Legend Fire

Account creation, deposits, and withdrawals for third-party platforms.

Base URL
Not specified in source (provided as the API Server Domain)
Authentication
appid + MD5 sign, IP whitelist
Sections
14

Overview#

FastAPI provides a simple and secure way to integrate with third-party platforms for account creation, deposits, and withdrawals.

Preparations

The integrator must obtain the following authorization details:

  • API Server Domain.
  • appid: API integration identification ID.
  • appsecret: API authentication private key.

The integrator must provide their server IP address to be added to the API access whitelist.

Endpoints

# Endpoint Path
1 Agent Login /fast/agent/login
2 Create Player /fast/user/create
3 Deposit /fast/user/deposit
4 Withdrawal /fast/user/withdrawal
5 Get Balance /fast/user/balance
6 Get Balance (With Password) /fast/user/balanceWithPasswd
7 Change Password /fast/user/updatePasswd
8 Get Trade List /fast/user/tradeList
9 Get Gamelog List /fast/user/gameLogList

Request format#

Unless specified otherwise, API requests should use HTTP POST with application/x-www-form-urlencoded format.

Parameter Description
appid API integration identification ID.
timestamp Request timestamp (milliseconds)
sign Signature generated by the signing algorithm

Example JSON Request:

{
  "appid": "h63inikngg2qyoii",
  "timestamp": 1701401242061,
  "sign": "c685901b15253d820dc1bc062d21d4f1"
}

Response format

All API responses follow this format:

{
  "msg": "message",
  "code": 0,
  "data": {object}
}

Request signature#

This signature is used when the client sends requests to the FastAPI server.

  1. Exclude the sign field from parameters.
  2. Sort the remaining fields in ascending order by parameter name.
  3. Format each parameter as key=value, then concatenate them using the & character to form the parameter string.
  4. Append the given appsecret to the end of the concatenated parameter string.
  5. Generate the signature by applying the MD5 hash algorithm to the resulting string.
  6. For POST requests (with JSON) and GET requests (with URL parameters), apply the same sorting and signing process.
  7. The server will only accept requests within 5 minutes of the provided timestamp.

Signature code example

function sign(array $data, string $appSecret)
{
    unset($data['sign']);
    $params = array_map(function ($value) {
        if (is_array($value)) {
            $value = json_encode($value);
        } elseif (is_bool($value)) {
            $value = var_export($value, true);
        }
        return $value;
    }, $data);
    ksort($params);
    $strArr = [];
    foreach ($params as $key => $value) {
        $strArr[] = $key . '=' . $value;
    }
    return md5(implode('&', $strArr) . $appSecret);
}

Response codes#

Description of the code field values in API responses:

Code Meaning
200 Success
1 New User Is Created
2 User Does Not Exist
3 Parameter Error
4 Invalid Signature
5 Agent Ban
6 Account length error
7 Account format error
8 Password length error
9 Password format error
10 Requestid Used
11 Unknown Database Error
12 User Already Exist
13 Top Up Fail
14 Insufficient Credit
15 Withdrawal Failed
16 Get Balance Failed
17 Operations are Not Allowed In The Game
18 System Is Under Maintenance
19 The Requested Address Does Not Exist
20 Password error
21 Agent Name Or Password error
22 Platform Not Configured

AES decryption of appsecret_encrypted#

  1. Perform base64_decode on the appsecret_encrypted string returned by the agent login API.
  2. Extract the first 16 characters as the initialization vector (IV), and use the remaining characters starting from the 17th as the data to be AES decrypted.
  3. Convert the agent password to lowercase, then apply MD5 hashing twice to generate the AES decryption key.
  4. Use the AES-256-CBC algorithm to decrypt the data using the key and IV to obtain the appsecret.

Sample AES decryption code

function aesDecrypt($data, $key) {
  $data = base64_decode($data);
  $iv = substr($data, 0, 16); // Extract the first 16 bytes as IV
  $encrypted = substr($data, 16); // The rest is the encrypted data
  return openssl_decrypt($encrypted, 'AES-256-CBC', $key, OPENSSL_RAW_DATA, $iv);
}

Agent Login#

POST/fast/agent/login

The appsecret_encrypted returned by the API has been encrypted using the AES algorithm. In order to use the actual appsecret, the client must perform AES decryption as described in AES decryption.

Headers

Parameter Name Parameter Value Required
Content-Type application/x-www-form-urlencoded Yes

Body

Parameter Name Type Required Remark
requestid text Yes Unique request ID (up to 64 alphanumeric characters)
timestamp text Yes Request timestamp (milliseconds)
account text Yes Agent account
passwd text Yes Agent password
sign text Yes sign

Response data

Parameter Name Type Required Remark
code integer Yes Status Code
message string Yes Description
data object Yes
data.balance number Yes Agent balance
data.appid string Yes appid
data.appsecret_encrypted string Yes The appsecret after AES encryption

Create Player#

POST/fast/user/create

Headers

Parameter Name Parameter Value Required
Content-Type application/x-www-form-urlencoded Yes

Body

Parameter Name Type Required Remark
requestid text Yes Unique request ID (up to 64 alphanumeric characters)
appid text Yes appid
timestamp text Yes Request timestamp (milliseconds)
sign text Yes sign
account text Yes Player account (not include prefix, 3-16 characters, only letters/numbers)
passwd text Yes Player password (6-16 characters, must include letters and numbers; allowed symbols: !@#$()%^/.,)

