Skip to content

API Reference ​

The RetentionPlay /v1 HTTP API as described by the canonical OpenAPI document (backend/crates/api/openapi/playflow-v1.openapi.json).

Interactive Swagger UI

The running API also serves a live, "try it out" Swagger UI at /docs (for example http://api.localhost/docs locally), backed by the same spec at /docs/openapi.json.

RetentionPlay embed gamification / retention API: widget, progression, rewards, admin.

  • Anonymous free-play — one loader script plus project_id; no customer secret in the browser.
  • Session token — issued by POST /v1/server/session-token with a session:issue server API key, then sent as Authorization: Bearer for play/events.
  • Preview — no-write previews use GET /v1/admin/widget-preview and require an authenticated project owner with verified 2FA.
  • Admin JWT — from POST /v1/admin/auth/login for /v1/admin/*.
  • Server API key — X-PlayFlow-Server-Key or Bearer for /v1/server/events, /v1/server/session-token and /v1/economy/grant.

Servers​

http://localhost:8080Local API

health​


Liveness check​

GET
/v1/health

Responses​

OK

Playground​

Samples​


Readiness (Postgres + Dragonfly)​

GET
/v1/ready

Responses​

Ready

Playground​

Samples​


Public status page data​

GET
/v1/status

Responses​

Status JSON

Playground​

Samples​


Dev helper: signed session token for proj_demo (disabled when ENABLE_DEMO_ENDPOINTS=0)​

GET
/v1/demo/token

Responses​

session_token

Playground​

Samples​


Issue verified player session token (API key scope session:issue)​

POST
/v1/server/session-token

Authorizations​

ServerBearer

Server API key scoped to the project; preferred over compatibility headers

Type
HTTP (bearer)
or
ServerApiKey

Legacy header; Authorization Bearer or X-RetentionPlay-Server-Key also accepted

Type
API Key (header: X-PlayFlow-Server-Key)

Request Body​

application/json
JSON
{
  
"project_id": "string",
  
"external_user_id": "string",
  
"ttl_seconds": 3600
}

Responses​

session_token, expires_at, subject_type=verified

Playground​

Authorization
Body

Samples​


Ingest widget event​

POST
/v1/events

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
  
"type": "streak.ui_ack",
  
"payload": {
  
},
  
"session_id": "string"
}

Responses​

Accepted

Playground​

Authorization
Body

Samples​


Server-confirmed gameplay event (e.g. streak.server_confirm)​

POST
/v1/server/events

Authorizations​

ServerApiKey

Legacy header; Authorization Bearer or X-RetentionPlay-Server-Key also accepted

Type
API Key (header: X-PlayFlow-Server-Key)

Request Body​

application/json
JSON
{
  
"type": "streak.ui_ack",
  
"payload": {
  
},
  
"session_id": "string"
}

Responses​

Accepted

Playground​

Authorization
Body

Samples​


Analytics-only business events (product_click, favorite, merchant_click, purchase)​

POST
/v1/server/business-events

Authorizations​

ServerApiKey

Legacy header; Authorization Bearer or X-RetentionPlay-Server-Key also accepted

Type
API Key (header: X-PlayFlow-Server-Key)

Parameters​

Header Parameters

Idempotency-Key*
Type
string
Required

Request Body​

application/json
JSON
{
  
"project_id": "string",
  
"external_user_id": "string",
  
"type": "string",
  
"payload": {
  
}
}

Responses​

Accepted (idempotent)

Playground​

Authorization
Headers
Body

Samples​


Current progression state​

GET
/v1/progress/state

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Parameters​

Query Parameters

session_token

Legacy fallback; use Authorization to avoid token URLs

Type
string

Responses​

Progress JSON

Playground​

Authorization
Variables
Key
Value

Samples​


Start or resume a game run​

POST
/v1/game-runs

Механика и уровень выбираются сервером; Origin должен совпадать с origin API. Повтор создавшего партию start_id разбирается до лимитов. intent=next возвращает активную партию с resumed=true. HTTP body ≤2097152байт. Ошибки JSON/Content-Type/UUID в теле: безопасный JSON validation_error с request_id (400/415/422), превышение HTTP-предела —413.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
  
"start_id": "string",
  
"replace_active": false,
  
"intent": "next",
  
"level_number": 0,
  
"expected_mechanic": "match3_v1",
  
"supported_game_versions": [
  
  
[
  
  
  
1
  
  
]
  
]
}

Responses​

Партия начата, возвращена активная или найдена по повтору start_id

application/json
JSON
{
  
"run_id": "string",
  
"game_id": "match3_v1",
  
"mechanic": "match3_v1",
  
"game_version": 1,
  
"level": {
  
  
"id": "level-001",
  
  
"version": 1,
  
  
"number": 0,
  
  
"best_score": 0,
  
  
"cycle_round": 0
  
},
  
"status": "string",
  
"sequence": 0,
  
"is_replay": true,
  
"end_reason": "string",
  
"expires_at": "string",
  
"resumable": true,
  
"started_at": "string",
  
"server_time": "string",
  
"view": {
  
  
"additionalProperties": "string"
  
},
  
"resumed": true
}

Playground​

Authorization
Body

Samples​


Fetch the current game run state​

GET
/v1/game-runs/{run_id}

Чтение по механике партии, в том числе после смены механики проекта. Активная просроченная партия закрывается abandoned/expired; чтение может изменить её состояние. Origin не проверяется. Лимит 60/мин на игрока.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Parameters​

