HZURA APIs
Developer Documentation
HZURA provides a Sports API and a Casino API for customer integrations. Version 1 responses are JSON from https://api.hzura.com/api/v1. Customers authenticate public routes with an API key. Casino access also has to be enabled for that customer.
What the APIs provide
The public API host is https://api.hzura.com. Application routes live under /api/v1. This site is the documentation. It does not proxy API calls.
Sports responses are the catalog and odds currently cached at request time. Casino responses are the games this customer may see, a launch URL, or a wallet result. There is no request body on sports routes.
| Resource | URL |
|---|---|
| API | https://api.hzura.com |
| API base | https://api.hzura.com/api/v1 |
| Playground | https://www.hzura.com/api-playground |
| This documentation | https://www.hzura.com/developers |
Sports API
Read-only GET routes for the sports enabled for the caller, the current event catalog, and one event with its markets. Odds are the odds array on the single-event response. Result state, when the feed provides it, is market status. There is no separate settlement route.
GET /api/v1/health— liveness. No API key and no IP policy.GET /api/v1/sports— sport keys this client may use.GET /api/v1/{sport}/events— published events, without full odds.GET /api/v1/{sport}/events/{eventId}— one event and its current markets.
Casino API
Casino routes require a customer API key. An IP-only sports client has no customer and cannot call them. The customer id is taken from the key. Requests do not accept a customer id, a provider player id, provider credentials, or a return URL.
GET /api/v1/casino/games— one page of games visible to this customer.POST /api/v1/casino/games/{gameId}/launch— a launch URL for one visible game.POST /api/v1/casino/wallet—BALANCE,DEBIT,CREDIT, orROLLBACK.
Authentication
Admin-managed customers send an API key as Authorization: Bearer or X-Api-Key. The calling IP must also match that customer's CIDR allow-list. Legacy sports access can be an enabled public-IP policy with no key. Casino always needs the key, because that is how the customer is identified.
Errors
Failed JSON routes return { "error", "message" }. Codes are stable. Messages do not echo the request, keys, or upstream bodies. GET /api/v1/health is the exception: its body is { "status", "redis" }.
Getting started
- Ask HZURA for an API key and register the public egress IP of the servers that will call the API.
- Call
GET /api/v1/healthto confirm the host answers. This route is not authenticated. - For sports, call
GET /api/v1/sports, then the event list, then a single event. The playground can send those reads. - For casino, list games with the API key, launch a player once, then call the wallet with that same
player_id.
curl -sS "https://api.hzura.com/api/v1/health"
curl -sS "https://api.hzura.com/api/v1/sports" \
-H "Authorization: Bearer YOUR_API_KEY"