All posts
Checklist

Casino API Integration Checklist — 22 Checks Before Go-Live

Sep 13, 2026 · 14 min read

A casino API integration looks simple on paper — get a key, launch a game URL, handle a few callbacks. In production, small oversights become expensive player-facing bugs. Use this checklist before you flip the switch.

1. Credentials & environment

  • Sandbox and production keys are stored in separate secret managers, never in Git or client bundles.
  • Base URLs, provider IDs, and callback secrets are environment-specific.
  • IP whitelists include the aggregator's egress ranges and any failover proxies.

2. Wallet callback endpoints

  • Balance returns the current player balance instantly, with no side effects.
  • Debit subtracts the bet amount atomically and rejects duplicate transaction IDs.
  • Credit adds winnings only when the corresponding debit exists and is not already credited.
  • Rollback reverses a pending debit when a round is cancelled or timed out.
  • Every response includes the new balance and a status code the provider expects.

3. Signature verification

Verify HMAC or JWT signatures on every callback before touching the balance. Reject unknown algorithms, expired timestamps, and replayed nonces. Log verification failures with the raw payload for dispute resolution.

4. Idempotency & concurrency

  • The same transaction ID cannot be processed twice, even under retry storms.
  • Database updates use row-level locking or optimistic concurrency to avoid race conditions.
  • Timeouts from the provider trigger a status query before any manual reconciliation.

5. Game launch flow

  • Player ID, currency, language, and device are passed correctly.
  • The returned launch URL is used once and expires within the documented window.
  • Mobile browsers open the game in the same session or a trusted WebView.
  • Free/demo mode is wired separately from real-money mode.

6. Lobby & catalog

  • Game list is cached with a TTL that matches provider update frequency.
  • Filters by provider, category, RTP, volatility, and currency work on real data.
  • Broken or removed games are hidden automatically.
  • Thumbnails load from a CDN and have a branded fallback.

7. Latency & reliability

  • Wallet callback p95 latency is under 200 ms from the nearest edge.
  • Provider API calls have timeouts, retries with backoff, and circuit breakers.
  • Failover regions are tested, not just documented.

8. Player & session safety

  • Session tokens rotate and expire correctly.
  • Self-exclusion, deposit limits, and cooling-off periods are enforced before any bet.
  • Geo-blocking and KYC status are checked at login and before cashout.

9. Compliance & audit

  • Every bet, win, rollback, and balance adjustment is logged immutably.
  • Logs include provider round ID, transaction ID, timestamp, and raw callback.
  • Reporting endpoints can produce daily GGR/NGR and settlement files.

10. Production sign-off

  • Run a 24-hour soak test with simulated players across slots, live casino, and crash games.
  • Test insufficient-balance, disconnection, and rollback edge cases explicitly.
  • Confirm finance reconciliation matches the provider's settlement report.
  • Soft-launch to 5% of traffic before full rollout.

Need a partner that passes every item on this list? Talk to GamingAPI or read the full API docs.