Hacksaw Integration Guide

Panduan Integrasi Hacksaw

Connect an operator, create players, launch Ze Zeus, and integrate either a transfer or seamless wallet using the production API contract.

Hubungkan operator, buat pemain, launch Ze Zeus, dan integrasikan transfer atau seamless wallet menggunakan kontrak API production.

Overview

Gambaran Umum

The authenticated operator determines wallet mode, currency, player ownership, and access. Game launch and wallet endpoints never accept a client-selected wallet strategy.

Operator yang terautentikasi menentukan mode wallet, currency, kepemilikan pemain, dan akses. Endpoint game launch dan wallet tidak menerima strategi wallet pilihan client.

Transfer wallet: this backend owns the playable balance and updates it atomically in PostgreSQL.

Transfer wallet: backend ini menjadi pemilik saldo bermain dan memperbaruinya secara atomik di PostgreSQL.

Seamless wallet: the operator owns the balance. This backend sends signed callbacks to the operator's configured callback URL.

Seamless wallet: operator menjadi pemilik saldo. Backend ini mengirim callback bertanda tangan ke callback URL operator.

Authentication

Autentikasi

All operator endpoints under /api/v1/users, /api/v1/game, and /api/v1/wallet require an active API token as a bearer token.

Semua endpoint operator di bawah /api/v1/users, /api/v1/game, dan /api/v1/wallet memerlukan API token aktif sebagai bearer token.

Keep API tokens and secret keys on a trusted server. Never embed them in browser JavaScript, mobile applications, launch URLs, logs, or public repositories.

Simpan API token dan secret key di server tepercaya. Jangan menaruhnya di JavaScript browser, aplikasi mobile, launch URL, log, atau repository publik.

If an operator has an IP allowlist, requests must arrive from an allowed address. X-Request-ID is optional and is returned in the response headers.

Jika operator memiliki IP allowlist, request harus berasal dari alamat yang diizinkan. X-Request-ID opsional dan dikembalikan pada header respons.

Required headersHeader wajib
Authorization: Bearer <operator_api_token>
Content-Type: application/json
X-Request-ID: 6ca6a797-a9d6-4b16-ae51-f4184472ba23

Common Response Format

Format Respons Umum

Every application outcome uses HTTP 200 OK. Read the JSON status and code; do not infer the result from HTTP status.

Semua hasil aplikasi menggunakan HTTP 200 OK. Baca status dan code pada JSON; jangan menentukan hasil dari HTTP status.

A success response has data and no error. An error response has error and no data.

Respons sukses memiliki data tanpa error. Respons gagal memiliki error tanpa data.

SuccessSukses
{
  "status": true,
  "code": "SUCCESS",
  "data": {}
}
Error
{
  "status": false,
  "code": "VALIDATION_ERROR",
  "error": {}
}

Integer Money Rules

Aturan Nominal Integer

All wallet amounts are signed 64-bit JSON integers in minor units. Never send floating-point values or numeric strings. A mutation amount must be from 1 through 1000000000000.

Semua nominal wallet adalah integer JSON 64-bit dalam minor unit. Jangan mengirim floating-point atau string angka. Amount mutasi harus dari 1 sampai 1000000000000.

  • IDR: configured with zero decimal places and multiplier 1, so 1000 means IDR 1,000.
  • Currency: exactly three uppercase ASCII letters and must match the player.
  • Overflow: credits that exceed integer balance capacity are rejected.
  • IDR: dikonfigurasi tanpa angka desimal dan multiplier 1, jadi 1000 berarti IDR 1.000.
  • Currency: tepat tiga huruf ASCII kapital dan harus sama dengan currency pemain.
  • Overflow: credit yang membuat saldo melewati kapasitas integer akan ditolak.

Idempotency

reference_id is the operator-scoped idempotency key for debit, credit, deposit, and withdraw. rollback_reference_id is the key for rollback.

reference_id adalah idempotency key per operator untuk debit, credit, deposit, dan withdraw. rollback_reference_id adalah key untuk rollback.

