Integration Tester

The Operator Integration Tester is a self-service tool that validates your wallet callback implementation against the RGS specification. It simulates the RGS making real HTTP calls to your endpoints and reports pass/fail results in real time.

Open Integration Tester

What It Tests

The tester runs test cases across 7 categories against your wallet callback endpoints:

Happy Path

Normal bet → win/loss flows, balance checks, and complete round lifecycles.

Idempotency

Duplicate request handling — your server should return the same response for repeated transactionId values.

Error Handling

Insufficient funds, rollback of unknown transactions, and unknown players on authenticate.

HMAC Security

Signature validation, replay attack protection, and tampered body detection.

Attack Vectors

SQL injection, XSS, negative amounts, zero amounts, and concurrent duplicate requests.

Edge Cases

Very long strings, Unicode characters, decimal precision, and rapid sequential requests.

How to Use

Open the Tester

Navigate to the Integration Tester. You'll see a configuration panel on the left and test selection on the right.

Enter Your Credentials

Fill in three fields:

Field Description
Wallet Base URL Your wallet API base URL (e.g., https://your-api.com)
HMAC Secret The shared HMAC secret for signing requests
Player ID A test player ID that exists in your system
Operator ID Optional. Sent as the X-Operator-ID header, like the RGS does
Currency The test player's currency (default USD)

Callbacks use game code dice-alpha. The multi-debit round uses blackjack-leo and is skipped if your wallet refuses that game.

Select Tests

Choose which test categories to run. Start with Happy Path tests to validate basic functionality, then progressively enable more categories. You can select individual tests or entire categories.

Run & Review

Click Run Tests. Results stream in real time — each test shows pass/fail status, assertions, and the raw HTTP request/response logs. After completion, you can save the report as a PDF using the "Save as PDF" button on the report page.

Test Categories

Happy Path

Basic operations: authenticate on launch, debit on bet, credit on win, zero-amount loss credit, balance query, rollback, and complete round flows. These should all pass before moving to other categories.

Idempotency

Sends the same transactionId twice for debit, credit, and rollback. A replay must not move money again, and a replayed rollback must still answer HTTP 200 with OK or ERROR_TRANSACTION_DOES_NOT_EXIST. Reusing a transactionId with different parameters may be refused (we recommend ERROR_DUPLICATE_TRANSACTION) or answered with the original result, but must not move money again.

Error Handling

Tests your error responses: a debit of one unit more than the balance, rollback of an unknown transaction, and an unknown player on authenticate. Any refusal of the debit passes, but only HTTP 200 with ERROR_NOT_ENOUGH_MONEY avoids a warning, because it is the only answer that lets the RGS tell the player the balance is too low. The unknown rollback must answer HTTP 200 with OK or ERROR_TRANSACTION_DOES_NOT_EXIST.

HMAC Security

Sends requests with invalid HMAC signatures, expired timestamps, and tampered request bodies. Includes authenticate endpoint HMAC validation. Your server must refuse all of these, either with a non-200 HTTP status (we recommend 401) or with HTTP 200 and status: "ERROR_INVALID_SIGNATURE". Accepting a 60-second-old timestamp gives a warning, not a failure.

Attack Vectors

Attempts SQL injection in string fields, XSS payloads, negative and zero bet amounts, and concurrent duplicate requests. Your server should handle all of these safely.

Edge Cases

Tests with very long player IDs, Unicode characters, high-precision decimal amounts, and rapid sequential requests. Validates that your server handles boundary conditions gracefully.

Debit/Rollback Ordering

Tests rollback before debit, concurrent debit and rollback, and late debit after a confirmed rollback. Validates your server's state machine logic.

Callback Endpoints Tested

The tester calls the same five callback endpoints that the RGS uses. See Wallet Callbacks for the full request/response schemas.

Endpoint Tested For
POST /callback/authenticate Player verification, balance on launch, HMAC security, invalid player
POST /callback/debit Bet placement, insufficient funds, idempotency, attack resistance
POST /callback/credit Win crediting, zero-amount loss, idempotency
POST /callback/balance Balance queries
POST /callback/rollback Bet reversal, ordering constraints, non-existent transactions