MaxBridge Service

A service dedicated to the integration of MaxBet payment retail into Singular platform
Appendix
Hash Calculation

Each request sent to the MaxBridge API includes hash parameter to make sure that request in valid and that requestor has right to request transaction validity check.

Hash is being calculated by combining several parameters of the request and applying SHA256 hash to it. More specifically, hash of the request is calculated in a following way:

SHA256(request body + nonce + provider secret key)

  • Nonce - Parameter sent in a header of the request used for security purposes.Random integer
  • Request Body - JSON that is sent in the body of the request
  • Provider Secret Key - Shared key needed to communicate with the MaxBridge

For example, lets look at following get-transaction-details request:

nonce: 1234

{“transaction_id”:“00000000-0000-0000-0000-000000000000”,“service_id”:1,“user_id”:1121}

String needed to calculate the hash will be:

{"transaction_id":"00000000-0000-0000-0000-000000000000","service_id":1,"user_id":1121}1234secret


SHA256 value of the string will be:

cc41fd49c92fced1a58a3df2557f61bb5c033768f2a415aa8b774c57767f0787

Status Codes
Code Name Description
10 STATUS_SUCCESS Operation was successful
99 WRONG_REQUEST Received request had invalid structure
100 FIELD_LIMIT_REACHED Value specified in the field has reached its limit
101 FIELD_MIN_MAX_NOT_MATCHED Value specified in the field does not meet Min / Max requirements
102 FIELD_FORMAT_NOT_MATCHED Value specified in the field does not meet its format requirements
103 FIELD_IS_EMPTY Field can`t be empty
104 PATTERN_IS_NOT_MATCHED Value specified in the field does not meet its pattern requirements
105 COUNTRY_NOT_SUPPORTED Specified country is not supported by the system
106 AGE_LIMIT_NOT_MATCHED Specified age of the user does not meet system defined requirements
107 ID_DOCUMENT_IS_MISSING ID Document of the user must be specified
108 MAX_POSSIBLE_REG_PER_IP_REACHED IP has reached its limit for number of registrations allowed
109 UNABLE_TO_SAVE_ID_DOC ID Document of the user could not be saved
110 UNABLE_TO_ASSIGN_ACCOUNT_TO_USER Can not assign the payment account to the user
111 GENERIC_FAILED_ERROR Generic error
112 MISSING_PARAMETERS The request is missing mandatory parameters
113 USER_WITH_GIVEN_AUTH_CREDENTIALS_NOT_FOUND Specified user identifier or password was incorrect
114 OTP_REQUEST_LIMIT_REACHED Reached maximum number of OTP send requests
115 UNABLE_TO_SEND_OTP_TEL_IS_MISSING The user has no phone number assigned to it
116 UNABLE_TO_SEND_SMS_CODE_OTP_IS_ENABLED Could not send high security enable OTP
117 FAILED_TO_SEND_OTP OTP code could not be sent
118 OTP_IS_SENT OTP code has been sent to the user
119 OTP_NOT_FOUND Specified otp code was incorrect
120 OTP_IS_NOT_ENABLED High security mode is not activated for the user
121 UNABLE_TO_GENERATE_OTP Unable to generate OTP
122 OTP_IS_REQUIRED User has high security enabled and no OTP was provided
123 LAST_ACCESS_FROM_DIFFERENT_IP The last requester IP for the session was different from the current one
124 IP_IS_BLOCKED IP has exceeded number of requests allowed and has been blocked
125 ACCOUNT_NOT_FOUND Specified user account can not be found
126 SESSION_NOT_FOUND Specified user has no active session
127 OLD_AND_NEW_VALUES_MATCH_ERROR The old and new values match, the value can not be updated
128 CONTACT_DETAILS_NOT_ASSIGNED The user has no contact details assigned
129 CONTACT_DETAIL_NOT_MATCHED Provided contact detail information is invalid
130 UNABLE_TO_ENABLE_OTP_TEL_IS_MISSING The user has no phone number assigned to it
131 ACCOUNT_IS_BLOCKED User account is blocked
132 OTP_IS_OFF High security mode is disabled for the user
133 USER_HAS_GIVEN_ID_DOC ID document already exists
134 OTP_IS_ENABLED High security mode is activated for the user
135 USERS_DOCUMENT_NOT_FOUND Document with the specified id can not be found
136 DOCUMENT_PHOTO_ALREADY_EXISTS ID document already has a photo
137 PROVIDER_NOT_FOUND Could not find the provider id
138 ACCESS_DENIED Access denied to the specified operation
139 WRONG_HASH The has of the request is invalid
140 ACCESS_GRANTED Access granted
141 USER_IS_SELF_EXCLUDED The user has self-exclusion limit
142 WRONG_DATES Dates are invalid
143 CAN_NOT_BE_NEGATIVE The amount can not be negative
144 MUST_BE_MORE_THAN_ZERO The amount can not be negative
145 CURRENCY_NOT_FOUND Specified currency could not be found
146 USERS_ACCOUNTS_NOT_FOUND User has no account in the specified currency
147 TOKEN_NOT_FOUND Specified token could not be found
148 TOKEN_IS_EXPIRED Specified token is expired
149 INCORRECT_USER_STATUSID Specified user status id is invalid
150 ACCESS_DENIED_FOR_GIVEN_PROVIDER Provider doesn’t have the access to perform the operation
151 DUPLICATED_PROVIDERS_TRANSACTIONID Specified provider transaction id already exists
152 PRIMARY_CURRENCY_NOT_FOUND No preferred currency is specified
153 TRANSACTION_AMOUNT_AND_LIMIT_DONT_MATCH Transaction amount breaches the limit rules
154 INSUFFICIENT_FUNDS Insufficient funds on the account
155 INCORRECT_TRANSACTION_ID_FORMAT Transaction id format is invalid
156 TRANSACTION_NOT_FOUND Couldn’t find transaction with the given id
157 TRANSACTION_STATUS_SUCCESS Transaction status is - SUCCESS
158 TRANSACTION_STATUS_ROLLBACK Transaction status is - ROLLBACK
159 ACCOUNT_IS_SUSPENDED User account is suspended
170 UNABLE_TO_GET_BALANCE Unable to get user balance
171 UNABLE_TO_EXCHANGE Unable to exchange between currencies
172 TRANSACTION_ROLLBACK_TIME_EXPIRED Rollback time limit expired
173 UNABLE_TO_ROLLBACK_TRANSACTION Unable to rollback transaction
174 PAYMENT_ACCOUNT_NOT_FOUND Payment account with the specified id not found
175 PAYMENT_ACCOUNT_IS_NOT_VERIFIED Specified payment account is not verified
176 EXCHANGE_RATE_NOT_FOUND Exchange rate between currencies is not specified
177 CARD_VERIFICATION_TRANSACTION_DOES_NOT_REQUIRE_APPROVAL Approval is not required for card verification transaction
178 UNIDENTIFIED_TRANSACTION_STATUS Couldn’t identify transaction status
179 UNABLE_TO_CHANGE_TRANSACTION_STATUS_FROM_CURRENT_STATUS Transaction can not be updated from the current status to the specified one
180 UNABLE_TO_CHANGE_TRANSACTION_STATUS Unable to change transaction status
181 TRANSACTION_STATUS_APPROVED Transaction status is - APPROVED
182 TRANSACTION_STATUS_PENDING Transaction status is - PENDING
183 TRANSACTION_STATUS_REJECTED Transaction status is - REJECTED
184 TRANSACTION_STATUS_FROZEN Transaction status is - FROZEN
185 TRANSACTION_STATUS_CANCELED Transaction status is - CANCELED
186 PROVIDER_IS_DISABLED Specified provider is disabled
187 FAILED_TO_VERIFY_PARAMETERS Couldn’t verify provided parameters
188 REGISTRATION_PROFILE_NOT_FOUND Specified registration profile doesn’t exist
189 ORIGIN_DOMAIN_NOT_ALLOWED Origin domain is not allowed
190 UNABLE_TO_SEND_EMAIL_VERIFICATION_EMAIL_IS_MISSING Email couldn’t be sent because user has no email specified
191 FIELD_NEW_VALUE_CAN_NOT_BE_LESS_THAN_CURRENT_VALUE The specified value can not be less than the old one
192 TERMS_AND_CONDITION_NOT_FOUND Specified T&C could not be found
193 USER_IS_MISSING_REGISTRATION_DOMAIN User has no registration domain specified
194 UNABLE_TO_ACCEPT_PROVIDED_TERMS Specified T&C could not be accepted
195 USER_HAS_TO_ACCEPT_REQUIRED_TERMS User is required to accept specific T&C for the operation
196 TRANSACTION_STATUS_RETURN Transaction status is - RETURN
197 CONTACT_CHANNEL_NOT_VERIFIED Specified contact channel is not verified
198 USER_IS_MISSING_DATE_OF_BIRTH Date of birth is not specified for the user
199 CARD_VERIFICATION_TRANSACTION_CANNOT_PARTICIPATE_IN_BONUS Card verification transaction can not be a bonus transaction
200 STATUS_ITEM_EXISTS The requested resource is available
201 CASH_TRANSACTION_CANNOT_PARTICIPATE_IN_BONUS Cash transaction can not be a bonus transaction
202 BONUS_WITH_SPECIFIED_PARAMETERS_NOT_FOUND Bonus with specified parameters doesn’t exist
203 BONUS_IS_MISSING_ALLOWED_GAMES_LIST Bonus is missing allowed games list
204 PROVIDER_SERVICE_IS_NOT_ALLOWED_TO_USE_BONUS Specified provider is not allowed for the bonus
205 BONUS_IS_EXPIRED Bonus is expired
206 UNABLE_TO_MODIFY_CORRUPTED_TRANSACTION Unable to modify corrupted transaction
207 INVALID_IMAGE_FILE_NAME Image file name is invalid
208 STATUS_CANNOT_BE_CHANGE_TO_GIVEN_NEW_STATUS Old and new statuses are the same
209 THIRD_PARTY_AUTH_SYSTEM_DISABLED External authentication system is disabled
210 THIRD_PARTY_AUTH_SYSTEM_NOT_ALLOWED External authentication system is not allowed
211 PAYMENT_ACCOUNT_ALREADY_EXISTS Specified payment account already exists
212 SESSION_CHECK_WITH_EXPOSED_SESSION_ID_NOT_ALLOWED Can not check the session with exposed session id
213 USER_DOES_NOT_BELONG_TO_ORIGIN_DOMAIN User registration and origin domains don’t match
214 TX_FEE_MUST_BE_NULL_OR_MORE_THAN_ZERO Transaction fee can not be 0, it should be “null” or more than 0
215 PROVIDED_TX_FEE_CAN_NOT_OVERRIDE_PROVIDERS_TX_FEES Provider’s transaction fees can not be overriden
216 PROVIDER_TX_REFERENCE_ID_IS_ALREADY_SET Specified transaction reference id already exists
217 PROVIDER_MIN_AMOUNT_IS_GREATER_THAN_AMOUNT Amount is less than minimum allowed amount
218 DEPOSIT_LIMIT_REACHED Maximum deposit amount reached
219 WAGER_LIMIT_REACHED Maximum wager amount reached
220 LOSS_LIMIT_REACHED Maximum loss amount reached
221 TRANSACTION_TYPE_NOT_ALLOWED Transaction type not allowed
222 USER_HAS_ACTIVE_LIMIT_IN_DIFFERENT_CURRECNY User has active limit in different currency
223 VALUE_IS_ALREADY_SET Specified value is already set
224 CURRENCY_NOT_FOUND_OR_IS_VIRTUAL Currency doesn’t exist or is virtual
225 FINANCIAL_LIMIT_REACHED Maximum financial limit reached
226 REALITY_CHECK_IS_DUE Reality check time limit reached
227 REALITY_CHECK_IS_NOT_DUE_YET Reality check time limit is not yet reached
228 ID_DOCUMENT_WITH_CURRENT_STATUS_CAN_NOT_BE_ALTERED ID document with current status can not be changed
229 ID_DOCUMENT_IS_EXPIRED ID document is expired
230 ID_DOCUMENT_IS_MISSING_SCANNED_IMAGES ID document has no scanned images
231 INVALID_PROVIDER_TRANSACTION_SESSION_STATUS Provider transaction session status is invalid
232 NOT_ALLOWED_TO_OPEN_TRANSACTION_SESSION Denied to open transaction session
233 CARD_VERIFICATION_CANNOT_BE_PART_OF_TRANSACTION_SESSION Card verification can not be part of transaction session
234 CARD_VERIFICATION_AMOUNT_MUST_BE_MORE_THAN_ZERO Card verification amount must be more than 0
235 BONUS_AMOUNT_CAN_NOT_BE_NEGATIVE Bonus amount can not be negative
236 ZERO_AMOUNT_TRANSACTION_MUST_CLOSE_SESSION Session must be closed on 0 amount transaction
237 ZERO_AMOUNT_SESSION_CLOSE_TX_CAN_NOT_REQUIRE_APPROVAL 0 amount session close transaction can not require approval
238 PROVIDER_TX_REFERENCE_ID_IS_REQUIRED Provider transaction reference id is required
239 TRANSACTION_SESSION_IS_CLOSED Transaction session is closed
240 CASH_TRANSACTION_CANNOT_BE_PART_OF_TRANSACTION_SESSION Cash transaction can not be part of transaction session
241 ZERO_AMOUNT_SESSION_OPEN_TX_CAN_NOT_REQUIRE_APPROVAL 0 amount session open transaction can not require approval
242 BONUS_AWARD_ID_MUST_BE_NULL_FOR_ZERO_AMOUNT_TX 0 amount transaction can not have a bonus amount
243 ------
244 TRANSACTION_IN_PROVIDER_TRANSACTION_SESSION_IS_WAITING_FOR_APPROVAL Transaction in provider transaction session is waiting for approval
245 PAYMENT_PROVIDER_IS_NOT_ALLOWED_TO_PERFORM_ROLLBACK_WITH_TX_REFERENCE_ID Payment provider is not allowed to perform rollback with tx reference id
246 SUBSEQUENT_TX_IN_PROVIDER_TRANSACTION_SESSION_IS_PENDING_TRANSACTION Subsequent tx in provider transaction session is pending transaction
247 TRANSACTION_IS_NOT_LAST_IN_PROVIDER_TRANSACTION_SESSION Transaction is not last in provider transaction session
248 FAILED_TO_VERIFY_PROVIDER_TRANSACTION_SESSION Failed to verify provider transaction session
249 TRANSACTION_FEE_CANNOT_BE_APPLIED_TO_CARD_VERIFICATION_TRANSACTION Transaction fee cannot be applied to card verification transaction
250 TRANSACTION_AMOUNT_CHECKSUM_ERROR Transaction amount checksum error
251 FEE_EXCEEDS_TRANSACTION_AMOUNT Fee can not be more than transaction amount
252 NOT_ALLOWED_TO_SET_PROVIDER_TX_REFERENCE_ID_TO_EXISTING_GAME_TX Not allowed to set provider tx reference id to existing game tx
253 VALID_TRANSACTION_SESSION_NOT_FOUND Valid transaction session not found
254 FAILED_TO_RETRIEVE_ACTIVE_BONUS_BALANCE Failed to retrieve active bonus balance
255 USER_VALIDATION_WITH_REGULATOR_SERVICE_HAS_FAILED_WITH_SYSTEM_ERROR User validation with regulator service has failed with system error
256 USER_IS_BLACKLISTED_BY_REGULATOR_SERVICE User is blacklisted by regulator service
257 QUERY_NOT_ALLOWED Query not allowed
258 AUTH_CREDENTIALS_DOES_NOT_MATCH Auth credentials do not match
259 USER_IS_BLOCKED_FOR_MALICIOUS_ACTIVITY User is blocked for malicious activity
260 ALTERATION_NOT_ALLOWD Alteration is not allowed for the field
261 VALUE_NOT_ALLOWED_TO_BE_SET Value not allowed to be changed
262 FAILED_TO_SET_MANDATORY_SESSION_LIMIT Failed to set mandatory session limit
265 USER_IS_REGULATORY_EXCLUDED User is excluded by regulatory limitations
266 OTP_DELIVERY_CHANNEL_IS_NOT_AVAILABLE Requested contact channel(email/phone) is not configured for delivering OTP
267 PARAMETER_VALIDATION_FAILED Some of the request parameters are invalid
268 SERVER_ERROR General server error
277 FORGET_USER_IDS_LIMIT_EXCEEDED Array of user IDs exceeds the maximum allowed limit
278 FORGET_USER_BALANCE_LIMIT_EXCEEDED User’s balance exceeds maximum allowed limit to be forgotten
279 FORGET_USER_HAS_PENDING_TRANSACTIONS User has pending transactions and can not be forgotten
280 FORGET_USER_HAS_OPEN_BETS User has open bets/rounds and can not be forgotten
281 USER_IS_FORGOTTEN The user is already forgotten
282 ACCOUNT_IS_LIMITED The user account has specific status/limit and can not be forgotten
283 FORGET_USERS_ERROR Forget user request failed
284 USER_IS_OBFUSCATED The user is obfuscated
285 USER_IS_NOT_FORGOTTEN The user is not forgotten/obfuscated
361 WITHDRAW_LIMIT_REACHED Users withdraw limit is reached
400 STATUS_ITEM_DOES_NOT_EXISTS The requested resource is not available
500 STATUS_UNABLE_TO_CHECK_ITEM Status unable to check item
Document Statuses

