Appearance
(Operator implements, optional) Receive the end-of-animation signal
POST
/reportAnimationEnd
Sent once the animation of the current gameround has finished, the spin / play button is active again and the player can start a new game. This call should never fail and must always return HTTP 200.
Use case: a round can be closed immediately in a single doTransactions call while client animations are still running, so from the player's point of view the game is still going. Where game start / end events have to be reported to a regulator's safe server (mostly German regulation), this call provides the correct end event.
The operator has to request that this endpoint be enabled (see the reportAnimationEnd game setting in Appendix C); otherwise nothing is sent.
Fields to sign (in order): secret, X-H-AUTH-ID, X-H-TIMESTAMP, gameRound.
Authorizations
hiziAuthId
Operator ID. Sent on every request in both directions, and part of every signature.
Type
API Key (header: X-H-AUTH-ID)
hiziAuthSignature
Signature of the request, sent on every request in both directions.
OpenAPI cannot express an HMAC-over-computed-string scheme natively, so this is modelled as an apiKey header. The value is not a static key: it is the base64-encoded SHA-256 HMAC digest of a defined, ordered set of request fields joined with a hash character (#).
The first three fields are always the shared secret, the X-H-AUTH-ID header and the X-H-TIMESTAMP header; the remaining fields differ per operation and are listed in each operation's description under "Fields to sign". For doTransactions the per- transaction hashes (and non-zero amounts) are appended in exactly the order the transactions appear in the payload.
The secret is retrieved by logging in to the hizi.io backoffice, which also provides sample implementations. Including the timestamp in the signature is what makes it safe to share the secret without ever sending it.
Type
API Key (header: X-H-AUTH-SIG)
hiziTimestamp
ISO 8601 timestamp of the request (UTC recommended, e.g. 2020-01-21T14:48:04Z). Sent on every request in both directions and always included in the signature.
Type
API Key (header: X-H-TIMESTAMP)
Request Body
application/json
JSON "gameRound": "123e4567-e89b-12d3-a456-426655440000"
{
}
Responses
Success. The documented sample response is an empty JSON object; an errorCode object may be present but is ignored on a 200 unless X-H-ERROR-ID is also set.
application/json
JSON "errorCode": { "id": 1, "msg": "player id unknown", "clientmsg": "You reached your daily betting limit!" }, "additionalProperties": "string"
{
}