API B2B v1

Base: /api/public/v1/lottery. Formato POSNET normalizado; nunca se expone el formato de la fuente. Credenciales pk_test_ = sandbox.

Autenticación

Cada cliente recibe API_KEY y API_SECRET desde el backoffice. El secret se muestra una sola vez.

x-api-key: pk_test_xxxxxxxx
x-api-secret: sk_xxxxxxxxxxxxxxxx

Endpoints

GET/jurisdictionslottery:readJurisdicciones y turnos habilitados
GET/draws?date=YYYY-MM-DD&jurisdiction=ERlottery:readSorteos y horarios de cierre
GET/results/latestresults:readÚltimos resultados OFICIALES
GET/results/{draw_id}results:readResultado oficial de un sorteo
POST/betsbets:writeRegistrar apuesta (requiere Idempotency-Key)
GET/tickets/{ticket_id}tickets:readEstado de un ticket
POST/tickets/validatetickets:readValidar por qr_token o short_code
POST/tickets/{ticket_id}/paytickets:payPagar premio (una sola vez)

Ejemplo: apostar

curl -X POST $BASE/bets \
  -H "x-api-key: $KEY" -H "x-api-secret: $SECRET" \
  -H "Idempotency-Key: terminal-42-op-000981" \
  -H "content-type: application/json" \
  -d '{"draw_id":"<uuid>","number":"0047","position_range":1,"stake":500}'

Reintentar con la misma Idempotency-Key devuelve el ticket original (idempotent_replay: true) sin debitar dos veces.

Códigos de error

MISSING_CREDENTIALSINVALID_CREDENTIALSSCOPE_REQUIREDIDEMPOTENCY_KEY_REQUIREDDRAW_CLOSEDINSUFFICIENT_BALANCESTAKE_LIMIT_EXCEEDEDNO_PAYOUT_RULEALREADY_PAIDNOT_WINNERBETTING_DISABLED