Documents can have one of the following statuses:

ID Status
0 Unverified
1 Verified
2 Under Review
3 Rejected
User Statuses

User statuses are dynamic and can be configured at any time to enhance user management capabilities.

Each status can enforce following on the users:

  • Different Block Type
  • Different Cash Out Limit

System supports functionality enabling clients to add new statuses at any point of time.

By default, following statuses are supported by the system:

ID Name Block Type
1 Registered None
2 Verified None
3 Full Block Fully Blocked
4 Game Block Blocked from placing bets
5 Withdraw Blocked Blocked from withdrawing amount from account balance
6 VIP None

The block types in the system are the following

ID Block Type Description
null No Block Not blocked on any action
0 Full Block Restricts almost every action
1 Game Block Restricts placing bets
2 Transaction Block Restricts any transaction, other than game wins

Full description https://singular.atlassian.net/wiki/spaces/GPA/pages/473270485002/Core+System+-+Player+Statuses

Document Statuses
ID Name
1 IDCard
2 Passport
3 HomeRegistry
4 DriverLicense
5 Warrant
6 FaceID
7 OtherID
8 ProofofAddress
9 BankStatement
10 ScanofCard
11 ScreenshotofeWallet
12 SourceofFunds
14 BankAccountID
15 RefugeeIDCertificate
16 ElectronicRegistry
17 Ekeng
100 OtherDocuments
101 OtherDocuments
Maxbet Retail Error Codes
Error Code Error Description
1000 RequestValidationFailed
1001 RouteParameterInvalid
1002 QueryParameterInvalid
1003 BodyMissing
1004 InvalidJsonBody
1005 UnsupportedMediaType
1100 DomainInvariantViolation
1101 DuplicateEntity
1102 InvalidStateTransition
1103 OperationNotAllowed
1104 ResourceNotFound
2000 AuthMissingApiKey
2001 AuthInvalidApiKey
2002 AuthForbidden
2003 AuthTokenExpired
3000 DownstreamTimeout
3001 DownstreamUnavailable
3002 DownstreamHttpFailure
3003 DownstreamDeserializationFailed
3100 RmsTimeout
3101 RmsUnavailable
3102 RmsHttpFailure
3103 RmsDeserializationFailed
3110 RmsLocationNotFound
3200 SingularTimeout
3201 SingularUnavailable
3202 SingularHttpFailure
3203 SingularDeserializationFailed
3210 SingularUserNotFound
4000 LocklessUserHasUnpaidReservation
4001 LocklessAmountExceedsBalance
4002 LocklessInvalidCurrency
4003 LocklessReservationNotFound
4004 LocklessReservationExpired
4005 LocklessReservationAlreadyPaid
4006 LocklessStatusInvalidForOp
4007 LocklessPreferredBranchMissing
4008 LocklessInvalidLocation
4009 LocklessValidAfterEarlierThanCreated
4010 LocklessValidAfterLaterThanNow
4011 LocklessValidAfterLaterThanCurrent
4012 LocklessReservedAmountBelowPaidOut
4013 LocklessReservedAmountIncreaseNotAllowed
4014 LocklessExpirationDateInPast
4015 LocklessExpirationEarlierThanValidAfter
4016 LocklessReservationOwnershipMismatch
4017 LocklessAmountExceedsReserved
4018 LocklessPreferredBranchCreateFailed
4019 LocklessPreferredBranchUpdateFailed
5000 SsbtReservationCodeInvalid
5001 SsbtPayoutNotAvailable
5002 SsbtNotEnoughFundsForPayout
5003 SsbtDepositTimeExpired
5004 SsbtAdditionalDataMissing
5005 SsbtShopIdMissing
5006 SsbtDeviceIdInvalid
5007 SsbtDepositCreateFailed
5008 SsbtDepositNotFound
5009 SsbtStatusInvalidForOp
5010 SsbtReservationReferenceInvalid
6000 WalletInsufficientFunds
6001 WalletTransactionNotFound
6002 ProviderRejectedTransaction
6003 WalletCancelFailed
7000 CashDeskOperationNotFound
7001 CashDeskRollbackInvalidOperationType
7002 CashDeskRollbackWindowExpired
7003 CashDeskRollbackDuplicate
API
Operations
Incoming / Cash-Desk Withdrawals
POST /maxbridge/api/v1/cashdesks/get-locations
GET /maxbridge/api/v1/cashdesks/get-users-default-location
GET /maxbridge/api/v1/cashdesks/get-reservation
POST /maxbridge/api/v1/cashdesks/create-withdraw-reservation
GET /maxbridge/api/v1/cashdesks/get-regulatory-payout-limit
POST /maxbridge/api/v1/cashdesks/cancel-reservation
Get Locations
POST /maxbridge/api/v1/cashdesks/get-locations

Returns the cash-desk locations the player can choose for a withdrawal. An empty body returns every location, served from a 10-minute cache.

