Seamless login
Integration schema
A solid arrow is a call to the endpoint named in the label; a dashed arrow is the data returned in response.
User flow
User-flow description
-
login - when the operator’s user enters the operator’s platform, he enters the form and tries to log in to the platform.
1.1 login-request - the operator’s platform FE sends a login request to the operator’s platform BE for credentials validation when the operator’s user is trying to log in to the platform. Request returns platform auth token.
-
go-to-sportsbook-page - user goes to the operator’s platform page with integrated Sportsbook iFrame.
2.1 /get-jwt-token - operators platform FE requests operators platform BE for the jwt-token which will be used for iFrame initialization. Note that iFrame can work with jwt-token for unauthorized users.
2.2 {iframe-host}/{lang}/?jwt={jwt-token} - operators platform FE renders Sportsbook iFrame.
2.3 /auth-with-jwt - Sportsbook iFrame sends a request to the Sportsbook BE for jwt-token validation on its init.
2.4 /get-public-key - Sportsbook BE requests operators BE for the public key which will be used for jwt-token validation.
2.5 JWT token validation - after jwt-token validation Sportsbook BE will use encrypted information for the creation of a simplified user account in the Sportsbook BE system and will respond with the Sportsbook iFrame auth token, which will guarantee user authentification in Sportsbook iFrame.
Integration
The client must implement the next endpoints on the side of their platform to guarantee the correct work of a seamless login mechanism:
- get-jwt-token — called by your own frontend to issue the signed JWT used for iFrame initialization. The Sportsbook iFrame never calls it.
- get-public-key — called by the GR8 Tech back-end to fetch the public key it verifies the JWT signature with.
Player account and balance will be created in our system during the first authorized player entrance to the iFrame.
Player account and balance will be created using the currency that was provided in the JWT token the first time. Player account currency can’t be changed.
Sportsbook iFrame will show an error and will not authorize player in case when the currency in JWT token is not equal to the account currency.