  • Retry an identical request with the same key to receive the original result.
  • Reusing a key with different user, amount, currency, or operation returns IDEMPOTENCY_CONFLICT.
  • One completed transaction can be rolled back only once.
  • A seamless mutation timeout is an unknown outcome. Reconcile it before retrying.
  • Retry request identik dengan key yang sama untuk menerima hasil awal.
  • Memakai ulang key dengan user, amount, currency, atau operasi berbeda menghasilkan IDEMPOTENCY_CONFLICT.
  • Satu transaksi completed hanya dapat di-rollback satu kali.
  • Timeout mutasi seamless adalah hasil yang belum diketahui. Lakukan rekonsiliasi sebelum retry.

Games: Hosts & Base URLs

Game: Host & Base URL

The API host serves operator and native gameplay APIs. The game host serves the Ze Zeus client and its static assets. The documentation host serves this guide and its protected trial launcher.

Host API melayani API operator dan gameplay native. Host game melayani client Ze Zeus beserta aset statis. Host dokumentasi melayani panduan ini dan trial launcher yang terlindungi.

Production hostsHost production
Operator API   https://api-hacksaw.ohmybet.online
Game client    https://hacksaw.ohmybet.online
Documentation https://hacksaw-docs.pages.dev
https://api-hacksaw.ohmybet.online/api/v1

Create a Player

Buat Pemain

Create the player before launch. external_user_id is the stable identity within one operator. A duplicate identity returns USER_ALREADY_EXISTS.

Buat pemain sebelum launch. external_user_id adalah identitas stabil di dalam satu operator. Identitas duplikat menghasilkan USER_ALREADY_EXISTS.

POST/api/v1/users

Request fields

Field request

operator_id      string  required  Authenticated operator UUID
external_user_id string  required  Stable player identity
username         string  optional  Display name
currency         string  required  Exact uppercase currency
operator_id      string  wajib     UUID operator terautentikasi
external_user_id string  wajib     Identitas pemain yang stabil
username         string  opsional  Nama tampilan
currency         string  wajib     Currency kapital yang tepat
Request bodyBody request
{
  "operator_id": "<operator_uuid>",
  "external_user_id": "player-1001",
  "username": "Player 1001",
  "currency": "IDR"
}
Success responseRespons sukses
{
  "status": true,
  "code": "SUCCESS",
  "data": {
    "id": "7cf96ba7-9bca-4eb8-9823-65423fdc32f1",
    "operator_id": "<operator_uuid>",
    "external_user_id": "player-1001",
    "username": "Player 1001",
    "currency": "IDR",
    "balance_amount": 0,
    "rtp": 96.00,
    "status": "active",
    "created_at": "2026-06-15T12:00:00Z",
    "updated_at": "2026-06-15T12:00:00Z"
  }
}

Launch a Game

Launch Game

Request a fresh launch URL from your trusted backend, then redirect or open it in the player's browser. The launch session expires after 30 minutes.

Minta launch URL baru dari backend tepercaya Anda, lalu redirect atau buka URL tersebut di browser pemain. Sesi launch berakhir setelah 30 menit.

POST/api/v1/game/launch

Request fields

Field request

game_code       string  required  Canonical game ID, currently "1508"
external_user_id string required  Existing active player
currency        string  required  Must match player currency
language        string  optional  Defaults to "en"
device          string  optional  "desktop" or "mobile"
game_code       string  wajib     ID game kanonik, saat ini "1508"
external_user_id string wajib     Pemain aktif yang sudah ada
currency        string  wajib     Harus sama dengan currency pemain
language        string  opsional  Default "en"
device          string  opsional  "desktop" atau "mobile"

Unknown games return NOT_FOUND. Unknown players return USER_NOT_FOUND. Currency mismatch returns CURRENCY_MISMATCH.

Game tidak dikenal menghasilkan NOT_FOUND. Pemain tidak dikenal menghasilkan USER_NOT_FOUND. Currency berbeda menghasilkan CURRENCY_MISMATCH.

Request bodyBody request
{
  "game_code": "1508",
  "external_user_id": "player-1001",
  "currency": "IDR",
  "language": "en",
  "device": "desktop"
}
Success responseRespons sukses
{
  "status": true,
  "code": "SUCCESS",
  "data": {
    "launch_url": "https://hacksaw.ohmybet.online/1508/1.32.0/index.html?...",
    "game_code": "1508",
    "currency": "IDR"
  }
}
curl
curl -sS https://api-hacksaw.ohmybet.online/api/v1/game/launch \
  -H "Authorization: Bearer <operator_api_token>" \
  -H "Content-Type: application/json" \
  --data '{
    "game_code":"1508",
    "external_user_id":"player-1001",
    "currency":"IDR",
    "language":"en",
    "device":"desktop"
  }'

Native Gameplay Protocol

Protokol Gameplay Native

After launch, the game client calls these endpoints directly. Operators should not call them and should not parse or modify their payloads.