Request headers

X-Requested-With
string required

Always true. Required by the Auth Proxy.

Referer
string required

Auth Proxy origin.

Cookie
string required

Session cookie issued by CORE during authentication and forwarded by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

Request body

Optional filters.

Object

All filters are optional. An empty body returns every location (cached for 10 minutes).

id
string uuid

Optional exact location id filter.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
address
string

Optional address filter. At least 3 characters when provided.

Example:
Knez Mihailova
name
string

Optional name filter. At least 3 characters when provided.

Example:
Centar

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope carrying a list of locations.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Array
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/get-locations HTTP/1.1 

Content-Type: application/json

{
    "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "address": "Knez Mihailova",
    "name": "Centar"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": [
        {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        }
    ],
    "httpStatusCode": 1
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/get-locations HTTP/1.1 

Content-Type: application/json

{
    "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "address": "Knez Mihailova",
    "name": "Cr"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 99,
  "message" : "'Name' must be at least 3 characters."
}
Get Users Default Location
GET /maxbridge/api/v1/cashdesks/get-users-default-location

Returns the player’s preferred cash-desk branch, chosen during their first withdrawal. Only an administrator can change it.

Request headers

X-Requested-With
string required

Always true. Required by the Auth Proxy.

Referer
string required

Auth Proxy origin.

Cookie
string required

Session cookie issued by CORE during authentication and forwarded by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope carrying a list of locations.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Array
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
GET https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/get-users-default-location HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": [
        {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        }
    ],
    "httpStatusCode": 1
}
GET https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/get-users-default-location HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 404,
  "message" : "The user has not selected a preferred branch."
}
Get Reservation
GET /maxbridge/api/v1/cashdesks/get-reservation

Returns the player’s current cash-desk withdrawal reservation, including the confirmationPin shown at the desk.

Request headers

X-Requested-With
string required

Always true. Required by the Auth Proxy.

Referer
string required

Auth Proxy origin.

Cookie
string required

Session cookie issued by CORE during authentication and forwarded by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope for Get Reservation.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Object

Cash-desk withdrawal reservation. error is only populated when the outcome code is 362.

id
string uuid

Reservation id.

Example:
9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31
amount
number double

Reserved amount (provider field reservedAmount).

Example:
15000
confirmationPin
string

PIN the player shows at the cash desk.

Example:
482913
fee
number double

Reservation fee.

Example:
0
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
createDate
string date-time

Creation timestamp.

Example:
2026-09-24T11:42:05Z
expirationDate
string date-time

Expiration timestamp.

Example:
2026-09-26T11:42:05Z
validAfterDate
string date-time

Payout becomes possible after this timestamp.

Example:
2026-09-24T12:42:05Z
status
string

Reservation status.

Enumeration:
Active
PaidOut
Expired
Cancelled
Example:
Active
description
string

Provider description.

Example:
Lockless reservation created from web
userId
integer int32

User id.

Example:
1234
error
Object

Structured error returned inside data.error for whitelisted provider errors. Shared by the SSBT deposit and lockless reservation flows.

errorCode
integer int32

Provider raw error code (5011 or 4022). For traceability, not for branching.

Example:
5011
reason
string

Machine-friendly reason, safe to branch on.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
message
string

Human readable summary, safe to show to the user.

Example:
SSBT deposit regulatory rolling limit exceeded.
traceId
string

Provider trace id for correlation.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
details
Object

Provider-supplied numbers for a whitelisted error. Superset of the SSBT (5011) and lockless reservation (4022) shapes; irrelevant fields are null.

domain
string

Provider domain the limit belongs to: SsbtDeposit or LocklessReservation.

Example:
SsbtDeposit
userId
integer int64

User id reported by the provider.

Example:
1234
requestedAmount
number double

Amount that was requested.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits inside the rolling window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits inside the rolling window.

Example:
80000
depositedInWindow
number double

Total deposits inside the rolling window.

Example:
200000
paidOutInWindow
number double

Total payouts inside the rolling window (withdrawal flow).

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
Example 3
GET https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/get-reservation HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": {
        "id": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
        "amount": 15000,
        "confirmationPin": "482913",
        "fee": 1,
        "location": {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        },
        "createDate": "2026-09-24T11:42:05Z",
        "expirationDate": "2026-09-26T11:42:05Z",
        "validAfterDate": "2026-09-24T12:42:05Z",
        "status": "Active",
        "description": "Lockless reservation created from web",
        "userId": 1234,
        "error": {
            "errorCode": 5011,
            "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
            "message": "SSBT deposit regulatory rolling limit exceeded.",
            "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
            "details": {
                "domain": "SsbtDeposit",
                "userId": 1234,
                "requestedAmount": 5000,
                "cashDeskDepositedInWindow": 120000,
                "ssbtDepositedInWindow": 80000,
                "depositedInWindow": 200000,
                "paidOutInWindow": 200000,
                "limit": 200000,
                "remaining": 1,
                "windowDays": 30,
                "windowStart": "2026-08-25T00:00:00Z"
            }
        }
    },
    "httpStatusCode": 1
}
GET https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/get-reservation HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 362,
  "message" : "Regulatory rolling limit exceeded.",
  "data" : {
    "id" : "00000000-0000-0000-0000-000000000000",
    "amount" : 0,
    "fee" : 0,
    "createDate" : "0001-01-01T00:00:00Z",
    "expirationDate" : "0001-01-01T00:00:00Z",
    "validAfterDate" : "0001-01-01T00:00:00Z",
    "status" : "Active",
    "userId" : 0,
    "error" : {
      "errorCode" : 4022,
      "reason" : "REGULATORY_ROLLING_LIMIT_EXCEEDED",
      "message" : "Regulatory rolling limit exceeded.",
      "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
      "details" : {
        "domain" : "LocklessReservation",
        "userId" : 1234,
        "requestedAmount" : 15000,
        "paidOutInWindow" : 200000,
        "limit" : 200000,
        "remaining" : 0,
        "windowDays" : 30,
        "windowStart" : "2026-08-25T00:00:00Z"
      }
    }
  }
}
GET https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/get-reservation HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 404,
  "message" : "Lockless reservation not found"
}
Create Withdrawal Reservation
POST /maxbridge/api/v1/cashdesks/create-withdraw-reservation

Reserves a cash-desk withdrawal at the selected branch. No money moves here - the amount is paid out at the desk later. The Rule Engine and the CORE withdraw limit are checked first.

Request headers

X-Requested-With
string required

Always true. Required by the Auth Proxy.

Referer
string required

Auth Proxy origin.

Cookie
string required

Session cookie issued by CORE during authentication and forwarded by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

Request body

Amount, currency and branch.

Object
amount
number double required

Amount to reserve. Must be a valid positive amount.

Example:
15000
currency
string required

ISO-4217 alphabetic currency code; must be supported by the integration.

Example:
BAM
locationId
string uuid required

Branch chosen by the user. Required.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope for Create Withdrawal Reservation.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Object

GetReservationResponse plus the provider-reported balance and currency.

id
string uuid

Reservation id.

Example:
9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31
amount
number double

Reserved amount.

Example:
15000
confirmationPin
string

PIN the player shows at the cash desk.

Example:
482913
fee
number double

Reservation fee.

Example:
0
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
createDate
string date-time

Creation timestamp.

Example:
2026-09-24T11:42:05Z
expirationDate
string date-time

Expiration timestamp.

Example:
2026-09-26T11:42:05Z
validAfterDate
string date-time

Payout becomes possible after this timestamp.

Example:
2026-09-24T12:42:05Z
status
string

Reservation status.

Enumeration:
Active
PaidOut
Expired
Cancelled
Example:
Active
description
string

Provider description.

Example:
Lockless reservation created from web
userId
integer int32

User id.

Example:
1234
error
Object

Structured error returned inside data.error for whitelisted provider errors. Shared by the SSBT deposit and lockless reservation flows.

errorCode
integer int32

Provider raw error code (5011 or 4022). For traceability, not for branching.

Example:
5011
reason
string

Machine-friendly reason, safe to branch on.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
message
string

Human readable summary, safe to show to the user.

Example:
SSBT deposit regulatory rolling limit exceeded.
traceId
string

Provider trace id for correlation.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
details
Object

Provider-supplied numbers for a whitelisted error. Superset of the SSBT (5011) and lockless reservation (4022) shapes; irrelevant fields are null.

domain
string

Provider domain the limit belongs to: SsbtDeposit or LocklessReservation.

Example:
SsbtDeposit
userId
integer int64

User id reported by the provider.

Example:
1234
requestedAmount
number double

Amount that was requested.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits inside the rolling window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits inside the rolling window.

Example:
80000
depositedInWindow
number double

Total deposits inside the rolling window.

Example:
200000
paidOutInWindow
number double

Total payouts inside the rolling window (withdrawal flow).

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
balance
number double

Wallet balance reported back by the provider after the reservation.

Example:
137300
currency
string

Currency of the reservation.

