API Reference
All game APIs are serverless functions under/api/* on the app origin. Auth for
money-touching calls is the stateless wallet signature described in
Crash Money Model. Responses are
JSON; game state endpoints send cache-control: no-store.
Crash — /api/crash
GET /api/crash?wallet=0x…&authSig=0x…
Full state snapshot. Sweeps round commits, settlements and vault deposits before
responding (self-healing — any instance can serve any state).
GET /api/crash?action=verify-seeds
Publishes (seed_hash, seed, pepper) for the last 12 settled bet-bearing rounds —
the raw fairness disclosure (see Provably Fair).
POST /api/crash actions
Entropy dice — /api/entropy
GET /api/entropy
Public config:
POST /api/entropy
seedHash, seed, meta
with mine positions / draws / bucket), plus the payout. action: "recent" returns
the recent-results feed for the in-app strip.
Games: mines (params: mines, pick), limbo (target), plinko (risk,
bucket derived server-side), keno (picks[]).
Lootbox — /api/lootbox
LootBox NFT — /api/lootbox-nft
Flow guarantee: three wallet prompts total, never more — buy (payable), open
(submits the signed commitment), claim (free DUST cash).
Wallet bridge — /api/wallet/* (vfair platform)
Implements the partner-wallet contract the vfair-games platform calls during
real-money play, backed by the same crash-chip ledger:
- Auth: partner JWT (HS256, ≤30s TTL) in the Authorization header, verified with node:crypto in constant time.
playerId= the player’s wallet address;currency= chip token (ETH/USDG); amounts in whole units (1.0 = 1 token).- Idempotency keys are persisted (
vfair_wallet_txs) so platform retries can never double-move funds.
RPC proxy — /api/rpc
Same-origin JSON-RPC proxy for the Robinhood chain RPCs. The public RPC sends a
malformed CORS header (Access-Control-Allow-Origin: *,*), which browsers hard-reject;
the proxy performs upstream calls server-side and answers from our own origin with a
single valid CORS header. Upstreams are allowlisted.
Rate limits & reliability notes
- Game state endpoints are read-heavy and cheap; they always self-sweep pending work before answering.
- Money endpoints verify auth signatures against the current and previous 24h window — a once-a-day signature is sufficient.
- All ledger mutations are idempotent per round/nonce; replays from clients or the platform are safe by construction.