Path Parameters

run_id*
Type
string
Required
Format
"uuid"

Responses​

Актуальное состояние

application/json
JSON
{
  
"run_id": "string",
  
"game_id": "match3_v1",
  
"mechanic": "match3_v1",
  
"game_version": 1,
  
"level": {
  
  
"id": "level-001",
  
  
"version": 1,
  
  
"number": 0,
  
  
"best_score": 0,
  
  
"cycle_round": 0
  
},
  
"status": "string",
  
"sequence": 0,
  
"is_replay": true,
  
"end_reason": "string",
  
"expires_at": "string",
  
"resumable": true,
  
"started_at": "string",
  
"server_time": "string",
  
"view": {
  
  
"additionalProperties": "string"
  
}
}

Playground​

Authorization
Variables
Key
Value

Samples​


Apply one game command​

POST
/v1/game-runs/{run_id}/commands

Origin должен совпадать с origin API. Механика берётся из партии. Match3 payload ≤512 байт под общим потолком конверта 8192 байт. Игровой отказ — HTTP 200 accepted=false. progression есть у завершающего хода уровня. Просроченная партия закрывается abandoned/expired, новая команда получает 409 run_not_active. HTTP body ≤2097152байт; сохранённый конверт command_id/sequence/action/payload ≤8192байт по Postgres jsonb::text проверяется до FraudGate. Ошибки JSON/Content-Type возвращают безопасный JSON с request_id, ошибки path UUID остаются текстовыми.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Parameters​

Header Parameters

X-RetentionPlay-Client-Version

Диагностическая версия клиента; не входит в payload/fingerprint и не влияет на результат. Произвольные значения не журналируются.

Type
string
Pattern
"^(r[0-9a-f]{12}|legacy-v1)$"

Path Parameters

run_id*
Type
string
Required
Format
"uuid"

Request Body​

application/json
JSON
{
  
"command_id": "string",
  
"sequence": 0,
  
"action": "swap",
  
"payload": {
  
  
"additionalProperties": "string"
  
}
}

Responses​

Команда обработана

application/json
JSON
{
  
"run_id": "string",
  
"sequence": 0,
  
"accepted": true,
  
"rejection_code": "string",
  
"status": "string",
  
"view": {
  
  
"additionalProperties": "string"
  
},
  
"animation_steps": [
  
  
{
  
  
  
"additionalProperties": "string"
  
  
}
  
],
  
"facts": [
  
  
{
  
  
  
"additionalProperties": "string"
  
  
}
  
],
  
"progression": {
  
  
"level_number": 1,
  
  
"first_completion": true,
  
  
"is_replay": true,
  
  
"next_level_number": 2,
  
  
"levels_total": 3,
  
  
"track_complete": true,
  
  
"cycle_round": 0,
  
  
"best_score": 0,
  
  
"new_best": true
  
}
}

Playground​

Authorization
Headers
Variables
Key
Value
Body

Samples​


Serve an uploaded project background​

GET
/v1/project-game-assets/{project_id}/{asset_id}

Файл отдаётся с домена сервиса по идентификатору, выведенному из содержимого, поэтому кэшируется как неизменяемый.

Parameters​

Path Parameters

project_id*
Type
string
Required
asset_id*
Type
string
Required

Responses​

Изображение

Playground​

Variables
Key
Value

Samples​


Lobby state for the current player​

GET
/v1/lobby

Состояние лобби одним запросом: режим показа, механика «Играть», следующий уровень, незавершённая партия и итог последней партии. Прогресс и награды не меняет; при превышении лимита сохраняется fraud flag rate_exceeded. Origin не проверяется. Лимит — 60 запросов в минуту на игрока.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Responses​

Состояние лобби

application/json
JSON
{
  
"schema": 1,
  
"config_revision": 0,
  
"entry_mode": "string",
  
"server_time": "string",
  
"viewport": {
  
  
"width": 420,
  
  
"height": 760
  
},
  
"theme": {
  
  
"accent": "#d79a3c"
  
},
  
"assets": {
  
  
"lobby_background": {
  
  
  
"url": "/v1/project-game-assets/proj_demo/3f2a9c",
  
  
  
"width": 840,
  
  
  
"height": 1520
  
  
}
  
},
  
"play": {
  
  
"mechanic": "match3_v1",
  
  
"title": "string",
  
  
"available": true,
  
  
"unavailable_reason": "string",
  
  
"next_level": {
  
  
  
"number": 1,
  
  
  
"id": "level-001",
  
  
  
"cycle_round": 0,
  
  
  
"preview": {
  
  
  
  
"additionalProperties": "string"
  
  
  
}
  
  
},
  
  
"levels_total": 3,
  
  
"track_complete": true,
  
  
"active_run": {
  
  
  
"run_id": "string",
  
  
  
"level_number": 0,
  
  
  
"sequence": 0,
  
  
  
"started_at": "string",
  
  
  
"resumable": true
  
  
}
  
},
  
"last_result": {
  
  
"run_id": "string",
  
  
"mechanic": "match3_v1",
  
  
"status": "string",
  
  
"level_number": 0,
  
  
"reward": {
  
  
  
"status": "string"
  