Example:
BAM
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
Example 3
Example 4
Example 5
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/create-withdraw-reservation HTTP/1.1 

Content-Type: application/json

{
    "amount": 15000,
    "currency": "BAM",
    "locationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": {
        "id": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
        "amount": 15000,
        "confirmationPin": "482913",
        "fee": 1,
        "location": {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        },
        "createDate": "2026-09-24T11:42:05Z",
        "expirationDate": "2026-09-26T11:42:05Z",
        "validAfterDate": "2026-09-24T12:42:05Z",
        "status": "Active",
        "description": "Lockless reservation created from web",
        "userId": 1234,
        "error": {
            "errorCode": 5011,
            "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
            "message": "SSBT deposit regulatory rolling limit exceeded.",
            "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
            "details": {
                "domain": "SsbtDeposit",
                "userId": 1234,
                "requestedAmount": 5000,
                "cashDeskDepositedInWindow": 120000,
                "ssbtDepositedInWindow": 80000,
                "depositedInWindow": 200000,
                "paidOutInWindow": 200000,
                "limit": 200000,
                "remaining": 1,
                "windowDays": 30,
                "windowStart": "2026-08-25T00:00:00Z"
            }
        },
        "balance": 137300,
        "currency": "BAM"
    },
    "httpStatusCode": 1
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/create-withdraw-reservation HTTP/1.1 

Content-Type: application/json

{
    "amount": 15000,
    "currency": "BAM",
    "locationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 183,
  "message" : "Transaction rejected by RuleEngine"
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/create-withdraw-reservation HTTP/1.1 

Content-Type: application/json

{
    "amount": 15000,
    "currency": "BAM",
    "locationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 361,
  "message" : "The requested amount exceeds the user's limit."
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/create-withdraw-reservation HTTP/1.1 

Content-Type: application/json

{
    "amount": 15000,
    "currency": "BAM",
    "locationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 409,
  "message" : "User has already created lockless reservation"
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/create-withdraw-reservation HTTP/1.1 

Content-Type: application/json

{
    "amount": 15000,
    "currency": "BAM",
    "locationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 99,
  "message" : "Currency not supported"
}
Get Regulatory Payout Limit
GET /maxbridge/api/v1/cashdesks/get-regulatory-payout-limit

Returns the regulatory rolling payout limit for the signed-in player.

Request headers

X-Requested-With
string required

Always true. Required by the Auth Proxy.

Referer
string required

Auth Proxy origin.

Cookie
string required

Session cookie issued by CORE during authentication and forwarded by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope for Get Regulatory Payout Limit.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Object
userId
integer int64

User id.

Example:
1234
paidOutAmount
number double

Amount already paid out inside the rolling window.

Example:
45000
limitAmount
number double

Regulatory limit for the window.

Example:
200000
remainingAmount
number double

Remaining headroom. null when enforced is false.

Example:
155000
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
asOf
string date-time

Timestamp the numbers were calculated at.

Example:
2026-09-24T11:42:05Z
enforced
boolean

Whether the limit is currently enforced for this user.

Example:
true
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
GET https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/get-regulatory-payout-limit HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": {
        "userId": 1234,
        "paidOutAmount": 45000,
        "limitAmount": 200000,
        "remainingAmount": 155000,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z",
        "asOf": "2026-09-24T11:42:05Z",
        "enforced": true
    },
    "httpStatusCode": 1
}
GET https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/get-regulatory-payout-limit HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 111,
  "message" : "Provider returned an empty regulatory payout limit response"
}
Cancel Reservation
POST /maxbridge/api/v1/cashdesks/cancel-reservation

Cancels the signed-in player’s active cash-desk reservation and releases the reserved amount.

Request headers

X-Requested-With
string required

Always true. Required by the Auth Proxy.

Referer
string required

Auth Proxy origin.

Cookie
string required

Session cookie issued by CORE during authentication and forwarded by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope for Cancel Reservation.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Object
id
string uuid

Cancelled reservation id.

Example:
9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31
reservedAmount
number double

Amount that was reserved and is now released.

Example:
15000
currency
string

Currency of the reservation.

Example:
BAM
status
string

Status after cancellation.

Enumeration:
Active
PaidOut
Expired
Cancelled
Example:
Cancelled
locationId
string uuid

Branch the reservation belonged to.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/cancel-reservation HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": {
        "id": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
        "reservedAmount": 15000,
        "currency": "BAM",
        "status": "Cancelled",
        "locationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
    },
    "httpStatusCode": 1
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/cashdesks/cancel-reservation HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 404,
  "message" : "Lockless reservation not found"
}
Incoming / Retail
POST /pay-maxbridge/api/v1/retail/get-user-info
POST /pay-maxbridge/api/v1/retail/withdraw
Get User Info
POST /pay-maxbridge/api/v1/retail/get-user-info

Returns the player’s CORE profile, KYC documents and current wallet balance. The cash-desk operator calls it before paying out a reservation.

Request headers

hash
string required

Signature used to validate request data. Hash is calculated on the concatenated string SHA256(rawRequestBody + Nonce + Secret), lower-case hex.

nonce
string required

Random single-use value generated per request and included in the hash payload. MaxBridge returns the UNIX timestamp in seconds as the response nonce.

Request body

User and currency to look up.

Object
userId
integer int32 required

User id in PAM&Wallet. Must be greater than zero.

Example:
12345
currency
string required

ISO-4217 alphabetic currency code; must be present in SupportedCurrencies.

Example:
EUR

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope for Get User Info.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Object
userDataResult
Object

User profile returned by CORE, including limits and KYC documents.

userId
integer int64

User id in PAM&Wallet.

Example:
12345
userName
string

Login name.

Example:
player_12345
fullName
string

Full name.

Example:
Marko Markovic
birthDate
string date-time

Date of birth.

Example:
1988-04-17T00:00:00Z
gamingIndex
integer int32

CORE gaming index.

Example:
0
fraudIndex
integer int32

CORE fraud index.

Example:
0
isOtpRequired
boolean

Whether CORE requires OTP for this user.

Example:
false
userDocs
Array
Object

KYC document attached to the user in CORE.

documentId
integer int64

CORE document id.

Example:
90210
documentTypeId
integer int32

Document type id.

Example:
1
documentNumber
string

Document number.

Example:
A1234567
personalId
string

National personal identification number.

Example:
1704988710023
documentCountryId
integer int32

Issuing country id.

Example:
70
documentIssueDate
string date-time

Issue date.

Example:
2019-05-02T00:00:00Z
documentExpirationDate
string date-time

Expiration date.

Example:
2029-05-02T00:00:00Z
documentIssuingAuthority
string

Issuing authority.

Example:
MUP
documentIssuingPlace
string

Issuing place.

Example:
Sarajevo
documentStatus
string

Verification status in CORE.

Example:
Approved
statusNote
string

Reviewer note.

userId
integer int64

Owner user id.

Example:
12345
dateModified
string date-time

Last modification timestamp.

Example:
2024-03-11T09:15:00Z
additionalData
string

Free-form additional data.

transactionMaxLimit
number double

Maximum allowed transaction amount for the requested transaction type.

Example:
500000
transactionMinLimit
number double

Minimum allowed transaction amount.

Example:
500
userStatusId
integer int32

CORE user status id.

Example:
1
preferredCurrencyId
integer int32

Preferred currency id.

Example:
978
referralId
integer int64

Referral id.

registrationDomain
string

Registration domain.

Example:
maxbet.rs
additionalData
string

Free-form additional data.

balance
integer int64

Current wallet balance in minor units as reported by CORE.

Example:
152300
currency
string

Alphabetic currency code of the balance.

Example:
EUR
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
Example 3
Example 4
POST https://fimb-pts.maxbet.cloud/pay-maxbridge/api/v1/retail/get-user-info HTTP/1.1 

Content-Type: application/json

{
    "userId": 12345,
    "currency": "EUR"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": {
        "userDataResult": {
            "userId": 12345,
            "userName": "player_12345",
            "fullName": "Marko Markovic",
            "birthDate": "1988-04-17T00:00:00Z",
            "gamingIndex": 1,
            "fraudIndex": 1,
            "isOtpRequired": true,
            "userDocs": [
                {
                    "documentId": 90210,
                    "documentTypeId": 1,
                    "documentNumber": "A1234567",
                    "personalId": "1704988710023",
                    "documentCountryId": 70,
                    "documentIssueDate": "2019-05-02T00:00:00Z",
                    "documentExpirationDate": "2029-05-02T00:00:00Z",
                    "documentIssuingAuthority": "MUP",
                    "documentIssuingPlace": "Sarajevo",
                    "documentStatus": "Approved",
                    "statusNote": "",
                    "userId": 12345,
                    "dateModified": "2024-03-11T09:15:00Z",
                    "additionalData": ""
                }
            ],
            "transactionMaxLimit": 500000,
            "transactionMinLimit": 500,
            "userStatusId": 1,
            "preferredCurrencyId": 978,
            "referralId": 1,
            "registrationDomain": "maxbet.rs",
            "additionalData": ""
        },
        "balance": 152300,
        "currency": "EUR"
    },
    "httpStatusCode": 1
}
POST https://fimb-pts.maxbet.cloud/pay-maxbridge/api/v1/retail/get-user-info HTTP/1.1 

Content-Type: application/json

{
    "userId": 12345,
    "currency": "EUR"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 111,
  "message" : "Unable to get currency model"
}
POST https://fimb-pts.maxbet.cloud/pay-maxbridge/api/v1/retail/get-user-info HTTP/1.1 

Content-Type: application/json

{
    "userId": 12345,
    "currency": "EUR"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 139,
  "message" : "Wrong hash"
}
POST https://fimb-pts.maxbet.cloud/pay-maxbridge/api/v1/retail/get-user-info HTTP/1.1 

Content-Type: application/json

{
    "userId": 12345,
    "currency": "EUR"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 112,
  "message" : "'hash' header must not be empty."
}
Withdraw
POST /pay-maxbridge/api/v1/retail/withdraw

Debits the player’s wallet - the money-moving step of a cash-desk payout. The transaction is recorded in Pay Persistence and booked in CORE; providerTransactionId acts as the idempotency key.

Request headers

hash
string required

Signature used to validate request data. Hash is calculated on the concatenated string SHA256(rawRequestBody + Nonce + Secret), lower-case hex.

nonce
string required

Random single-use value generated per request and included in the hash payload. MaxBridge returns the UNIX timestamp in seconds as the response nonce.

Request body

Withdrawal instruction.

Object
userId
integer int32 required

User id in PAM&Wallet. Must be greater than zero.

Example:
12345
currency
string required

ISO-4217 alphabetic currency code; must be supported by the integration.

Example:
EUR
amount
number double required

Amount to withdraw. Must be greater than zero.

Example:
100
fee
number double

Transaction fee. Must be zero or greater; 0 means no fee is booked.

Example:
1
serviceId
integer int32 required

MaxBet service/desk identifier. Must be greater than zero.

Example:
1234
clientIp
string required

IP address of the operator workstation. Required.

Example:
192.168.1.1
language
string

Optional UI language code.

Example:
en
providerTransactionId
string uuid required

Provider transaction id (GUID). Required; used as the CORE provider transaction reference, so resending it yields code 151.

Example:
9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31
additionalData
string

Optional JSON object serialised as a string; stored on the transaction.

Example:
{"locationId":"3fa85f64-5717-4562-b3fc-2c963f66afa6"}

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope for Withdraw.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Object
sisTransactionId
integer int64

Pay Persistence transaction id.

Example:
987654
providerTransactionId
string

Provider transaction id / reference.

Example:
9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31
coreTransactionId
string

CORE transaction id.

