Skip to Content

get-public-key

GET /api/v1/sportsbook-iframe/auth/keys/get-public-key

This endpoint must be used by the Sportsbook iFrame for further iFrame JWT signature verification. The token it verifies is described in get-jwt-token.

The client can implement this endpoint and use any URL for it.

Client needs to notify GR8 Tech about the URL of this endpoint for future configuration as it will be used by Sportsbook iFrame on the backend side.

This endpoint must be hidden with an IP-whitelisting mechanism. Ask the GR8 Tech team for their IP addresses to whitelist them.

This endpoint response will be cached on the Sportsbook iFrame side for 15 minutes. The sportsbook iframe will be unavailable for players for 15 minutes in case of public key rotation.

Note

The operator must provide different URLs per tenant for these endpoints if he has a few Sportsbook iFrame brands/tenants or build different logic depending on the X-Brand and X-Operator-Id headers.

Caution

After generated DO NOT MODIFY PUBLIC KEY. Just leave as it is

Response example:
-----BEGIN PUBLIC KEY----- MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAy2LAhwUOIss8UdNogG5g KY6ijQUtnrlTohaSvGKg9RkR0BmOQGZMbRlK093VWtW8DM3qALItEQK+FmFazXHY nvlnONikHaXf1o+7nDKJtAZRPvS5BXMvrjdf5HJL74XYo3Bt845HARHobnHK6q9F HeRXcGt6rcR9N3dl3o/r0uRxOmz5IF8q1Mt/LJyqCp0UmhRwRbtmjOGTE3wrMPkq TDflnhy3YyZf9wcllNsFYgIRXjLcoWnHQf4ydSsJwcma8mp2MCGY4c4DtzpuoDw2 JinDx8MM878q+qLdsAw3WUAX2ih5guFdoBx3kDYctfOuEzN4KbkzVO5Agl15GSed /QIDAQAB -----END PUBLIC KEY-----

Private and public keys can be generated using the bash command:

openssl genrsa > private.pem openssl rsa -in private.pem -pubout -out public.pem