Dragon Fury

Runs on the FastApi integration: player accounts, deposits, withdrawals, balances and records.

Base URL
Not specified in source (provided as the API Server Domain)
Authentication
appid + MD5 sign, IP whitelist
Sections
2

FastApi#

FastAPI provides a simple and secure way to integrate with third-party platforms for account creation, deposits, and withdrawals.

Preparations#

The integrator must obtain the following authorization details:

  • API Server Domain.
  • appid: API integration identification ID.
  • appsecret: API authentication private key.

The integrator must provide their server IP address to be added to the API access whitelist.

Request Format

Unless specified otherwise, API requests should use HTTP POST with application/x-www-form-urlencoded format.

  • appid: API integration identification ID.
  • timestamp: Request timestamp (milliseconds)
  • sign: Signature generated by the signing algorithm Example JSON Request:

Response Format

All API responses follow this format:

Request API Signature:

This signature is used when the client sends requests to the FastAPI server. Steps:

  1. Exclude the sign field from parameters.
  2. Sort the remaining fields in ascending order by parameter name.
  3. Format each parameter as key=value, then concatenate them using the & character to form the parameter string.
  4. Append the given appsecret to the end of the concatenated parameter string.
  5. Generate the signature by applying the MD5 hash algorithm to the resulting string.
  6. For POST requests (with JSON) and GET requests (with URL parameters), apply the same sorting and signing process.
  7. The server will only accept requests within 5 minutes of the provided timestamp.

Signature Code Example:

Response Code

Description of the Code field values in API responses:

CodeMeaning
200Success
1New User Is Created
2User Does Not Exist
3Parameter Error
4Invalid Signature
5Agent Ban
6Account length error
7Account format error
8Password length error
9Password format error
10Requestid Used
11Unknown Database Error
12User Already Exist
13Top Up Fail
14Insufficient Credit
15Withdrawal Failed
16Get Balance Failed
17Operations are Not Allowed In The Game
18System Is Under Maintenance
19The Requested Address Does Not Exist
20Password error
21Agent Name Or Password error
22Platform Not Configured

AES Decryption of appsecret_encrypted

  1. Perform base64_decode on the appsecret_encrypted string returned by the agent login API.
  2. Extract the first 16 characters as the initialization vector (IV), and use the remaining characters starting from the 17th as the data to be AES decrypted.
  3. Convert the agent password to lowercase, then apply MD5 hashing twice to generate the AES decryption key.
  4. Use the AES-256-CBC algorithm to decrypt the data using the key and IV to obtain the appsecret.

Sample AES Decryption Code:

Agent Login

Path: /fast/agent/login Method: POST

The appsecret_encrypted returned by the API that has been encrypted using the AES algorithm. In order to use the actual appsecret, the client must perform AES decryption on the specified decryption process.

Headers:

Parameter NameParameter ValueRequired
Content-Typeapplication/x-www-form-urlencodedYes

Body:

Parameter NameTypeRequiredRemark
requestidtextYesUnique request ID (up to 64 alphanumeric characters)
timestamptextYesRequest timestamp (milliseconds)
accounttextYesAgent account
passwdtextYesAgent password
signtextYessign

Response Data:

Parameter NameTypeRequiredRemark
codeintegerYesStatus Code
messagestringYesDescription
dataobjectYes
├─ balancenumberYesAgent balance
├─ appidstringYesappid
├─ appsecret_encryptedstringYesThe appsecret after AES encryption
  1. Create Player Path: /fast/user/create Method: POST

Headers:

Parameter NameParameter ValueRequired
Content-Typeapplication/x-www-form-urlencodedYes

Body:

Parameter NameTypeRequiredRemark
requestidtextYesUnique request ID (up to 64 alphanumeric characters)
appidtextYesappid
timestamptextYesRequest timestamp (milliseconds)
signtextYessign
accounttextYesPlayer account(not include prefix, 3–16 characters, only letters/numbers)
passwdtextYes

Player password (6–16 characters, must include letters and numbers; allowed

symbols: !@#$()%^/.,)

Response Data:

Parameter NameTypeRequiredRemark
codeintegerYesStatus Code
messagestringYesDescription
dataobjectYes
├─ full_accountstringYesFull account name with prefix

Deposit

Path: /fast/user/deposit Method: POST

Headers:

Parameter NameParameter ValueRequired
Content-Typeapplication/x-www-form-urlencodedYes

Body:

Parameter NameTypeRequiredRemark
requestidtextYesUnique request ID (up to 64 alphanumeric characters)
appidtextYesappid
timestamptextYesRequest timestamp (milliseconds)
signtextYessign
accounttextYesPlayer account (not include prefix)
amounttextYese.g., 100.55, up to 2 decimal places

Response Data:

Parameter NameTypeRequiredRemark
codeintegerYesStatus Code
messagestringYesDescription
dataobjectYes
├─ balancenumberYesUpdated balance
├─ order_numstringYesOrder number
├─ requestidstringYesUnique request ID
├─ timeintegerYesTimestamp of the operation

