Skip to main content

Security and Limitations

This page is two lists: what you must not do, and the platform behavior to design around.

It covers only what you cannot learn from the API reference or from general web practice.

The platform does not accept cookie credentials cross-origin, so the token travels in a header your code sets. On any page that calls the platform directly, that puts it in reach of JavaScript.

Prohibitions​

1. The operator auth_token must never reach the browser​

The platform stores your auth_token server-side against the Bettor and uses it only to call your wallet endpoints. A custom frontend never needs it, and no platform endpoint returns it.

2. The platform JWT must not be stored in localStorage​

Keep it in memory. Where the session must survive a reload, sessionStorage is the ceiling.

Neither choice stops cross-site scripting. Prefer memory because the token stays valid for 24 hours, so any copy that outlives the tab is still usable.

3. rejection_reason must never be rendered or logged​

The field is an internal diagnostic string. It is not display copy, it is not stable, and it is not translated.

Bind your message and your localization to rejection_code instead. See Handle a rejection.

4. session_request_id must be generated server-side​

It must not be logged, must not be sent to analytics, and must not be persisted anywhere. It is single-use and lives 1 to 2 minutes.

One more rule sits with localization rather than security: never render a server message string to a bettor. Those strings are English and are not translated. Render your own copy, keyed off status and rejection_code. See Design for mixed-language content.

Platform behavior to plan for​

Sessions​

  • The platform JWT is valid for 24 hours. Run the session exchange again to get a new one.
  • Treat every 401 the same way: run the session exchange again.
  • POST /api/v1/auth/session answers 500 for any request it cannot accept. Retry once with a fresh session_request_id, then show a general error. partner_slug is required alongside it.

Bets​

  • Read bet status by polling. See Poll until the bet resolves.
  • A bet does not always reach a terminal status inside your poll window. Tell the bettor it is still processing and let them check their bet history.
  • After a failed bet, read the balance from GET /api/v1/auth/me to confirm the stake returned.
  • Cash out is not available. A bet settles when its market resolves.

Timeouts​

  • Set your client timeouts above 3 s. The platform answers 500 when it cuts a slow request.