Setelah launch, client game memanggil endpoint berikut secara langsung. Operator tidak perlu memanggil, membaca, atau mengubah payload-nya.

  • POST /api/play/authenticate
  • POST /api/play/gameLaunch
  • POST /api/play/bet
  • GET /api/meta/gameInfo

Native responses use statusCode and statusMessage, not the operator API envelope. A native success has statusCode: 0.

Respons native menggunakan statusCode dan statusMessage, bukan envelope API operator. Respons native sukses memiliki statusCode: 0.

Native success exampleContoh sukses native
{
  "statusCode": 0,
  "statusMessage": "",
  "serverTime": "2026-06-15T12:00:00Z"
}
Native error exampleContoh error native
{
  "statusCode": 7,
  "statusMessage": "Session expired"
}

Supported Games

Game Tersedia

The production catalog currently exposes one canonical game configuration.

Katalog production saat ini menyediakan satu konfigurasi game kanonik.

game_code          1508
name               Ze Zeus
version            1.32.0
currency           IDR
currency decimals  0
currency multiplier 1
bet levels         10, 20, 50, 100, 200, 500, 1000
default bet        100
max exposure       10000000
max feature cost   250000

Live Trial

Coba Langsung

The button calls a same-origin Cloudflare Pages Function. The function keeps the operator token server-side, requests a fresh launch URL for the fixed trial player, and returns only the launch result.

Tombol memanggil Cloudflare Pages Function pada origin yang sama. Function menyimpan token operator di server, meminta launch URL baru untuk pemain trial tetap, dan hanya mengembalikan hasil launch.

game       Ze Zeus
game_code  1508
currency   IDR
player     trial-player-001

Ze Zeus

slot

Production trial using a dedicated transfer-wallet player.

Trial production menggunakan pemain transfer-wallet khusus.


Transfer Wallet Flow

Alur Transfer Wallet

Transfer mode stores the authoritative balance locally. Create the player, deposit funds, launch the game, and use the ledger endpoints for audit or controlled corrections.

Mode transfer menyimpan saldo utama secara lokal. Buat pemain, deposit dana, launch game, lalu gunakan endpoint ledger untuk audit atau koreksi terkontrol.

  1. Create the player with POST /api/v1/users.
  2. Fund it with POST /api/v1/wallet/deposit.
  3. Launch game 1508.
  4. Use balance and transactions for reconciliation.
  5. Rollback one completed debit or credit only when required.
  1. Buat pemain dengan POST /api/v1/users.
  2. Isi dana dengan POST /api/v1/wallet/deposit.
  3. Launch game 1508.
  4. Gunakan balance dan transactions untuk rekonsiliasi.
  5. Rollback satu debit atau credit completed hanya bila diperlukan.

Balance

Returns the current authoritative local balance. This read does not create a ledger row.

Mengembalikan saldo lokal utama saat ini. Operasi baca ini tidak membuat row ledger.

GET/api/v1/wallet/balance
external_user_id string required
currency         string required
RequestRequest
GET /api/v1/wallet/balance?external_user_id=player-1001&currency=IDR
Success responseRespons sukses
{
  "status": true,
  "code": "SUCCESS",
  "data": {
    "balance_amount": 1000000,
    "currency": "IDR",
    "timestamp": "2026-06-15T12:00:00Z"
  }
}

Deposit

Credits a transfer player's local balance and creates one completed credit ledger row.

Menambah saldo lokal pemain transfer dan membuat satu row ledger credit berstatus completed.

POST/api/v1/wallet/deposit
operator_id      string  required
external_user_id string  required
reference_id     string  required, unique per operator
amount           integer required, 1..1000000000000
currency         string  required
Request bodyBody request
{
  "operator_id": "<operator_uuid>",
  "external_user_id": "player-1001",
  "reference_id": "deposit-20260615-0001",
  "amount": 500000,
  "currency": "IDR"
}
Response data fieldsField data respons
id, operator_id, user_id, external_user_id,
wallet_type, type, amount, currency,
balance_before, balance_after, reference_id,
status, failure_code, metadata,
created_at, completed_at

Withdraw

Debits the local balance for an operator-controlled transfer-out. Insufficient funds do not change the balance.