Example:
CORE-556677
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
Example 3
POST https://fimb-pts.maxbet.cloud/pay-maxbridge/api/v1/retail/withdraw HTTP/1.1 

Content-Type: application/json

{
    "userId": 12345,
    "currency": "EUR",
    "amount": 100,
    "fee": 1,
    "serviceId": 1234,
    "clientIp": "192.168.1.1",
    "language": "en",
    "providerTransactionId": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
    "additionalData": "{\"locationId\":\"3fa85f64-5717-4562-b3fc-2c963f66afa6\"}"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": {
        "sisTransactionId": 987654,
        "providerTransactionId": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
        "coreTransactionId": "CORE-556677"
    },
    "httpStatusCode": 1
}
POST https://fimb-pts.maxbet.cloud/pay-maxbridge/api/v1/retail/withdraw HTTP/1.1 

Content-Type: application/json

{
    "userId": 12345,
    "currency": "EUR",
    "amount": 100,
    "fee": 1,
    "serviceId": 1234,
    "clientIp": "192.168.1.1",
    "language": "en",
    "providerTransactionId": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
    "additionalData": "{\"locationId\":\"3fa85f64-5717-4562-b3fc-2c963f66afa6\"}"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 111,
  "message" : "Users max limit is less than amount"
}
POST https://fimb-pts.maxbet.cloud/pay-maxbridge/api/v1/retail/withdraw HTTP/1.1 

Content-Type: application/json

{
    "userId": 12345,
    "currency": "EUR",
    "amount": 100,
    "fee": 1,
    "serviceId": 1234,
    "clientIp": "192.168.1.1",
    "language": "en",
    "providerTransactionId": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
    "additionalData": "{\"locationId\":\"3fa85f64-5717-4562-b3fc-2c963f66afa6\"}"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 99,
  "message" : "Currency not supported"
}
Incoming / SSBT Deposits
GET /maxbridge/api/v1/ssbt/get-transaction-details
POST /maxbridge/api/v1/ssbt/deposit
POST /maxbridge/api/v1/ssbt/reject
Get Transaction Details
GET /maxbridge/api/v1/ssbt/get-transaction-details

Returns the terminal (SSBT) deposit reservation the player started, so the front-end can show amount, fee, terminal and branch.

Request parameters

reservationId
string uuid required

Unique id of the deposit reservation in the MaxBet retail service.

Request headers

X-Requested-With
string required

Always true. Required by the Auth Proxy.

Referer
string required

Auth Proxy origin.

Cookie
string required

Session cookie issued by CORE during authentication and forwarded by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope for SSBT deposit details / reject.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Object

SSBT (terminal) deposit reservation. Same shape is returned by Get Transaction Details, Reject and inside providerTransactionDetails.

reservationId
string uuid

Deposit reservation id (provider field depositId).

Example:
5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44
deviceId
integer int32

Numeric terminal id.

Example:
4711
maxBetDeviceId
string uuid

MaxBet terminal GUID.

Example:
1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c
fee
number double

Deposit fee.

Example:
0
amount
number double

Deposit amount. Must be greater than zero for the commit to proceed.

Example:
5000
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
currency
string

ISO-4217 alphabetic currency code (exactly 3 characters).

Example:
BAM
operatorFirstName
string

Terminal operator first name.

Example:
Ana
operatorLastName
string

Terminal operator last name.

Example:
Ilic
status
string

Deposit status on the provider side.

Enumeration:
Pending
Success
Failed
RolledBack
Rejected
Example:
Pending
createdAt
string date-time

Creation timestamp.

Example:
2026-09-24T11:58:12Z
deviceStickerId
string

Physical sticker id of the terminal.

Example:
TRM-0091
identificationType
string

Identification type used at the terminal.

Example:
IdCard
identification
string

Identification value used at the terminal.

Example:
A1234567
reference
string

Provider transaction reference; becomes providerTransactionId after a commit.

Example:
MB-REF-99881
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
GET https://fimb-pts.maxbet.cloud/maxbridge/api/v1/ssbt/get-transaction-details HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": {
        "reservationId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44",
        "deviceId": 4711,
        "maxBetDeviceId": "1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c",
        "fee": 1,
        "amount": 5000,
        "location": {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        },
        "currency": "BAM",
        "operatorFirstName": "Ana",
        "operatorLastName": "Ilic",
        "status": "Pending",
        "createdAt": "2026-09-24T11:58:12Z",
        "deviceStickerId": "TRM-0091",
        "identificationType": "IdCard",
        "identification": "A1234567",
        "reference": "MB-REF-99881"
    },
    "httpStatusCode": 1
}
GET https://fimb-pts.maxbet.cloud/maxbridge/api/v1/ssbt/get-transaction-details HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 156,
  "message" : "Deposit not found"
}
Deposit
POST /maxbridge/api/v1/ssbt/deposit

Confirms a terminal deposit and credits the amount to the player’s wallet. MaxBridge re-reads the reservation, commits it on the provider side, records it in Pay Persistence and books the deposit in CORE.

Request headers

X-Requested-With
string required

Always true. Required by the Auth Proxy.

Referer
string required

Auth Proxy origin.

Cookie
string required

Session cookie issued by CORE during authentication and forwarded by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

Proxy-Client-IP
string required

Client IP forwarded by the Auth Proxy. Stored on the Pay Persistence and CORE transactions.

Request body

Reservation to commit.

Object
reservationId
string uuid required

Deposit reservation id created by the terminal. Required.

Example:
5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope for Deposit.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Object

Result of a committed terminal deposit. error is only populated when the outcome code is 362.

sisTransactionId
integer int64

Pay Persistence transaction id.

Example:
987654
providerTransactionId
string

Provider reference of the committed deposit.

Example:
MB-REF-99881
coreTransactionId
string

CORE transaction id of the credit.

Example:
CORE-556677
providerTransactionDetails
Object

SSBT (terminal) deposit reservation. Same shape is returned by Get Transaction Details, Reject and inside providerTransactionDetails.

reservationId
string uuid

Deposit reservation id (provider field depositId).

Example:
5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44
deviceId
integer int32

Numeric terminal id.

Example:
4711
maxBetDeviceId
string uuid

MaxBet terminal GUID.

Example:
1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c
fee
number double

Deposit fee.

Example:
0
amount
number double

Deposit amount. Must be greater than zero for the commit to proceed.

Example:
5000
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
currency
string

ISO-4217 alphabetic currency code (exactly 3 characters).

Example:
BAM
operatorFirstName
string

Terminal operator first name.

Example:
Ana
operatorLastName
string

Terminal operator last name.

Example:
Ilic
status
string

Deposit status on the provider side.

Enumeration:
Pending
Success
Failed
RolledBack
Rejected
Example:
Pending
createdAt
string date-time

Creation timestamp.

Example:
2026-09-24T11:58:12Z
deviceStickerId
string

Physical sticker id of the terminal.

Example:
TRM-0091
identificationType
string

Identification type used at the terminal.

Example:
IdCard
identification
string

Identification value used at the terminal.

Example:
A1234567
reference
string

Provider transaction reference; becomes providerTransactionId after a commit.

Example:
MB-REF-99881
error
Object

Structured error returned inside data.error for whitelisted provider errors. Shared by the SSBT deposit and lockless reservation flows.

errorCode
integer int32

Provider raw error code (5011 or 4022). For traceability, not for branching.

Example:
5011
reason
string

Machine-friendly reason, safe to branch on.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
message
string

Human readable summary, safe to show to the user.

Example:
SSBT deposit regulatory rolling limit exceeded.
traceId
string

Provider trace id for correlation.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
details
Object

Provider-supplied numbers for a whitelisted error. Superset of the SSBT (5011) and lockless reservation (4022) shapes; irrelevant fields are null.

domain
string

Provider domain the limit belongs to: SsbtDeposit or LocklessReservation.

Example:
SsbtDeposit
userId
integer int64

User id reported by the provider.

Example:
1234
requestedAmount
number double

Amount that was requested.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits inside the rolling window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits inside the rolling window.

Example:
80000
depositedInWindow
number double

Total deposits inside the rolling window.

Example:
200000
paidOutInWindow
number double

Total payouts inside the rolling window (withdrawal flow).

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
httpStatusCode
integer int32

HTTP status echo. Normally null.

Example 1
Example 2
Example 3
Example 4
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/ssbt/deposit HTTP/1.1 

Content-Type: application/json

{
    "reservationId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": {
        "sisTransactionId": 987654,
        "providerTransactionId": "MB-REF-99881",
        "coreTransactionId": "CORE-556677",
        "providerTransactionDetails": {
            "reservationId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44",
            "deviceId": 4711,
            "maxBetDeviceId": "1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c",
            "fee": 1,
            "amount": 5000,
            "location": {
                "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
                "name": "Cash Desk Centar",
                "description": "Main street branch",
                "lat": 44.7866,
                "long": 20.4489,
                "address": "Knez Mihailova 1",
                "stickerId": "SD-1042"
            },
            "currency": "BAM",
            "operatorFirstName": "Ana",
            "operatorLastName": "Ilic",
            "status": "Pending",
            "createdAt": "2026-09-24T11:58:12Z",
            "deviceStickerId": "TRM-0091",
            "identificationType": "IdCard",
            "identification": "A1234567",
            "reference": "MB-REF-99881"
        },
        "error": {
            "errorCode": 5011,
            "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
            "message": "SSBT deposit regulatory rolling limit exceeded.",
            "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
            "details": {
                "domain": "SsbtDeposit",
                "userId": 1234,
                "requestedAmount": 5000,
                "cashDeskDepositedInWindow": 120000,
                "ssbtDepositedInWindow": 80000,
                "depositedInWindow": 200000,
                "paidOutInWindow": 200000,
                "limit": 200000,
                "remaining": 1,
                "windowDays": 30,
                "windowStart": "2026-08-25T00:00:00Z"
            }
        }
    },
    "httpStatusCode": 1
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/ssbt/deposit HTTP/1.1 

Content-Type: application/json

{
    "reservationId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 182,
  "message" : "Provider Transaction status is Pending"
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/ssbt/deposit HTTP/1.1 

Content-Type: application/json

{
    "reservationId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 362,
  "message" : "SSBT deposit regulatory rolling limit exceeded.",
  "data" : {
    "sisTransactionId" : 0,
    "error" : {
      "errorCode" : 5011,
      "reason" : "REGULATORY_ROLLING_LIMIT_EXCEEDED",
      "message" : "SSBT deposit regulatory rolling limit exceeded.",
      "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
      "details" : {
        "domain" : "SsbtDeposit",
        "userId" : 1234,
        "requestedAmount" : 5000,
        "cashDeskDepositedInWindow" : 120000,
        "ssbtDepositedInWindow" : 80000,
        "depositedInWindow" : 200000,
        "limit" : 200000,
        "remaining" : 0,
        "windowDays" : 30,
        "windowStart" : "2026-08-25T00:00:00Z"
      }
    }
  }
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/ssbt/deposit HTTP/1.1 

Content-Type: application/json

{
    "reservationId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 111,
  "message" : "Users max limit is less than amount"
}
Reject
POST /maxbridge/api/v1/ssbt/reject

Rejects a still-pending terminal deposit reservation. Nothing is booked in CORE or Pay Persistence.