Response data

Parameter Name Type Required Remark
code integer Yes Status Code
message string Yes Description
data object Yes
data.full_account string Yes Full account name with prefix

Deposit#

POST/fast/user/deposit

Headers

Parameter Name Parameter Value Required
Content-Type application/x-www-form-urlencoded Yes

Body

Parameter Name Type Required Remark
requestid text Yes Unique request ID (up to 64 alphanumeric characters)
appid text Yes appid
timestamp text Yes Request timestamp (milliseconds)
sign text Yes sign
account text Yes Player account (not include prefix)
amount text Yes e.g., 100.55, up to 2 decimal places

Response data

Parameter Name Type Required Remark
code integer Yes Status Code
message string Yes Description
data object Yes
data.balance number Yes Updated balance
data.order_num string Yes Order number
data.requestid string Yes Unique request ID
data.time integer Yes Timestamp of the operation

Withdrawal#

POST/fast/user/withdrawal

Headers

Parameter Name Parameter Value Required
Content-Type application/x-www-form-urlencoded Yes

Body

Parameter Name Type Required Remark
requestid text Yes Unique request ID (up to 64 alphanumeric characters)
appid text Yes Appid
timestamp text Yes Request timestamp (milliseconds)
sign text Yes sign
account text Yes Player account (not include prefix)
amount text Yes e.g., 100.55, up to 2 decimal places

Response data

Parameter Name Type Required Remark
code integer Yes Status Code
message string Yes Description
data object Yes
data.balance number Yes Updated balance
data.order_num string Yes Order number

Get Balance#

POST/fast/user/balance

Headers

Parameter Name Parameter Value Required
Content-Type application/x-www-form-urlencoded Yes

Body

Parameter Name Type Required Remark
requestid text Yes Unique request ID (up to 64 alphanumeric characters)
appid text Yes appid
timestamp text Yes Request timestamp (milliseconds)
sign text Yes sign
account text Yes Player account (not include prefix)

Response data

Parameter Name Type Required Remark
code integer Yes Status Code
message string Yes Description
data object Yes
data.balance number Yes Player's updated balance

Get Balance (With Password)#

POST/fast/user/balanceWithPasswd

Headers

Parameter Name Parameter Value Required
Content-Type application/x-www-form-urlencoded Yes

Body

Parameter Name Type Required Remark
requestid text Yes Unique request ID (up to 64 alphanumeric characters)
appid text Yes appid
timestamp text Yes Request timestamp (milliseconds)
sign text Yes sign
account text Yes Player account (not include prefix)
passwd text Yes Player password

Response data

Parameter Name Type Required Remark
code integer Yes Status Code
message string Yes Description
data object Yes
data.balance number Yes Player's updated balance

Change Password#

POST/fast/user/updatePasswd

Headers

Parameter Name Parameter Value Required
Content-Type application/x-www-form-urlencoded Yes

Body

Parameter Name Type Required Remark
requestid text Yes Unique request ID (up to 64 alphanumeric characters)
appid text Yes appid
timestamp text Yes Request timestamp (milliseconds)
sign text Yes sign
account text Yes Player account (not include prefix, 3-16 characters, only letters/numbers)
passwd text Yes (6-16 characters, must include letters and numbers; allowed symbols: !@#$()%^/.,)
new_passwd text Yes New password

Response data

Parameter Name Type Required Remark
code integer Yes Status Code
message string Yes Description

Get Trade List#

POST/fast/user/tradeList

Headers

Parameter Name Parameter Value Required
Content-Type application/x-www-form-urlencoded Yes

Body

Parameter Name Type Required Remark
requestid text Yes Unique request ID (up to 64 alphanumeric characters)
appid text Yes appid
timestamp text Yes Request timestamp (milliseconds)
sign text Yes sign
account text Yes Player account (not include prefix)
start_date text Yes Start date (ex: 2025-06-01)
end_date text Yes End date (ex: 2025-06-11)
page text Yes Page number (pass 0 for first page)
page_num text Yes Number of records per page (ex: 20)

Response data

Parameter Name Type Required Remark
code integer Yes Status Code
message string Yes Description
data object Yes
data.total integer Yes Total record
data.pages boolean Yes Total page
data.list object [] Yes Data list
list[].order_num string Yes Order number
list[].start_score number Yes Score before operation
list[].score number Yes Operation score (+ deposit, - withdrawal)
list[].time integer Yes Times of the operation

Get Gamelog List#

POST/fast/user/gameLogList

Note: Retrieve up to the latest 1,000 game records.

Headers

Parameter Name Parameter Value Required
Content-Type application/x-www-form-urlencoded Yes

Body

Parameter Name Type Required Remark
requestid text Yes Unique request ID (up to 64 alphanumeric characters)
appid text Yes appid
timestamp text Yes Request timestamp (milliseconds)
sign text Yes sign
account text Yes Player account (not include prefix)

Response data

Parameter Name Type Required Remark
code integer Yes Status Code
message string Yes Description
data object Yes
data.list object [] Yes Data List
list[].game_id integer Yes Game ID
list[].game_name string Yes Game Name
list[].start_score string Yes Score before operation
list[].end_score string Yes Operation score (+ deposit, - withdrawal)
list[].pay string Yes Bet amount
list[].win string Yes Win amount
list[].time integer Yes Times of the operation
list[].uniqleid string Yes Unique ID