const auth = { keyId: process.env.ELITE_KEY_ID, secret: process.env.ELITE_SECRET };
const { tables } = await call('GET', '/api/tenant/v1/tables', undefined, auth);
console.log(tables.map((t) => `${t.tableId} ${t.game} enabled=${t.enabled}`));

A successful answer is {"ok": true, "data": {"tables": [...]}}, and in the sandbox S01, S02, S03 and N01 are all "enabled": true. If you get UNAUTHORIZED, paste the same inputs into the signature debugger and compare line by line; common causes are listed under Authentication & signing.

4. Launch a test player ​

Call POST /player/launch. The player is created automatically if it does not exist:

json
{ "username": "test001", "lang": "ENG", "device": "pc" }

Response:

json
{ "ok": true, "data": { "url": "https://elite.ewin888.com/Launch?t=…", "expiresIn": 60 } }

Open url in a browser within 60 seconds (it works once) and you land in the game lobby with the simulator tables. In production your site calls launch when the player clicks "Play", then redirects the player to the URL (or opens it in an iframe); see Launching the game.

5. Deposit test coins and bet ​

A new player starts with 0. Deposit test coins with POST /wallet/deposit, using the currency you chose at sign-up:

json
{ "username": "test001", "txnId": "qs-0001", "amount": "1000", "currency": "TWD" }

txnId is your transfer ID and the idempotency key: resending the same txnId never credits twice (the response says duplicate: true). Go back to the game (launch again if needed) and bet on a simulator table. The full rules are in Wallet (transfer).

6. Read the bets back ​

Once a round is settled, its bets can be read with GET /bets:

text
GET /api/tenant/v1/bets?limit=100

Store the nextCursor from the response; the next call with ?cursor=<nextCursor> continues where you left off. The full sync loop, revisions (rev) and voids are covered in Bet sync.

7. Onboarding checklist ​

Go-live & integration → Go-live checklist in the Console calls five endpoints with your sandbox key to confirm that your sandbox tenant, key and permissions work:

ItemEndpoint
Signed callGET /tables
LaunchPOST /player/launch
DepositPOST /wallet/deposit
WithdrawPOST /wallet/withdraw
Bet syncGET /bets

Click "Re-check now"; when everything passes it shows "Ready to go live".

8. Going live ​

  • Your system handles launch, deposits and withdrawals (including resending the same txnId after a timeout), and cursor-based bet sync (de-duplicated on (slipId, rev)).
  • Switch to the live key (ek_l_…); the host stays the same.
  • Set your server's outbound IPs under Go-live & integration → IP allowlist and Webhook (recommended).
  • Pick the tables your players will see under Table → Table selection (at most 2 on the free plan).
  • Set languages and the "Return-to-lobby URL" under Branding & login.
  • Before real operation, top up and upgrade to the paid plan under Plan & billing; the free demo plan limits are listed in Rate limits & quotas and Billing.
  • (Paid plan) Set up webhooks if you want push notifications.

elite Tenant Integration API v1