Request headers

X-Requested-With
string required

Always true. Required by the Auth Proxy.

Referer
string required

Auth Proxy origin.

Cookie
string required

Session cookie issued by CORE during authentication and forwarded by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

Request body

Reservation to reject.

Object
reservationId
string uuid required

Deposit reservation id to reject. Required.

Example:
5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Envelope for SSBT deposit details / reject.

code
integer int32 required

Business outcome code. 10 = success.

Example:
10
message
string required

Outcome message.

Example:
Success
data
Object

SSBT (terminal) deposit reservation. Same shape is returned by Get Transaction Details, Reject and inside providerTransactionDetails.

reservationId
string uuid

Deposit reservation id (provider field depositId).

Example:
5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44
deviceId
integer int32

Numeric terminal id.

Example:
4711
maxBetDeviceId
string uuid

MaxBet terminal GUID.

Example:
1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c
fee
number double

Deposit fee.

Example:
0
amount
number double

Deposit amount. Must be greater than zero for the commit to proceed.

Example:
5000
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
currency
string

ISO-4217 alphabetic currency code (exactly 3 characters).

Example:
BAM
operatorFirstName
string

Terminal operator first name.

Example:
Ana
operatorLastName
string

Terminal operator last name.

Example:
Ilic
status
string

Deposit status on the provider side.

Enumeration:
Pending
Success
Failed
RolledBack
Rejected
Example:
Pending
createdAt
string date-time

Creation timestamp.

Example:
2026-09-24T11:58:12Z
deviceStickerId
string

Physical sticker id of the terminal.

Example:
TRM-0091
identificationType
string

Identification type used at the terminal.

Example:
IdCard
identification
string

Identification value used at the terminal.

Example:
A1234567
reference
string

Provider transaction reference; becomes providerTransactionId after a commit.

Example:
MB-REF-99881
httpStatusCode
integer int32

HTTP status echo. Normally null.

Examples
{
  "code" : 10,
  "message" : "Success",
  "data" : {
    "reservationId" : "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44",
    "deviceId" : 4711,
    "maxBetDeviceId" : "1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c",
    "fee" : 0,
    "amount" : 5000,
    "location" : {
      "id" : "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "name" : "Cash Desk Centar",
      "description" : "Main street branch",
      "lat" : 44.7866,
      "long" : 20.4489,
      "address" : "Knez Mihailova 1",
      "stickerId" : "SD-1042"
    },
    "currency" : "BAM",
    "operatorFirstName" : "Ana",
    "operatorLastName" : "Ilic",
    "status" : "Rejected",
    "createdAt" : "2026-09-24T11:58:12Z",
    "deviceStickerId" : "TRM-0091",
    "identificationType" : "IdCard",
    "identification" : "A1234567",
    "reference" : "MB-REF-99881"
  }
}
{
  "code" : 156,
  "message" : "Deposit not found"
}
Example 1
Example 2
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/ssbt/reject HTTP/1.1 

Content-Type: application/json

{
    "reservationId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
    "code": 10,
    "message": "Success",
    "data": {
        "reservationId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44",
        "deviceId": 4711,
        "maxBetDeviceId": "1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c",
        "fee": 1,
        "amount": 5000,
        "location": {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        },
        "currency": "BAM",
        "operatorFirstName": "Ana",
        "operatorLastName": "Ilic",
        "status": "Pending",
        "createdAt": "2026-09-24T11:58:12Z",
        "deviceStickerId": "TRM-0091",
        "identificationType": "IdCard",
        "identification": "A1234567",
        "reference": "MB-REF-99881"
    },
    "httpStatusCode": 1
}
POST https://fimb-pts.maxbet.cloud/maxbridge/api/v1/ssbt/reject HTTP/1.1 

Content-Type: application/json

{
    "reservationId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44"
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "code" : 156,
  "message" : "Deposit not found"
}
Outgoing / Cash-Desk Withdrawals
POST /api/location/get-locations
GET /api/lockless-reservation/preferred-branch
GET /api/lockless-reservation/get-reservation
POST /api/lockless-reservation/create
GET /api/lockless-reservation/regulatory-payout-limit
POST /api/lockless-reservation/cancel
Get Locations
POST /api/location/get-locations

Returns cash-desk locations from the MaxBet RMS service. An empty body returns every location and the answer is cached for 10 minutes.

Request headers

Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Request body

Optional filters.

Object

All filters are optional. An empty body returns every location (cached for 10 minutes).

id
string uuid

Optional exact location id filter.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
address
string

Optional address filter. At least 3 characters when provided.

Example:
Knez Mihailova
name
string

Optional name filter. At least 3 characters when provided.

Example:
Centar

Responses

200 200

OK - business outcome is carried in the payload.

Body
Array
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
Examples
Get Lockless Reservation Preferred Branch
GET /api/lockless-reservation/preferred-branch

Returns the branch the player selected during their first withdrawal.

Request parameters

userId
integer int64 required

User id in PAM&Wallet.

Request headers

Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Provider envelope carrying locations.

statusCode
integer int32

Provider HTTP-like status code.

Example:
200
message
string

Provider message.

Example:
Success
traceId
string

Provider trace id.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
errorCode
integer int32

Provider error code; 5011 and 4022 are mapped by MaxBridge to code 362.

errors
Object

errors object as returned by MaxBet next to errorCode.

domain
string

Provider domain.

Example:
SsbtDeposit
reason
string

Provider reason code.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
userId
integer int64

User id.

Example:
1234
requestedAmount
number double

Requested amount.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits in window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits in window.

Example:
80000
depositedInWindow
number double

Total deposits in window.

Example:
200000
paidOutInWindow
number double

Total payouts in window.

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
data
Array
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
Example 1
Example 2
GET https://fimb-pts.maxbet.cloud/api/lockless-reservation/preferred-branch HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "statusCode": 200,
    "message": "Success",
    "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
    "errorCode": 1,
    "errors": {
        "domain": "SsbtDeposit",
        "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
        "userId": 1234,
        "requestedAmount": 5000,
        "cashDeskDepositedInWindow": 120000,
        "ssbtDepositedInWindow": 80000,
        "depositedInWindow": 200000,
        "paidOutInWindow": 200000,
        "limit": 200000,
        "remaining": 1,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z"
    },
    "data": [
        {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        }
    ]
}
GET https://fimb-pts.maxbet.cloud/api/lockless-reservation/preferred-branch HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "statusCode" : 404,
  "message" : "Preferred branch not found",
  "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01"
}
Get Reservation
GET /api/lockless-reservation/get-reservation

Returns the player’s current lockless (cash-desk withdrawal) reservation. The provider exposes the amount as reservedAmount; MaxBridge republishes it as amount.

Request parameters

UserId
integer int64 required

User id in PAM&Wallet.

Request headers

Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Provider envelope for get-reservation.

statusCode
integer int32

Provider HTTP-like status code.

Example:
200
message
string

Provider message.

Example:
Success
traceId
string

Provider trace id.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
errorCode
integer int32

Provider error code; 5011 and 4022 are mapped by MaxBridge to code 362.

errors
Object

errors object as returned by MaxBet next to errorCode.

domain
string

Provider domain.

Example:
SsbtDeposit
reason
string

Provider reason code.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
userId
integer int64

User id.

Example:
1234
requestedAmount
number double

Requested amount.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits in window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits in window.

Example:
80000
depositedInWindow
number double

Total deposits in window.

Example:
200000
paidOutInWindow
number double

Total payouts in window.

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
data
Object
id
string uuid

Reservation id.

Example:
9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31
reservedAmount
number double

Reserved amount.

Example:
15000
confirmationPin
string

Confirmation PIN.

Example:
482913
fee
number double

Reservation fee.

Example:
0
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
createDate
string date-time

Creation timestamp.

Example:
2026-09-24T11:42:05Z
expirationDate
string date-time

Expiration timestamp.

Example:
2026-09-26T11:42:05Z
validAfterDate
string date-time

Valid-after timestamp.

Example:
2026-09-24T12:42:05Z
status
string

Reservation status.

Enumeration:
Active
PaidOut
Expired
Cancelled
Example:
Active
description
string

Provider description.

Example:
Lockless reservation created from web
userId
integer int32

User id.

Example:
1234
Example 1
Example 2
GET https://fimb-pts.maxbet.cloud/api/lockless-reservation/get-reservation HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "statusCode": 200,
    "message": "Success",
    "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
    "errorCode": 1,
    "errors": {
        "domain": "SsbtDeposit",
        "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
        "userId": 1234,
        "requestedAmount": 5000,
        "cashDeskDepositedInWindow": 120000,
        "ssbtDepositedInWindow": 80000,
        "depositedInWindow": 200000,
        "paidOutInWindow": 200000,
        "limit": 200000,
        "remaining": 1,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z"
    },
    "data": {
        "id": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
        "reservedAmount": 15000,
        "confirmationPin": "482913",
        "fee": 1,
        "location": {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        },
        "createDate": "2026-09-24T11:42:05Z",
        "expirationDate": "2026-09-26T11:42:05Z",
        "validAfterDate": "2026-09-24T12:42:05Z",
        "status": "Active",
        "description": "Lockless reservation created from web",
        "userId": 1234
    }
}
GET https://fimb-pts.maxbet.cloud/api/lockless-reservation/get-reservation HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "statusCode" : 400,
  "message" : "Regulatory rolling limit exceeded.",
  "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
  "errorCode" : 4022,
  "errors" : {
    "domain" : "LocklessReservation",
    "reason" : "REGULATORY_ROLLING_LIMIT_EXCEEDED",
    "userId" : 1234,
    "requestedAmount" : 15000,
    "paidOutInWindow" : 200000,
    "limit" : 200000,
    "remaining" : 0,
    "windowDays" : 30,
    "windowStart" : "2026-08-25T00:00:00Z"
  }
}
Create Withdrawal Reservation
POST /api/lockless-reservation/create

Creates a lockless reservation for the player. The provider answers HTTP 409 when an active reservation already exists.

Request headers

Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Request body

Reservation to create.

Object
amount
number double required

Amount to reserve.

Example:
15000
balance
integer int64

Wallet balance MaxBridge just read from CORE.

Example:
152300
currency
string required

Provider currency code.

Example:
BAM
locationId
string uuid required

Branch chosen by the user.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
userId
integer int32 required

User id in PAM&Wallet.

Example:
1234

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Provider envelope for create.

statusCode
integer int32

Provider HTTP-like status code.

Example:
200
message
string

Provider message.

Example:
Success
traceId
string

Provider trace id.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
errorCode
integer int32

Provider error code; 5011 and 4022 are mapped by MaxBridge to code 362.

errors
Object

errors object as returned by MaxBet next to errorCode.

domain
string

Provider domain.