  
}
  
},
  
"wheel": {
  
  
"enabled": true,
  
  
"wheel_id": "string",
  
  
"version": 0,
  
  
"entitlement": {
  
  
  
"additionalProperties": "string"
  
  
},
  
  
"pending": {
  
  
  
"additionalProperties": "string"
  
  
}
  
}
}

Playground​

Authorization

Samples​


Player-facing reward status of a run​

GET
/v1/game-runs/{run_id}/reward

Статус награды за партию для показа игроку. Только владелец партии; работает и после смены механики проекта. Причины, счёт риска и срок удержания не раскрываются. Несколько заявок одной партии сводятся в один статус по приоритету pending > checking > delayed > confirmed > unavailable. Для free_play и партий без заявки — none. Прогресс и заявки не меняет; при превышении лимита сохраняется fraud flag rate_exceeded. Лимит — 30 запросов в минуту.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Parameters​

Path Parameters

run_id*
Type
string
Required
Format
"uuid"

Responses​

Статус

application/json
JSON
{
  
"status": "string",
  
"label_key": "reward.status.pending",
  
"updated_at": "string"
}

Playground​

Authorization
Variables
Key
Value

Samples​


Обезличенная диагностика транспорта клиента​

POST
/v1/client-telemetry

До256 байт, неизвестные поля запрещены. Origin API и действующий токен игрока. Максимум3 сообщения/мин на сессию и300 на проект. Журнал содержит только enum/status/build_version; без token/IP/player/game payload. Клиент отправляет выборку5% и не ждёт отправки. Legacy передаёт только диагностический header версии команды.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
  
"build_version": "string",
  
"kind": "string",
  
"status": 0
}

Responses​

Принято

Playground​

Authorization
Body

Samples​


Issue origin-bound anonymous free_play session token​

POST
/v1/widget/session

Request Body​

application/json
JSON
{
  
"project_id": "string",
  
"anonymous_id": "string"
}

Responses​

session_token, external_user_id, expires_at, subject_type=anonymous

Playground​

Body

Samples​


Widget loader script​

GET
/v1/widget.js

Parameters​

Header Parameters

If-None-Match
Type
string

Responses​

JavaScript; no-cache, max-age=0, must-revalidate

Playground​

Headers

Samples​


Widget config (preview or play)​

GET
/v1/widget/config

Parameters​

Query Parameters

project_id*
Type
string
Required
session_token
Type
string

Responses​

Config JSON

Playground​

Variables
Key
Value

Samples​


A/B exposure bucket​

GET
/v1/widget/exposure

Parameters​

Query Parameters

project_id*
Type
string
Required
external_user_id
Type
string
session_token
Type
string

Responses​

show_widget, cohort

Playground​

Variables
Key
Value

Samples​


Play shell HTML (iframe)​

GET
/v1/play

Токен сессии в адресе не передаётся: окно получает его рукопожатием postMessage (retentionplay:ready -> retentionplay:bootstrap). Параметр mode обязателен.

Parameters​

Query Parameters

project_id*
Type
string
Required
mode*

Настоящая партия. Публичный preview запрещён (403); предпросмотр владельца — /v1/admin/widget-preview.

Type
string
Required
Valid values
"play"
template_id
Type
string

Responses​

HTML

Playground​

Variables
Key
Value

Samples​


Template UI bundle​

GET
/v1/templates/{template_id}/bundle.js

Parameters​

Path Parameters

template_id*
Type
string
Required

Responses​

JavaScript bundle

Playground​

Variables
Key
Value

Samples​


Точка входа клиента игры​

GET
/v1/games/{game_id}/entry.js

Обычный скрипт, который подключает текущий собранный модуль клиента. Отдаётся без кеша, потому что имя собранного файла меняется со сборкой.

Parameters​

Path Parameters

game_id*
Type
string
Required
Example"match3_v1"

Responses​

JavaScript

Playground​

Variables
Key
Value

Samples​


Собранный файл клиента игры​

GET
/v1/game-assets/{game_id}/{version}/{file}

Имя файла содержит хэш содержимого, поэтому ответ кешируется на год (public, max-age=31536000, immutable). Выпуск shell/ отдаётся с заранее сжатыми br/gzip по Accept-Encoding, Vary: Accept-Encoding. Прямой запрос .br/.gz — 404. Старая сборка сжимается gzip на лету.

Parameters​

Path Parameters

game_id*
Type
string
Required
Example"match3_v1"
version*

Версия старой сборки (1) или id выпуска оболочки (r + 12 hex) при game_id = shell.

Type
string
Required
Example"r0123456789ab"
Pattern
"^[A-Za-z0-9_-]{1,64}$"
file*

Путь внутри сборки. Выход за её пределы запрещён.