Mengurangi saldo lokal untuk transfer-out yang dikontrol operator. Saldo tidak cukup tidak mengubah balance.

POST/api/v1/wallet/withdraw

The body shape is identical to deposit. Use a new reference_id for every distinct transfer.

Bentuk body sama dengan deposit. Gunakan reference_id baru untuk setiap transfer yang berbeda.

Request bodyBody request
{
  "operator_id": "<operator_uuid>",
  "external_user_id": "player-1001",
  "reference_id": "withdraw-20260615-0001",
  "amount": 100000,
  "currency": "IDR"
}

Debit & Credit

These provider-neutral wallet operations are used for game financial movement. Debit removes funds; credit adds funds. The game engine uses the same wallet gateway internally.

Operasi wallet netral-provider ini digunakan untuk pergerakan finansial game. Debit mengurangi dana; credit menambah dana. Game engine memakai wallet gateway yang sama secara internal.

POST/api/v1/wallet/debit
POST/api/v1/wallet/credit

Unlike deposit and withdraw, these bodies do not contain operator_id.

Berbeda dari deposit dan withdraw, body ini tidak memiliki operator_id.

Debit or credit bodyBody debit atau credit
{
  "external_user_id": "player-1001",
  "reference_id": "round-5501-bet",
  "amount": 100,
  "currency": "IDR"
}
Response dataData respons
{
  "transaction_id": "659c881f-8afd-44f5-b35e-57f75dd07aa2",
  "balance_after": 999900,
  "currency": "IDR",
  "timestamp": "2026-06-15T12:00:00Z"
}

Rollback

Reverses one eligible completed debit or credit. The backend derives the original amount and currency; do not send them.

Membalik satu debit atau credit completed yang memenuhi syarat. Backend mengambil amount dan currency dari transaksi awal; jangan mengirimkannya.

POST/api/v1/wallet/rollback
Request bodyBody request
{
  "external_user_id": "player-1001",
  "original_reference_id": "round-5501-bet",
  "rollback_reference_id": "round-5501-bet-rollback"
}
Important codesKode penting
TRANSACTION_NOT_FOUND
TRANSACTION_NOT_ROLLBACKABLE
TRANSACTION_ALREADY_ROLLED_BACK
IDEMPOTENCY_CONFLICT

Transactions

Lists operator-owned ledger rows. Filters are optional. Default limit is 20; maximum limit is 100; maximum offset is 10000.

Menampilkan row ledger milik operator. Filter bersifat opsional. Limit default 20; limit maksimum 100; offset maksimum 10000.

GET/api/v1/wallet/transactions
external_user_id optional
type             optional: credit, debit, rollback
status           optional: pending, completed, failed,
                           reversed, mismatch
reference_id     optional
limit            optional: 1..100
offset           optional: 0..10000
RequestRequest
GET /api/v1/wallet/transactions?external_user_id=player-1001&status=completed&limit=20&offset=0
Response shapeBentuk respons
{
  "status": true,
  "code": "SUCCESS",
  "data": {
    "items": [],
    "limit": 20,
    "offset": 0
  }
}

Transfer Wallet Test Checklist

Checklist Pengujian Transfer Wallet

  • Create one active IDR player and verify duplicate creation.
  • Deposit, balance-check, withdraw, debit, credit, and rollback.
  • Repeat identical idempotent requests concurrently and verify one financial effect.
  • Reuse a key with a different amount and expect IDEMPOTENCY_CONFLICT.
  • Verify insufficient debit leaves balance unchanged.
  • Buat satu pemain IDR aktif dan uji pembuatan duplikat.
  • Uji deposit, balance, withdraw, debit, credit, dan rollback.
  • Ulangi request idempotent identik secara concurrent dan pastikan hanya ada satu efek finansial.
  • Pakai ulang key dengan amount berbeda dan harapkan IDEMPOTENCY_CONFLICT.
  • Pastikan debit dengan saldo tidak cukup tidak mengubah balance.

Error Codes

Kode Error

Handle errors by stable code. Do not depend on a human-readable message because public API errors intentionally do not include one.

Tangani error berdasarkan code yang stabil. Jangan bergantung pada pesan untuk manusia karena error API publik memang tidak menyertakannya.