Last reviewed: 2026-08-16
The public website and this repository may describe approved endpoint paths, the signing method, representative fields, and redacted examples. The exact paths for higher-risk fund-recovery and merchant-configuration operations remain controlled. These are integration references, not usable credentials or a complete production protocol. Publishing the HMAC algorithm does not expose the signing key.
The real Base URL, credentials, complete field constraints, final callback list, allowlists, and production configuration are supplied only through the controlled project process. Signing keys belong only in the designated server-side secret store.
Keep the following information in the designated private technical channel:
- API keys, secrets, merchant codes, signatures, or access tokens;
- private test or production Base URLs, callback hosts, and allowlists;
- player identifiers, personal data, wallet balances, or real transaction records;
- screenshots, logs, or example payloads containing private environment configuration.
Do not place signing keys or other secrets in browser code, client packages, source control, logs, tickets, chat, or public issues. Operational evidence should contain only the time, result code, trace identifier, and masked business identifiers required for investigation; remove full signatures, tokens, player details, and complete transaction payloads.
Before production, confirm and test timestamp freshness, nonce uniqueness, replay rejection, merchant-level authorization, rate and transaction limits, idempotency, reconciliation, rotation, revocation, and security monitoring in the final project protocol. This repository does not claim that a server has already enabled those controls.
If a credential or private value is exposed, stop using it and contact the AG technical representative through the existing private project channel.
For a public documentation error, prepare the affected file, the corrected statement, and a public source or reproducible explanation. Share private evidence through the designated technical channel.
Official website: https://aggameapi.com/