Type
string
Required

Responses​

Файл сборки

Playground​

Variables
Key
Value

Samples​


economy​


Resource balances for session user​

GET
/v1/economy/balances

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Responses​

Balances

Playground​

Authorization

Samples​


Spend resource (booster)​

POST
/v1/economy/spend

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
  
"booster_id": "string",
  
"idempotency_key": "string"
}

Responses​

effect_token

Playground​

Authorization
Body

Samples​


Grant resource (server API key)​

POST
/v1/economy/grant

Authorizations​

ServerApiKey

Legacy header; Authorization Bearer or X-RetentionPlay-Server-Key also accepted

Type
API Key (header: X-PlayFlow-Server-Key)

Request Body​

application/json
JSON
{
  
"project_id": "string",
  
"external_user_id": "string",
  
"resource_id": "string",
  
"amount": 0,
  
"idempotency_key": "string"
}

Responses​

New balance

Playground​

Authorization
Body

Samples​


Register admin account​

POST
/v1/admin/auth/signup

Request Body​

application/json
JSON
{
  
"email": "string",
  
"password": "string"
}

Responses​

Account ID and HttpOnly session cookie backed by Postgres registry; token is not returned in JSON

application/json
JSON
{
  
"token": "string",
  
"account_id": "string"
}

Playground​

Body

Samples​


Admin login​

POST
/v1/admin/auth/login

Request Body​

application/json
JSON
{
  
"email": "string",
  
"password": "string"
}

Responses​

JWT

application/json
JSON
{
  
"token": "string",
  
"account_id": "string"
}

Playground​

Body

Samples​


Current admin profile​

GET
/v1/admin/me

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Responses​

account_id, email

Playground​

Authorization

Samples​


List own active admin sessions​

GET
/v1/admin/auth/sessions

Requires verified 2FA. Only own unrevoked unexpired sessions. UUID ascending pagination; refresh from the beginning to see newly created sessions. No tokens, hashes or IP addresses.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Query Parameters

limit
Type
integer
Minimum
1
Maximum
50
Default
20
cursor
Type
string
Format
"uuid"

Responses​

Active sessions page

application/json
JSON
{
  
"sessions": [
  
  
{
  
  
  
"id": "string",
  
  
  
"created_at": "string",
  
  
  
"expires_at": "string",
  
  
  
"current": true
  
  
}
  
],
  
"next_cursor": "string"
}

Playground​

Authorization
Variables
Key
Value

Samples​


Revoke own active admin session​

DELETE
/v1/admin/auth/sessions/{session_id}

Requires verified 2FA and allowed Origin for cookie callers. Revocation and safe audit commit atomically. Revoking current session clears cookies; next request requires login.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

session_id*
Type
string
Required
Format
"uuid"

Responses​

Revoked

application/json
JSON
{
  
"revoked": true,
  
"current": true
}

Playground​

Authorization
Variables
Key
Value

Samples​


Change password and revoke every admin session​

POST
/v1/admin/auth/password

Requires active registry session, verified 2FA and current password. Updates password and revokes all sessions in one transaction. Cookie paths are cleared; login again. Cookie callers require allowed Origin.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
  
"current_password": "string",
  
"new_password": "string"
}

Responses​

Password updated; all sessions revoked

application/json
JSON
{
  
"status": "string",
  
"reauthenticate": true
}

Playground​

Authorization
Body

Samples​


Предпросмотр игры владельцем проекта​

GET
/v1/admin/widget-preview

Требует действующую admin-сессию, подтверждённый второй фактор и владение проектом. Браузер отправляет cookie на /v1/admin; токены в URL запрещены. CSP дополнительно разрешает ADMIN_ORIGIN только для preview. Не создаёт игровые прохождения, прогресс или награды.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Query Parameters

project_id*
Type
string
Required
mode*

Обязательный режим preview.

Type
string
Required
Valid values
"preview"
template_id
Type
string
primary_color

Preview-only branding override

Type
string
Example"#6c5ce7"

Responses​

HTML предпросмотра с HTTP CSP

Playground​

Authorization
Variables
Key
Value

Samples​


Game template catalog with stats​

GET
/v1/admin/templates

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Responses​

templates[]: engine, selectable, player_title, client_status (ready|disabled|not_built|unsupported_version), allowed_modes, прежние поля/статистика

Playground​

Authorization

Samples​


List projects for account​

GET
/v1/admin/projects

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Responses​

projects[]

Playground​

Authorization

Samples​


Create project​

POST
/v1/admin/projects

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
  
"name": "string",
  
"allowed_origins": [
  
  
"string"
  
]
}

Responses​

project

Playground​

Authorization
Body

Samples​


Get project​

GET
/v1/admin/projects/{project_id}

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

project + play_settings: active_players_24h (distinct активные игроки текущей механики с активностью за 24ч, непросроченные партии), site_wheel_ready, daily_wheel_ready

Playground​

Authorization
Variables
Key
Value

Samples​


Update project settings​

PATCH
/v1/admin/projects/{project_id}

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"name": "string",
  
"allowed_origins": [
  
  
"string"
  
],
  
"active_template_id": "string",
  
"primary_color": "string",
  
"game_mode": "string",
  
"webhook_url": "string",
  
"exposure_mode": "string",
  
"play_mechanic": "match3_v1",
  
"entry_mode": "string",
  
"lobby_wheel_enabled": true
}

Responses​

project

Playground​

Authorization
Variables
Key
Value
Body

Samples​


List API keys​

GET
/v1/admin/projects/{project_id}/api-keys

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

api_keys[]

Playground​

Authorization
Variables
Key
Value

Samples​


Create API key (secret shown once)​

POST
/v1/admin/projects/{project_id}/api-keys

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"name": "string",
  
"scopes": [
  
  
"string"
  
]
}

Responses​

api_key + secret

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Revoke API key​

DELETE
/v1/admin/projects/{project_id}/api-keys/{key_id}

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required
key_id*
Type
string
Required
Format
"uuid"