Example:
SsbtDeposit
reason
string

Provider reason code.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
userId
integer int64

User id.

Example:
1234
requestedAmount
number double

Requested amount.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits in window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits in window.

Example:
80000
depositedInWindow
number double

Total deposits in window.

Example:
200000
paidOutInWindow
number double

Total payouts in window.

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
data
Object
id
string uuid

Reservation id.

Example:
9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31
reservedAmount
number double

Reserved amount.

Example:
15000
confirmationPin
string

Confirmation PIN.

Example:
482913
fee
number double

Reservation fee.

Example:
0
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
createDate
string date-time

Creation timestamp.

Example:
2026-09-24T11:42:05Z
expirationDate
string date-time

Expiration timestamp.

Example:
2026-09-26T11:42:05Z
validAfterDate
string date-time

Valid-after timestamp.

Example:
2026-09-24T12:42:05Z
status
string

Reservation status.

Enumeration:
Active
PaidOut
Expired
Cancelled
Example:
Active
description
string

Provider description.

Example:
Lockless reservation created from web
userId
integer int32

User id.

Example:
1234
balance
number double

Wallet balance after the reservation.

Example:
137300
currency
string

Reservation currency.

Example:
BAM
Example 1
Example 2
POST https://fimb-pts.maxbet.cloud/api/lockless-reservation/create HTTP/1.1 

Content-Type: application/json

{
    "amount": 15000,
    "balance": 152300,
    "currency": "BAM",
    "locationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "userId": 1234
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
    "statusCode": 200,
    "message": "Success",
    "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
    "errorCode": 1,
    "errors": {
        "domain": "SsbtDeposit",
        "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
        "userId": 1234,
        "requestedAmount": 5000,
        "cashDeskDepositedInWindow": 120000,
        "ssbtDepositedInWindow": 80000,
        "depositedInWindow": 200000,
        "paidOutInWindow": 200000,
        "limit": 200000,
        "remaining": 1,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z"
    },
    "data": {
        "id": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
        "reservedAmount": 15000,
        "confirmationPin": "482913",
        "fee": 1,
        "location": {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        },
        "createDate": "2026-09-24T11:42:05Z",
        "expirationDate": "2026-09-26T11:42:05Z",
        "validAfterDate": "2026-09-24T12:42:05Z",
        "status": "Active",
        "description": "Lockless reservation created from web",
        "userId": 1234,
        "balance": 137300,
        "currency": "BAM"
    }
}
POST https://fimb-pts.maxbet.cloud/api/lockless-reservation/create HTTP/1.1 

Content-Type: application/json

{
    "amount": 15000,
    "balance": 152300,
    "currency": "BAM",
    "locationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "userId": 1234
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "statusCode" : 409,
  "message" : "Active reservation already exists",
  "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01"
}
Get Regulatory Payout Limit
GET /api/lockless-reservation/regulatory-payout-limit

Returns the regulatory rolling payout limit for the player.

Request parameters

userId
integer int64 required

User id in PAM&Wallet.

Request headers

Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Provider envelope for regulatory-payout-limit.

statusCode
integer int32

Provider HTTP-like status code.

Example:
200
message
string

Provider message.

Example:
Success
traceId
string

Provider trace id.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
errorCode
integer int32

Provider error code; 5011 and 4022 are mapped by MaxBridge to code 362.

errors
Object

errors object as returned by MaxBet next to errorCode.

domain
string

Provider domain.

Example:
SsbtDeposit
reason
string

Provider reason code.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
userId
integer int64

User id.

Example:
1234
requestedAmount
number double

Requested amount.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits in window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits in window.

Example:
80000
depositedInWindow
number double

Total deposits in window.

Example:
200000
paidOutInWindow
number double

Total payouts in window.

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
data
Object
userId
integer int64

User id.

Example:
1234
paidOutAmount
number double

Paid out inside the window.

Example:
45000
limitAmount
number double

Regulatory limit.

Example:
200000
remainingAmount
number double

Remaining headroom; only meaningful when enforced is true.

Example:
155000
windowDays
integer int32

Window length in days.

Example:
30
windowStart
string date-time

Window start.

Example:
2026-08-25T00:00:00Z
asOf
string date-time

Calculation timestamp.

Example:
2026-09-24T11:42:05Z
enforced
boolean

Whether the limit is enforced.

Example:
true
Example 1
Example 2
GET https://fimb-pts.maxbet.cloud/api/lockless-reservation/regulatory-payout-limit HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "statusCode": 200,
    "message": "Success",
    "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
    "errorCode": 1,
    "errors": {
        "domain": "SsbtDeposit",
        "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
        "userId": 1234,
        "requestedAmount": 5000,
        "cashDeskDepositedInWindow": 120000,
        "ssbtDepositedInWindow": 80000,
        "depositedInWindow": 200000,
        "paidOutInWindow": 200000,
        "limit": 200000,
        "remaining": 1,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z"
    },
    "data": {
        "userId": 1234,
        "paidOutAmount": 45000,
        "limitAmount": 200000,
        "remainingAmount": 155000,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z",
        "asOf": "2026-09-24T11:42:05Z",
        "enforced": true
    }
}
GET https://fimb-pts.maxbet.cloud/api/lockless-reservation/regulatory-payout-limit HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "statusCode" : 200,
  "message" : "Success",
  "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
  "data" : {
    "userId" : 1234,
    "paidOutAmount" : 45000,
    "limitAmount" : 200000,
    "windowDays" : 30,
    "windowStart" : "2026-08-25T00:00:00Z",
    "asOf" : "2026-09-24T11:42:05Z",
    "enforced" : false
  }
}
Cancel Lockless Reservation
POST /api/lockless-reservation/cancel

Cancels the player’s active lockless reservation.

Request headers

Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Request body

User whose reservation is cancelled.

Object
UserId
integer int32 required

User id in PAM&Wallet. Note the Pascal-case property name expected by the provider.

Example:
1234

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Provider envelope for cancel.

statusCode
integer int32

Provider HTTP-like status code.

Example:
200
message
string

Provider message.

Example:
Success
traceId
string

Provider trace id.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
errorCode
integer int32

Provider error code; 5011 and 4022 are mapped by MaxBridge to code 362.

errors
Object

errors object as returned by MaxBet next to errorCode.

domain
string

Provider domain.

Example:
SsbtDeposit
reason
string

Provider reason code.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
userId
integer int64

User id.

Example:
1234
requestedAmount
number double

Requested amount.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits in window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits in window.

Example:
80000
depositedInWindow
number double

Total deposits in window.

Example:
200000
paidOutInWindow
number double

Total payouts in window.

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
data
Object
id
string uuid

Reservation id.

Example:
9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31
reservedAmount
number double

Released amount.

Example:
15000
currency
string

Reservation currency.

Example:
BAM
status
string

Status after cancellation.

Enumeration:
Active
PaidOut
Expired
Cancelled
Example:
Cancelled
locationId
string uuid

Branch id.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
Example 1
Example 2
POST https://fimb-pts.maxbet.cloud/api/lockless-reservation/cancel HTTP/1.1 

Content-Type: application/json

{
    "UserId": 1234
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
    "statusCode": 200,
    "message": "Success",
    "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
    "errorCode": 1,
    "errors": {
        "domain": "SsbtDeposit",
        "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
        "userId": 1234,
        "requestedAmount": 5000,
        "cashDeskDepositedInWindow": 120000,
        "ssbtDepositedInWindow": 80000,
        "depositedInWindow": 200000,
        "paidOutInWindow": 200000,
        "limit": 200000,
        "remaining": 1,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z"
    },
    "data": {
        "id": "9c1f2b8e-4a77-4d51-9d0a-1f5e7c2b8a31",
        "reservedAmount": 15000,
        "currency": "BAM",
        "status": "Cancelled",
        "locationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
    }
}
POST https://fimb-pts.maxbet.cloud/api/lockless-reservation/cancel HTTP/1.1 

Content-Type: application/json

{
    "UserId": 1234
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "statusCode" : 404,
  "message" : "Not Found",
  "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01"
}
Outgoing / SSBT Deposits
GET /api/ssbt-deposit/details
POST /api/ssbt-deposit/commit
POST /api/ssbt-deposit/reject
SSBT Deposit Details
GET /api/ssbt-deposit/details

Returns a terminal (SSBT) deposit reservation by id.

Request parameters

depositId
string uuid required

Unique identifier of the SSBT deposit reservation.

Request headers

Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Provider envelope for the SSBT deposit endpoints.

statusCode
integer int32

Provider HTTP-like status code.

Example:
200
message
string

Provider message.

Example:
Success
traceId
string

Provider trace id.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
errorCode
integer int32

Provider error code; 5011 and 4022 are mapped by MaxBridge to code 362.

errors
Object

errors object as returned by MaxBet next to errorCode.

domain
string

Provider domain.

Example:
SsbtDeposit
reason
string

Provider reason code.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
userId
integer int64

User id.

Example:
1234
requestedAmount
number double

Requested amount.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits in window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits in window.

Example:
80000
depositedInWindow
number double

Total deposits in window.

Example:
200000
paidOutInWindow
number double

Total payouts in window.

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
data
Object

Shape returned by details, commit and reject on the MaxBet side.

depositId
string uuid

Deposit reservation id.

Example:
5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44
deviceId
integer int32

Numeric terminal id.

Example:
4711
maxBetDeviceId
string uuid

MaxBet terminal GUID.

Example:
1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c
deviceStickerId
string

Terminal sticker id.

Example:
TRM-0091
identificationType
string

Identification type.

Example:
IdCard
identification
string

Identification value.

Example:
A1234567
fee
number double

Deposit fee.

Example:
0
amount
number double

Deposit amount.

Example:
5000
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
currency
string

Currency code.

Example:
BAM
operatorFirstName
string

Operator first name.

Example:
Ana
operatorLastName
string

Operator last name.

Example:
Ilic
status
string

Deposit status.

Enumeration:
Pending
Success
Failed
RolledBack
Rejected
Example:
Pending
createdAt
string date-time

Creation timestamp.

Example:
2026-09-24T11:58:12Z
reference
string

Provider transaction reference.

