Skip to Content

get-jwt-token

GET /api/v1/auth/get-jwt-token

This endpoint must be used by the client’s FE for further iFrame initialization.

The client can implement this endpoint and use any URL for it.

The endpoint will not be in use of the Sportsbook iFrame solution.

Note

There is no need to receive and post jwt-token in a case when the end-user is not authorized on the client platform.

The path above is only an example — expose this endpoint at whatever URL suits your platform.

Response example (StatusCode: 200):
{ "token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHRlcm5hbFVzZXJJZCI6ImVlZGU5ODhmNTI3MzQzMTJhOTliNDJmNDExNGEyZWQzIiwiZGVmYXVsdEN1cnJlbmN5IjoiVVNEIiwiaWF0IjoxNzM4MTc5Nzc2fQ.oWvkghnn1VI4JPCd7xs0leXbr1_gg2aJR9E6Fkgb_MhK2QRI-hx0WFL-L4Wra0cRroOH85651WLxqdHTJAAmEAcC5ZnExEexIa-swJinaxjUyoq8kMZKmauUjJyHcFHLZlqtClaD-eb-bPC90M2f4Hi7ZguoVhATqX9x98RwI-G9CCrv21sF26FXRY97iZ3MZUU2OlDA63-6ESM4xayxAdLGKza5O8UrYqFyk4kV9osY7MmqzX2V3wJdwAuAtXKvEK4YJaUQ2w7jXRV0NEeShc6DB9batX712E6JmlM8XYzMycQMI0g0YWn-6XLoNvwRP6asl3aAorvCGakjfP7a8A" }

JWT-token is used for remote authentication on the Sportsbook iFrame. JWT-token should be sent to iFrame in the iFrame URL

Note

It is only a request implementation example and every operator can implement it on its own.

JWT structure

JWT.header
{ "alg": "RS256", "typ": "JWT" }
JWT.payload
{ "defaultCurrency": "<playerCurrency>", "externalUserId": "<playerId>", "iat": 1516239022, "exp": 1516539022, "operatorUserId": "<operatorUserId>", // Optional field "operatorUserName": "<operatorUserName>", // Optional field "country": "<registrationPlayerCountryIso3>" // Optional field }
Example of JWT payload
{ "externalUserId": "70bd9c7d-a138-4c0a-8d89-7982eb88ee77", "defaultCurrency": "USD", "iat": 1738179776, "exp": 1738266176, "operatorUserId": "userId-23", "operatorUserName": "customUserName", "country": "GBR" // ISO-3 format. Optional field }

JWT payload fields

FieldRequiredDescription
externalUserIdYesId of player account. This Id will be used for account creation and can’t be changed in the future. Max length: 36 symbols. In case you have a GR8Tech Casino aggregation, the max supported length of playerId is 20 symbols. Allowed characters: Latin letters (A-Z, a-z), numbers (0-9), and hyphen (-). Regex: ^([A-Za-z0-9-]{1,36})$
defaultCurrencyYesCurrency which player uses for betting. This currency will be used for account creation and can’t be changed in the future. The supported currencies list is on the Supported Currencies page.
iatYes(issued at) Timestamp that indicates the time at which the JWT was issued. The value of this claim is Epoch time in seconds. Must be a NumericDate value
expNo(expiration time) Time after which the JWT expires. The value of this claim is Epoch time in seconds. Default value: iat + 30 seconds. Must be a NumericDate value
countryNoPlayer’s registration country in ISO-3 format. Used for compliance and regional settings.
operatorUserIdNoReal user ID from the client’s platform. Used for search and display in the Players list in UBO.
operatorUserNameNoReal username from the client’s platform. Used for search and display in the Players list in UBO.
Warning

Important: Fields that can only be set during account creation

The following fields can only be set during the first player entrance to the iFrame (during account creation):

  • country
  • operatorUserId
  • operatorUserName

If these fields are not provided during the initial login, subsequent attempts to add or update them via JWT token will not change the player’s values. To update these fields later, you must use the S2S Player Profile API (requires sign-in).

JWT signature verification

JWT.verify-signature = RSASHA256(base64.Encode(JWT.header) + ”.” + base64.Encode(JWT.payload))

Note

The public key for RSASHA256 must be provided by a client. The client’s responsibility is to provide a private secure endpoint (IP whitelisting) that responds with the public key that GR8 Tech Platform will use for verifying the JWT signature. That endpoint is get-public-key.