Responses​

revoked

Playground​

Authorization
Variables
Key
Value

Samples​


Embed snippet​

GET
/v1/admin/projects/{project_id}/embed

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

snippet, instructions

Playground​

Authorization
Variables
Key
Value

Samples​


Read published level goals of own project​

GET
/v1/admin/projects/{project_id}/level-goals

Exact published level versions for Match3, Memory and Parcel Pilot; no closed run state. Legacy templates return null mechanic, empty levels and safe legacy_goals derived from the runtime defaults merged with project overrides. Wheel has no level goals.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

Published goals

application/json
JSON
{
  
"legacy_goals": [
  
  
"string"
  
],
  
"mechanic": "string",
  
"track_version": 0,
  
"levels": [
  
  
{
  
  
  
"number": 0,
  
  
  
"level_id": "string",
  
  
  
"level_version": 0,
  
  
  
"goals": [
  
  
  
  
"string"
  
  
  
],
  
  
  
"constraints": [
  
  
  
  
"string"
  
  
  
]
  
  
}
  
]
}

Playground​

Authorization
Variables
Key
Value

Samples​


admin-promo​


Event log​

GET
/v1/admin/projects/{project_id}/events

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Query Parameters

event_type
Type
string
external_user_id
Type
string
since
Type
string
Format
"date-time"
until
Type
string
Format
"date-time"
limit
Type
integer
Default
50
Maximum
500
cursor

opaque, from a previous response's next_cursor

Type
string

Responses​

{events: [], next_cursor: string|null}

Playground​

Authorization
Variables
Key
Value

Samples​


Export event log as CSV (streamed, unlimited rows, same filters as the list)​

GET
/v1/admin/projects/{project_id}/events/export

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Query Parameters

event_type
Type
string
external_user_id
Type
string
since
Type
string
Format
"date-time"
until
Type
string
Format
"date-time"

Responses​

text/csv attachment, streamed; formula-injection-safe (CWE-1236)

Playground​

Authorization
Variables
Key
Value

Samples​


GDPR delete player data​

DELETE
/v1/admin/projects/{project_id}/players/{external_user_id}/data

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required
external_user_id*
Type
string
Required

Responses​

Deletion summary

Playground​

Authorization
Variables
Key
Value

Samples​


List campaigns​

GET
/v1/admin/projects/{project_id}/campaigns

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

campaigns[]

Playground​

Authorization
Variables
Key
Value

Samples​


Create campaign​

POST
/v1/admin/projects/{project_id}/campaigns

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"name": "string",
  
"trigger_type": "game_won",
  
"trigger_params": {
  
},
  
"reward_type": "string",
  
"reward_metadata": {
  
},
  
"max_per_user": 1,
  
"webhook_url": "string",
  
"starts_at": "string",
  
"ends_at": "string"
}

Responses​

campaign

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Webhook delivery log​

GET
/v1/admin/projects/{project_id}/webhooks/deliveries

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

deliveries[]

Playground​

Authorization
Variables
Key
Value

Samples​


Retry failed webhook delivery​

POST
/v1/admin/projects/{project_id}/webhooks/deliveries/{delivery_id}/retry

Resets the delivery's attempt count and backoff schedule and queues it for another attempt. Scoped to project_id: a delivery_id belonging to a different project returns 404 rather than retrying it.

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required
delivery_id*
Type
string
Required
Format
"uuid"

Responses​

queued

Playground​

Authorization
Variables
Key
Value

Samples​


Reveal the current webhook signing secret​

POST
/v1/admin/projects/{project_id}/webhook-secret/reveal

The secret is never chosen by the integrator — it's derived per project from the platform's own master key and versioned. This is the only way to obtain it.

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

{ secret, version }

application/json
JSON
{
  
"secret": "string",
  
"version": 0
}

Playground​

Authorization
Variables
Key
Value

Samples​


Rotate the webhook signing secret​

POST
/v1/admin/projects/{project_id}/webhook-secret/rotate

Generates a new secret and increments the version. Outbound deliveries already queued re-sign with the new secret on their next attempt (they read the project's current version at send time, not a snapshot from when they were enqueued). The previous version is still accepted by the platform's own test-inbox receiver for a 24-hour grace window.

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

{ secret, version }

application/json
JSON
{
  
"secret": "string",
  
"version": 0
}

Playground​

Authorization
Variables
Key
Value

Samples​


Send test webhook payload​

POST
/v1/admin/projects/{project_id}/webhooks/test

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"webhook_url": "string"
}

Responses​

HTTP status from customer endpoint

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Player progress per template​

GET
/v1/admin/projects/{project_id}/players/{external_user_id}/progress

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required
external_user_id*
Type
string
Required

Responses​

templates[]

Playground​

Authorization
Variables
Key
Value

Samples​


Dashboard metrics​

GET
/v1/admin/projects/{project_id}/analytics/overview

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

dau, wau, d1/d7 return, preview→play funnel, avg session, fraud_flags, webhook_failures

Playground​

Authorization
Variables
Key
Value

Samples​


A/B cohort comparison​

GET
/v1/admin/projects/{project_id}/analytics/ab

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

enabled, cohorts[]