Example:
MB-REF-99881
Example 1
Example 2
GET https://fimb-pts.maxbet.cloud/api/ssbt-deposit/details HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "statusCode": 200,
    "message": "Success",
    "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
    "errorCode": 1,
    "errors": {
        "domain": "SsbtDeposit",
        "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
        "userId": 1234,
        "requestedAmount": 5000,
        "cashDeskDepositedInWindow": 120000,
        "ssbtDepositedInWindow": 80000,
        "depositedInWindow": 200000,
        "paidOutInWindow": 200000,
        "limit": 200000,
        "remaining": 1,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z"
    },
    "data": {
        "depositId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44",
        "deviceId": 4711,
        "maxBetDeviceId": "1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c",
        "deviceStickerId": "TRM-0091",
        "identificationType": "IdCard",
        "identification": "A1234567",
        "fee": 1,
        "amount": 5000,
        "location": {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        },
        "currency": "BAM",
        "operatorFirstName": "Ana",
        "operatorLastName": "Ilic",
        "status": "Pending",
        "createdAt": "2026-09-24T11:58:12Z",
        "reference": "MB-REF-99881"
    }
}
GET https://fimb-pts.maxbet.cloud/api/ssbt-deposit/details HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "statusCode" : 404,
  "message" : "Not Found",
  "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01"
}
SSBT Deposit Commit
POST /api/ssbt-deposit/commit

Commits a pending SSBT deposit reservation, finalising it on the provider side.

Request headers

Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Request body

Deposit reservation and user to commit.

Object
depositId
string uuid required

Deposit reservation id to commit.

Example:
5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44
userId
integer int32 required

User id in PAM&Wallet.

Example:
1234

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Provider envelope for the SSBT deposit endpoints.

statusCode
integer int32

Provider HTTP-like status code.

Example:
200
message
string

Provider message.

Example:
Success
traceId
string

Provider trace id.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
errorCode
integer int32

Provider error code; 5011 and 4022 are mapped by MaxBridge to code 362.

errors
Object

errors object as returned by MaxBet next to errorCode.

domain
string

Provider domain.

Example:
SsbtDeposit
reason
string

Provider reason code.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
userId
integer int64

User id.

Example:
1234
requestedAmount
number double

Requested amount.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits in window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits in window.

Example:
80000
depositedInWindow
number double

Total deposits in window.

Example:
200000
paidOutInWindow
number double

Total payouts in window.

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
data
Object

Shape returned by details, commit and reject on the MaxBet side.

depositId
string uuid

Deposit reservation id.

Example:
5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44
deviceId
integer int32

Numeric terminal id.

Example:
4711
maxBetDeviceId
string uuid

MaxBet terminal GUID.

Example:
1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c
deviceStickerId
string

Terminal sticker id.

Example:
TRM-0091
identificationType
string

Identification type.

Example:
IdCard
identification
string

Identification value.

Example:
A1234567
fee
number double

Deposit fee.

Example:
0
amount
number double

Deposit amount.

Example:
5000
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
currency
string

Currency code.

Example:
BAM
operatorFirstName
string

Operator first name.

Example:
Ana
operatorLastName
string

Operator last name.

Example:
Ilic
status
string

Deposit status.

Enumeration:
Pending
Success
Failed
RolledBack
Rejected
Example:
Pending
createdAt
string date-time

Creation timestamp.

Example:
2026-09-24T11:58:12Z
reference
string

Provider transaction reference.

Example:
MB-REF-99881
Example 1
Example 2
POST https://fimb-pts.maxbet.cloud/api/ssbt-deposit/commit HTTP/1.1 

Content-Type: application/json

{
    "depositId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44",
    "userId": 1234
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
    "statusCode": 200,
    "message": "Success",
    "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
    "errorCode": 1,
    "errors": {
        "domain": "SsbtDeposit",
        "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
        "userId": 1234,
        "requestedAmount": 5000,
        "cashDeskDepositedInWindow": 120000,
        "ssbtDepositedInWindow": 80000,
        "depositedInWindow": 200000,
        "paidOutInWindow": 200000,
        "limit": 200000,
        "remaining": 1,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z"
    },
    "data": {
        "depositId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44",
        "deviceId": 4711,
        "maxBetDeviceId": "1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c",
        "deviceStickerId": "TRM-0091",
        "identificationType": "IdCard",
        "identification": "A1234567",
        "fee": 1,
        "amount": 5000,
        "location": {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        },
        "currency": "BAM",
        "operatorFirstName": "Ana",
        "operatorLastName": "Ilic",
        "status": "Pending",
        "createdAt": "2026-09-24T11:58:12Z",
        "reference": "MB-REF-99881"
    }
}
POST https://fimb-pts.maxbet.cloud/api/ssbt-deposit/commit HTTP/1.1 

Content-Type: application/json

{
    "depositId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44",
    "userId": 1234
}

HTTP/1.1 200 OK 

Content-Type: application/json

{
  "statusCode" : 400,
  "message" : "SSBT deposit regulatory rolling limit exceeded.",
  "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
  "errorCode" : 5011,
  "errors" : {
    "domain" : "SsbtDeposit",
    "reason" : "REGULATORY_ROLLING_LIMIT_EXCEEDED",
    "userId" : 1234,
    "requestedAmount" : 5000,
    "cashDeskDepositedInWindow" : 120000,
    "ssbtDepositedInWindow" : 80000,
    "depositedInWindow" : 200000,
    "limit" : 200000,
    "remaining" : 0,
    "windowDays" : 30,
    "windowStart" : "2026-08-25T00:00:00Z"
  }
}
SSBT Deposit Reject
POST /api/ssbt-deposit/reject

Rejects a still-pending SSBT deposit reservation.

Request parameters

depositId
string uuid required

Unique identifier of the SSBT deposit reservation.

Request headers

Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Responses

200 200

OK - business outcome is carried in the payload.

Body
Object

Provider envelope for the SSBT deposit endpoints.

statusCode
integer int32

Provider HTTP-like status code.

Example:
200
message
string

Provider message.

Example:
Success
traceId
string

Provider trace id.

Example:
00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01
errorCode
integer int32

Provider error code; 5011 and 4022 are mapped by MaxBridge to code 362.

errors
Object

errors object as returned by MaxBet next to errorCode.

domain
string

Provider domain.

Example:
SsbtDeposit
reason
string

Provider reason code.

Example:
REGULATORY_ROLLING_LIMIT_EXCEEDED
userId
integer int64

User id.

Example:
1234
requestedAmount
number double

Requested amount.

Example:
5000
cashDeskDepositedInWindow
number double

Cash-desk deposits in window.

Example:
120000
ssbtDepositedInWindow
number double

SSBT deposits in window.

Example:
80000
depositedInWindow
number double

Total deposits in window.

Example:
200000
paidOutInWindow
number double

Total payouts in window.

Example:
200000
limit
number double

Regulatory limit.

Example:
200000
remaining
number double

Remaining headroom.

Example:
0
windowDays
integer int32

Rolling window length in days.

Example:
30
windowStart
string date-time

Start of the rolling window.

Example:
2026-08-25T00:00:00Z
data
Object

Shape returned by details, commit and reject on the MaxBet side.

depositId
string uuid

Deposit reservation id.

Example:
5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44
deviceId
integer int32

Numeric terminal id.

Example:
4711
maxBetDeviceId
string uuid

MaxBet terminal GUID.

Example:
1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c
deviceStickerId
string

Terminal sticker id.

Example:
TRM-0091
identificationType
string

Identification type.

Example:
IdCard
identification
string

Identification value.

Example:
A1234567
fee
number double

Deposit fee.

Example:
0
amount
number double

Deposit amount.

Example:
5000
location
Object

Cash-desk branch (location) as exposed to the front-end.

id
string uuid

Location (branch) identifier in the MaxBet retail system.

Example:
3fa85f64-5717-4562-b3fc-2c963f66afa6
name
string

Branch name.

Example:
Cash Desk Centar
description
string

Free-text branch description.

Example:
Main street branch
lat
number double

Latitude.

Example:
44.7866
long
number double

Longitude.

Example:
20.4489
address
string

Street address.

Example:
Knez Mihailova 1
stickerId
string

Physical sticker id glued on the branch/desk.

Example:
SD-1042
currency
string

Currency code.

Example:
BAM
operatorFirstName
string

Operator first name.

Example:
Ana
operatorLastName
string

Operator last name.

Example:
Ilic
status
string

Deposit status.

Enumeration:
Pending
Success
Failed
RolledBack
Rejected
Example:
Pending
createdAt
string date-time

Creation timestamp.

Example:
2026-09-24T11:58:12Z
reference
string

Provider transaction reference.

Example:
MB-REF-99881
Example 1
Example 2
POST https://fimb-pts.maxbet.cloud/api/ssbt-deposit/reject HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
    "statusCode": 200,
    "message": "Success",
    "traceId": "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01",
    "errorCode": 1,
    "errors": {
        "domain": "SsbtDeposit",
        "reason": "REGULATORY_ROLLING_LIMIT_EXCEEDED",
        "userId": 1234,
        "requestedAmount": 5000,
        "cashDeskDepositedInWindow": 120000,
        "ssbtDepositedInWindow": 80000,
        "depositedInWindow": 200000,
        "paidOutInWindow": 200000,
        "limit": 200000,
        "remaining": 1,
        "windowDays": 30,
        "windowStart": "2026-08-25T00:00:00Z"
    },
    "data": {
        "depositId": "5b2d1a7c-9e3f-4c88-b0d1-77ac9f2e1a44",
        "deviceId": 4711,
        "maxBetDeviceId": "1f7c0a64-2b8e-4f3a-9c55-0d1e2f3a4b5c",
        "deviceStickerId": "TRM-0091",
        "identificationType": "IdCard",
        "identification": "A1234567",
        "fee": 1,
        "amount": 5000,
        "location": {
            "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
            "name": "Cash Desk Centar",
            "description": "Main street branch",
            "lat": 44.7866,
            "long": 20.4489,
            "address": "Knez Mihailova 1",
            "stickerId": "SD-1042"
        },
        "currency": "BAM",
        "operatorFirstName": "Ana",
        "operatorLastName": "Ilic",
        "status": "Pending",
        "createdAt": "2026-09-24T11:58:12Z",
        "reference": "MB-REF-99881"
    }
}
POST https://fimb-pts.maxbet.cloud/api/ssbt-deposit/reject HTTP/1.1 


HTTP/1.1 200 OK 

Content-Type: application/json

{
  "statusCode" : 404,
  "message" : "Not Found",
  "traceId" : "00-9f1c7a2b8d3e4f5061728394a5b6c7d8-1a2b3c4d5e6f7081-01"
}
Headers
Authorization
string required

MaxBet API key taken from in Consul. Sent on every outgoing call.

Proxy-Client-IP
string required

Client IP forwarded by the Auth Proxy. Stored on the Pay Persistence and CORE transactions.

Referer
string required

Auth Proxy origin.

X-Requested-With
string required

Always true. Required by the Auth Proxy.

X-UserID
integer required

User identifier in PAM&Wallet. Bound by the controller - never read from the request body.

hash
string required

Signature used to validate request data. Hash is calculated on the concatenated string SHA256(rawRequestBody + Nonce + Secret), lower-case hex.

nonce
string required

Random single-use value generated per request and included in the hash payload. MaxBridge returns the UNIX timestamp in seconds as the response nonce.