Withdrawal

Path: /fast/user/withdrawal Method: POST

Headers:

Parameter NameParameter ValueRequired
Content-Typeapplication/x-www-form-urlencodedYes

Body:

Parameter NameTypeRequiredRemark
requestidtextYesUnique request ID (up to 64 alphanumeric characters)
appidtextYesAppid
timestamptextYesRequest timestamp (milliseconds)
signtextYessign
accounttextYesPlayer account (not include prefix)
amounttextYese.g., 100.55, up to 2 decimal places

Response Data:

Parameter NameTypeRequiredRemark
codeintegerYesStatus Code
messagestringYesDescription
dataobjectYes
├─ balancenumberYesUpdated balance
├─ order_numstringYesOrder number

Get Balance

Path: /fast/user/balance Method: POST

Headers:

Parameter NameParameter ValueRequired
Content-Typeapplication/x-www-form-urlencodedYes

Body:

Parameter NameTypeRequiredRemark
requestidtextYesUnique request ID (up to 64 alphanumeric characters)
appidtextYesappid
timestamptextYesRequest timestamp (milliseconds)
signtextYessign
accounttextYesPlayer account (not include prefix)

Response Data

Parameter NameTypeRequiredRemark
codeintegerYesStatus Code
messagestringYesDescription
dataobjectYes
├─ balancenumberYesPlayer’s updated balance
  1. Get Balance (With Password) Path: /fast/user/balanceWithPasswd Method: POST

Headers:

Parameter NameParameter ValueRequired
Content-Typeapplication/x-www-form-urlencodedYes

Body:

Parameter NameTypeRequiredRemark
requestidtextYesUnique request ID (up to 64 alphanumeric characters)
appidtextYesappid
timestamptextYesRequest timestamp (milliseconds)
signtextYessign
accounttextYesPlayer account (not include prefix)
passwdtextYesPlayer password

Response Data

Parameter NameTypeRequiredRemark
codeintegerYesStatus Code
messagestringYesDescription
dataobjectYes
├─ balancenumberYesPlayer’s updated balance

Change Password

Path: /fast/user/updatePasswd Method: POST

Headers:

Parameter NameParameter ValueRequired
Content-Typeapplication/x-www-form-urlencodedYes

Body:

Parameter NameTypeRequiredRemark
requestidtextYesUnique request ID (up to 64 alphanumeric characters)
appidtextYesappid
timestamptextYesRequest timestamp (milliseconds)
signtextYessign
accounttextYesPlayer account (not include prefix, 3–16 characters, only letters/numbers)
passwdtextYes

(6–16 characters, must include letters and

numbers; allowed symbols: !@#$()%^/.,)

new_passwdtextYesNew password

Response Data

Parameter NameTypeRequiredRemark
codeintegerYesStatus Code
messagestringYesDescription

Get Trade List

Path: /fast/user/tradeList Method: POST

Headers:

Parameter NameParameter ValueRequired
Content-Typeapplication/x-www-form-urlencodedYes

Body:

Parameter NameTypeRequiredRemark
requestidtextYesUnique request ID (up to 64 alphanumeric characters)
appidtextYesappid
timestamptextYesRequest timestamp (milliseconds)
signtextYessign
accounttextYesPlayer account (not include prefix)
start_datetextYesStart date (ex: 2025-06-01)
end_datetextYesEnd date (ex: 2025-06-11)
pagetextYesPage number (pass 0 for first page)
page_numtextYesNumber of records per page (ex: 20)

Response Data

Parameter NameTypeRequiredRemark
codeintegerYesStatus Code
messagestringYesDescription
dataobjectYes
├─ totalintegerYesTotal record
├─ pagesbooleanYesTotal page
├─ listobject []YesData list
├─ order_numstringYesOrder number
├─ start_scorenumberYesScore before operation
├─ scorenumberYesOperation score (+ deposit, - withdrawal)
├─ timeintegerYesTimes of the operation

Get Gamelog List

Path: /fast/user/gameLogList Method: POST

Note: Retrieve up to the latest 1,000 game records

Headers:

Parameter NameParameter ValueRequired
Content-Typeapplication/x-www-form-urlencodedYes

Body:

Parameter NameTypeRequiredRemark
requestidtextYesUnique request ID (up to 64 alphanumeric characters)
appidtextYesappid
timestamptextYesRequest timestamp (milliseconds)
signtextYessign
accounttextYesPlayer account (not include prefix)

Response Data

Parameter NameTypeRequiredRemark
codeintegerYesStatus Code
messagestringYesDescription
dataobjectYes
├─ listobject []YesData List
├─ game_idintegerYesGame ID
├─ game_namestringYesGame Name
├─ start_scorestringYesScore before operation
├─ end_scorestringYesOperation score (+ deposit, - withdrawal)
├─ paystringYesBet amount
├─ winstringYesWin amount
├─ timeintegerYesTimes of the operation
├─ uniqleidstringYesUnique ID