Playground​

Authorization
Variables
Key
Value

Samples​


Retention funnel start → day N → complete​

GET
/v1/admin/projects/{project_id}/analytics/funnel

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Query Parameters

day_n
Type
integer
Default
7

Responses​

started, returned_on_day_n, completed_by_day_n

Playground​

Authorization
Variables
Key
Value

Samples​


Full-range daily session-start series for the dashboard chart​

GET
/v1/admin/projects/{project_id}/analytics/session-series

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Query Parameters

days
Type
integer
Default
7
Minimum
1
Maximum
90

Responses​

{series: [{date, count}], delta_pct: number|null}

Playground​

Authorization
Variables
Key
Value

Samples​


Start a new experiment (fresh bucket assignments going forward; past exposures kept)​

POST
/v1/admin/projects/{project_id}/experiment/restart

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

{experiment_key: string}

Playground​

Authorization
Variables
Key
Value

Samples​


Player session history​

GET
/v1/admin/projects/{project_id}/players/{external_user_id}/sessions

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required
external_user_id*
Type
string
Required

Query Parameters

limit
Type
integer
Default
50

Responses​

sessions[]

Playground​

Authorization
Variables
Key
Value

Samples​


Player game runs (safe fields only, no closed engine state)​

GET
/v1/admin/projects/{project_id}/players/{external_user_id}/runs

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required
external_user_id*
Type
string
Required

Query Parameters

limit
Type
integer
Default
50

Responses​

runs[]

Playground​

Authorization
Variables
Key
Value

Samples​


Commands (moves) recorded for one game run, scoped to the owning project​

GET
/v1/admin/projects/{project_id}/runs/{run_id}/commands

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required
run_id*
Type
string
Required
Format
"uuid"

Responses​

commands[]

Playground​

Authorization
Variables
Key
Value

Samples​


Reward claims state log​

GET
/v1/admin/projects/{project_id}/reward-claims

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

claims[]

Playground​

Authorization
Variables
Key
Value

Samples​


Public plan catalog​

GET
/v1/admin/billing/plans

Responses​

plans[]

Playground​

Samples​


Current plan and usage​

GET
/v1/admin/billing

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Responses​

plan, usage

Playground​

Authorization

Samples​


Upgrade plan​

POST
/v1/admin/billing/upgrade

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
  
"plan_id": "growth"
}

Responses​

ok

Playground​

Authorization
Body

Samples​


List invoices​

GET
/v1/admin/billing/invoices

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Responses​

invoices[]

Playground​

Authorization

Samples​


Create Stripe Checkout session for issued invoice​

POST
/v1/admin/billing/invoices/{invoice_id}/checkout

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

invoice_id*
Type
string
Required
Format
"uuid"

Responses​

checkout_url, session_id

Playground​

Authorization
Variables
Key
Value

Samples​


Mark invoice paid (dev only, when Stripe disabled)​

POST
/v1/admin/billing/invoices/{invoice_id}/pay-simulated

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

invoice_id*
Type
string
Required
Format
"uuid"

Responses​

status paid

Playground​

Authorization
Variables
Key
Value

Samples​


webhooks​

Inbound provider and test-inbox webhooks


Stripe webhook (checkout.session.completed)​

POST
/v1/webhooks/stripe

Parameters​

Header Parameters

stripe-signature*
Type
string
Required

Responses​

received

Playground​

Headers

Samples​


Receive a test webhook by inbox token​

POST
/v1/webhooks/inbox/{token}

Локальный тестовый приёмник: секретный token принадлежит проекту. Не путь выдачи награды интегратору.

Parameters​

Header Parameters

X-RetentionPlay-Signature

Обязателен этот заголовок или старый X-PlayFlow-Signature; HMAC по сырому телу.

Type
string

Path Parameters

token*
Type
string
Required

Responses​

Successful response

Playground​

Headers
Variables
Key
Value

Samples​


admin-onboarding​


Onboarding checklist state​

GET
/v1/admin/onboarding

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Responses​

steps, next_step, finished

Playground​

Authorization

Samples​


Confirm successful embed-code copy​

POST
/v1/admin/onboarding/{step}/complete

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

step*
Type
string
Required
Valid values
"embed_copied"

Responses​

Updated onboarding state

Playground​

Authorization
Variables
Key
Value

Samples​


Economy settings​

GET
/v1/admin/projects/{project_id}/economy

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

economy_enabled, economy_config

Playground​

Authorization
Variables
Key
Value

Samples​


Update economy settings​

PATCH
/v1/admin/projects/{project_id}/economy

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"economy_enabled": true,
  
"economy_config": {
  
}
}

Responses​

ok

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Admin grant resources to player​

POST
/v1/admin/projects/{project_id}/economy/grant

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"external_user_id": "string",
  
"resource_id": "string",
  
"amount": 0
}

Responses​

Granted

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Fraud flags for project​

GET
/v1/admin/projects/{project_id}/fraud-flags

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

flags[]

Playground​

Authorization
Variables
Key
Value

Samples​


admin​


Upload the project background​

PUT
/v1/admin/projects/{project_id}/game-assets/{slot}/background

Принимает multipart-поле file. Формат определяется декодированием, а не расширением: PNG, JPEG или WebP, до 5 MiB, портретное изображение от 420×760 до 2160×3840 с отношением сторон 0.50–0.65. Произвольный URL не принимается. Сервер сохраняет оригинал и непрозрачную рантайм-копию WebP 840×1520, cover по центру, q78/70/62, не более220 КиБ; слот и play_config_revision обновляются одной SQL-инструкцией. EXIF-ориентация применяется перед нормализацией; оригинальные байты сохраняются. Габариты проверяются до выделения пиксельного буфера, бюджет декодера 64 MiB. На процесс допускаются две одновременные нормализации; перегрузка возвращает 429 с Retry-After: 1.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required
slot*

lobby или id механики вида run из реестра; колесо и старые шаблоны запрещены.

