Aggregator Wallet API
This document describes the connection between an aggregator partner and Prediction Markets.
Read the prefix in each path to find the direction. The prefix is the rule, and the name after the prefix is not.
a8r_provider— You call these endpoints on Prediction Markets. The Launcher endpoints start a game session for a player. The Round Details endpoint reads the details of one round.provider_a8r— Prediction Markets calls these endpoints on your system. The Player endpoint reads the player's balance. The Round endpoints debit a bet, credit a win, or do both.
The two prefixes are not interchangeable. Each prefix applies to one direction only. Write each path exactly as shown. Do not replace a prefix with the name of your company or your system.
Every request in both directions must include a valid X-REQUEST-SIGN header. The X-REQUEST-SIGN security scheme gives the signature method.
Authentication
- API Key: X-REQUEST-SIGN
The HMAC-SHA256 hex signature of the raw request body.
- Use the shared secret that Prediction Markets gives you before you go live.
- Calculate the signature:
signature = hex(HMAC-SHA256(secret, raw_request_body)) - Send the signature in the
X-REQUEST-SIGNheader.
Sign the exact bytes of the body. If you build the JSON again before you sign it, the signature can be different and the request fails with status code 403.
This scheme has no timestamp and no nonce value. This scheme does not prevent an attacker from sending a copy of a request a second time.
Security Scheme Type: | apiKey |
|---|---|
Header parameter name: | X-REQUEST-SIGN |