Documentation

API Reference

Everything you need to integrate. Sign up for an account to get an API key — all endpoints below require it.

Base URL
Prefix every endpoint below with this URL when making requests.
https://starta.sbs/api
Endpoints
All endpoints require authentication via API key passed in the Authorization header.
GET
/v1/catalog/providers

List all available game providers for the authenticated account.

GET
/v1/catalog/games

List all available games, optionally filtered by provider or category.

POST
/v1/sessions/launch

Create a new game session and return the launch URL for the player. Body: user_id, game_id, currency required; mode ('real' or 'fun', default 'real') selects real-money vs. demo play — build a toggle for this on your own site if you want players to choose. A demo-only game opens in either mode; a real-only game rejects mode 'fun' with 403 FUN_MODE_NOT_AVAILABLE; a launch request for a mode an admin-restricted game doesn't allow is rejected with 403.

GET
/v1/campaigns

List all campaigns for the authenticated account.

POST
/v1/campaigns

Create a new free-spins campaign with specified parameters.

POST
/v1/campaigns/{id}/grant

Grant free spins from a campaign to a specific player.

POST
/v1/campaigns/{id}/revoke

Revoke previously granted free spins from a player.

POST
/v1/campaigns/{id}/cancel

Cancel an entire campaign, revoking all grants.

Guides

Getting started

Sign up, generate an API key from your dashboard, and make your first authenticated request.

Launching demo vs. real-money sessions

Pass mode: "real" or mode: "fun" on /v1/sessions/launch. Demo-only games open in either mode; real-only games reject "fun" with FUN_MODE_NOT_AVAILABLE. Build the toggle for this on your own site — the parameter is the whole integration.

Handling webhooks

Configure your webhookUrl in account settings to receive balance checks, bets, wins, and refunds in real time.

Embedding the game iframe

Load the game_url from /v1/sessions/launch in an iframe on your page — it is our own /play page, which frames the provider session one level further down. If that iframe carries a sandbox attribute, keep allow-scripts, allow-same-origin, allow-popups and allow-popups-to-escape-sandbox in it (or omit sandbox entirely): provider SDKs need storage access and popups to finish starting, and a stricter sandbox leaves the player on a frame that never loads. There are no controls of ours inside it — put your own back/exit UI around the iframe.

Sessions are single-use — relaunch to recover

A launch URL is single-use and expires 10 minutes after it is issued, so never cache, re-embed or reload one. If a player's session ends, or a game never finishes loading, call /v1/sessions/launch again and load the new game_url — /play deliberately offers no reload of its own, because reloading a spent session only reproduces the expired state.

More questions? See the help center or contact us.