Type
string
Required
Example"lobby"

Request Body​

multipart/form-data
Format"binary"

Responses​

Фон сохранён

application/json
JSON
{
  
"slot": "string",
  
"background": {
  
  
"asset_id": "string",
  
  
"format": "string",
  
  
"width": 0,
  
  
"height": 0,
  
  
"bytes": 0,
  
  
"sha256": "string",
  
  
"original": "[Circular Reference]"
  
},
  
"config_revision": 0,
  
"url": "string"
}

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Reset the project background to the default​

DELETE
/v1/admin/projects/{project_id}/game-assets/{slot}/background

Снимает метаданные фона. Файл на диске остаётся; физическая уборка — отдельная задача. Слот и play_config_revision обновляются одной SQL-инструкцией.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required
slot*

lobby или id механики вида run из реестра; колесо и старые шаблоны запрещены.

Type
string
Required
Example"lobby"

Responses​

Возвращён базовый фон

application/json
JSON
{
  
"slot": "string",
  
"background": {
  
},
  
"config_revision": 0
}

Playground​

Authorization
Variables
Key
Value

Samples​


End the cookie admin session​

POST
/v1/admin/auth/logout

Requires active registry session; atomically revokes its server record and clears both cookie paths. Cookie callers require allowed Origin.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Responses​

Successful response

Playground​

Authorization

Samples​


List current account notifications​

GET
/v1/admin/notifications

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Query Parameters

project_id
Type
string

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Search current account projects and players​

GET
/v1/admin/search

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Query Parameters

q*
Type
string
Required
project_id
Type
string

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Project campaign analytics​

GET
/v1/admin/projects/{project_id}/analytics/case

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Project leaderboard​

GET
/v1/admin/projects/{project_id}/leaderboard

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Project fraud metrics​

GET
/v1/admin/projects/{project_id}/fraud-metrics

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Read player fraud status​

GET
/v1/admin/projects/{project_id}/players/{external_user_id}/fraud

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required
external_user_id*
Type
string
Required

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Set player fraud status​

PUT
/v1/admin/projects/{project_id}/players/{external_user_id}/fraud

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required
external_user_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"state": "string",
  
"reason": "string",
  
"expires_at": "string"
}

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Resolve a fraud flag​

PATCH
/v1/admin/projects/{project_id}/fraud-flags/{flag_id}

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required
flag_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"resolution": "string"
}

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Release a held or reviewed reward claim​

POST
/v1/admin/projects/{project_id}/reward-claims/{claim_id}/release

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required
claim_id*
Type
string
Required

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Reject a held or reviewed reward claim​

POST
/v1/admin/projects/{project_id}/reward-claims/{claim_id}/reject

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required
claim_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"reason": "string"
}

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Read project test webhook inbox​

GET
/v1/admin/projects/{project_id}/webhooks/inbox

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Clear project test webhook inbox​

DELETE
/v1/admin/projects/{project_id}/webhooks/inbox

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Rotate project test inbox token​

POST
/v1/admin/projects/{project_id}/webhooks/inbox/rotate

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value

Samples​


Update a campaign​

PATCH
/v1/admin/projects/{project_id}/campaigns/{campaign_id}

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Parameters​

Path Parameters

project_id*
Type
string
Required
campaign_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"name": "string",
  
"trigger_type": "game_won",
  
"trigger_params": {
  
},
  
"reward_type": "string",
  
"reward_metadata": {
  
},
  
"max_per_user": 0,
  
"webhook_url": "string",
  
"starts_at": "string",
  
"ends_at": "string"
}

Responses​

Successful response

Playground​

Authorization
Variables
Key
Value
Body

Samples​


Read account two-factor status​

GET
/v1/admin/two-factor/status

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Responses​

Successful response

Playground​

Authorization

Samples​


Begin TOTP enrollment​

POST
/v1/admin/two-factor/enroll

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Responses​

Successful response

Playground​

Authorization

Samples​


Confirm TOTP enrollment​

POST
/v1/admin/two-factor/confirm

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Request Body​

application/json
JSON
{
  
"code": "string"
}

Responses​

Successful response

Playground​

Authorization
Body

Samples​


Verify TOTP or recovery code​

POST
/v1/admin/two-factor/challenge

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Request Body​

application/json
JSON
{
  
"code": "string"
}

Responses​

Successful response

Playground​

Authorization
Body

Samples​


Sign in using a one-time recovery code​

POST
/v1/admin/two-factor/recovery

Authorizations​

AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)
or
AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)

Request Body​

application/json
JSON
{
  
"code": "string"
}

Responses​

Successful response

Playground​

Authorization
Body

Samples​


Read published R1 wheel​

GET
/v1/wheel

30 reads/minute/player. Anonymous sessions can use only free-play. no-store response.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Parameters​

Query Parameters

wheel_id
Type
string
Valid values
"daily""site"
Default
"daily"

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Variables
Key
Value

Samples​


Draw and persist one R1 spin​

POST
/v1/wheel/spins

512-byte body ceiling. Exact durable spin_id replay before quotas; new spins 6/minute and 30/hour/player plus daily entitlements. R1 tickets/resources only, no material prizes.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Parameters​

Header Parameters

Origin*

Admin site origin for cookie writes; API origin for public writes

Type
string
Required

Request Body​

application/json
JSON
{
  
"spin_id": "string",
  
"wheel_id": "string",
  
"wheel_version": 0,
  
"source": "string"
}

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Headers
Body

Samples​


Read owned spin​

GET
/v1/wheel/spins/{spin_id}

Only this project/player can read or acknowledge the spin. 30 reads/minute/player.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Parameters​

Path Parameters

spin_id*
Type
string
Required
Format
"uuid"

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Variables
Key
Value

Samples​


Acknowledge result (idempotent)​

POST
/v1/wheel/spins/{spin_id}/seen

Only this project/player can read or acknowledge the spin. 30 reads/minute/player.

Authorizations​

SessionBearer

Platform-issued identified or anonymous player session token

Type
HTTP (bearer)

Parameters​

Header Parameters

Origin*

Admin site origin for cookie writes; API origin for public writes

Type
string
Required

Path Parameters

spin_id*
Type
string
Required
Format
"uuid"

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Headers
Variables
Key
Value

Samples​


Built-in wheel SVG icon​

GET
/v1/game-assets/wheel/icons/{icon}

Parameters​

Path Parameters

icon*
Type
string
Required

Responses​

image/svg+xml; public max-age=3600

Playground​

Variables
Key
Value

Samples​


GET wheel settings​

GET
/v1/admin/projects/{project_id}/wheels/settings

Authenticated project owner with verified 2FA. Simulation draws 10000 results and creates no award. Published weights are not in public views.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Variables
Key
Value

Samples​


PUT wheel settings​

PUT
/v1/admin/projects/{project_id}/wheels/settings

Authenticated project owner with verified 2FA. Simulation draws 10000 results and creates no award. Published weights are not in public views.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Header Parameters

Origin*

Admin site origin for cookie writes; API origin for public writes

Type
string
Required

Path Parameters

project_id*
Type
string
Required

Request Body​

application/json
JSON
{
  
"timezone": "string"
}

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Headers
Variables
Key
Value
Body

Samples​


GET wheel draft​

GET
/v1/admin/projects/{project_id}/wheels/{wheel_id}/draft

Authenticated project owner with verified 2FA. Simulation draws 10000 results and creates no award. Published weights are not in public views.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required
wheel_id*
Type
string
Required
Valid values
"daily""site"

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Variables
Key
Value

Samples​


PUT wheel draft​

PUT
/v1/admin/projects/{project_id}/wheels/{wheel_id}/draft

Authenticated project owner with verified 2FA. Simulation draws 10000 results and creates no award. Published weights are not in public views.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Header Parameters

Origin*

Admin site origin for cookie writes; API origin for public writes

Type
string
Required

Path Parameters

project_id*
Type
string
Required
wheel_id*
Type
string
Required
Valid values
"daily""site"

Request Body​

application/json
JSON
{
  
"free_spins_per_day": 0,
  
"max_spins_per_day": 0,
  
"ticket_cost": 0,
  
"segments": [
  
  
{
  
  
}
  
],
  
"rules": {
  
  
"text": "string",
  
  
"organizer": {
  
  
}
  
},
  
"budget_daily_minor": 0,
  
"budget_total_minor": 0
}

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Headers
Variables
Key
Value
Body

Samples​


POST wheel publish​

POST
/v1/admin/projects/{project_id}/wheels/{wheel_id}/publish

Authenticated project owner with verified 2FA. Simulation draws 10000 results and creates no award. Published weights are not in public views.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Header Parameters

Origin*

Admin site origin for cookie writes; API origin for public writes

Type
string
Required

Path Parameters

project_id*
Type
string
Required
wheel_id*
Type
string
Required
Valid values
"daily""site"

Request Body​

application/json
JSON
{
  
"expected_draft_hash": "string"
}

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Headers
Variables
Key
Value
Body

Samples​


POST wheel simulate​

POST
/v1/admin/projects/{project_id}/wheels/{wheel_id}/simulate

Authenticated project owner with verified 2FA. Simulation draws 10000 results and creates no award. Published weights are not in public views.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Header Parameters

Origin*

Admin site origin for cookie writes; API origin for public writes

Type
string
Required

Path Parameters

project_id*
Type
string
Required
wheel_id*
Type
string
Required
Valid values
"daily""site"

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Headers
Variables
Key
Value

Samples​


GET wheel stats​

GET
/v1/admin/projects/{project_id}/wheels/{wheel_id}/stats

Authenticated project owner with verified 2FA. Simulation draws 10000 results and creates no award. Published weights are not in public views.

Authorizations​

AdminCookie

HttpOnly сессия админки. Изменяющие запросы с cookie требуют допустимый Origin; Bearer — альтернатива.

Type
API Key (cookie: playflow_admin_session)
or
AdminBearer

Admin JWT from signup/login

Type
HTTP (bearer)

Parameters​

Path Parameters

project_id*
Type
string
Required
wheel_id*
Type
string
Required
Valid values
"daily""site"

Responses​

JSON response; see /integration/wheel

Playground​

Authorization
Variables
Key
Value

Samples​


Powered by VitePress OpenAPI

Internal & integration documentation