Log in
curl --request POST \
--url https://api.4casters.io/user/login \
--header 'Content-Type: application/json' \
--data '
{
"username": "your_username",
"password": "your_password"
}
'import requests
url = "https://api.4casters.io/user/login"
payload = {
"username": "your_username",
"password": "your_password"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({username: 'your_username', password: 'your_password'})
};
fetch('https://api.4casters.io/user/login', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.4casters.io/user/login",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'username' => 'your_username',
'password' => 'your_password'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.4casters.io/user/login"
payload := strings.NewReader("{\n \"username\": \"your_username\",\n \"password\": \"your_password\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.4casters.io/user/login")
.header("Content-Type", "application/json")
.body("{\n \"username\": \"your_username\",\n \"password\": \"your_password\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.4casters.io/user/login")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"username\": \"your_username\",\n \"password\": \"your_password\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"user": {
"id": "<string>",
"username": "<string>",
"type": "free",
"oddsFormat": "american",
"displayBalance": 123,
"creditLimit": 123,
"liability": 123,
"commissionCharged": 123,
"maxLiability": 123,
"matchedVolume": {},
"openInterest": {},
"isAdmin": true,
"hasMarketMakerAccess": true,
"isPro": true,
"isDeposit": true,
"isAlphaUser": true,
"sportsbookDefault": true,
"defaultRotationNumbers": true,
"displayRotationNumbers": true,
"viewOddsWithCommission": true,
"defaultExpiry": 123,
"defaultOffer": 123,
"defaultSendOrderMessage": true,
"sportsbookMinimumDisplay": 123,
"showChatLastMessage": true,
"yesNoSummary": true,
"accessCode": "<string>",
"code": "<string>",
"p2pCode": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"emailConfirmation": true,
"auth": "<string>",
"email": "[email protected]",
"passwordSecurityChecks": {}
}
}
}{
"error": "<string>"
}Getting started
Authentication
Log in and authorize requests
POST
/
user
/
login
Log in
curl --request POST \
--url https://api.4casters.io/user/login \
--header 'Content-Type: application/json' \
--data '
{
"username": "your_username",
"password": "your_password"
}
'import requests
url = "https://api.4casters.io/user/login"
payload = {
"username": "your_username",
"password": "your_password"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({username: 'your_username', password: 'your_password'})
};
fetch('https://api.4casters.io/user/login', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.4casters.io/user/login",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'username' => 'your_username',
'password' => 'your_password'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.4casters.io/user/login"
payload := strings.NewReader("{\n \"username\": \"your_username\",\n \"password\": \"your_password\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.4casters.io/user/login")
.header("Content-Type", "application/json")
.body("{\n \"username\": \"your_username\",\n \"password\": \"your_password\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.4casters.io/user/login")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"username\": \"your_username\",\n \"password\": \"your_password\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"user": {
"id": "<string>",
"username": "<string>",
"type": "free",
"oddsFormat": "american",
"displayBalance": 123,
"creditLimit": 123,
"liability": 123,
"commissionCharged": 123,
"maxLiability": 123,
"matchedVolume": {},
"openInterest": {},
"isAdmin": true,
"hasMarketMakerAccess": true,
"isPro": true,
"isDeposit": true,
"isAlphaUser": true,
"sportsbookDefault": true,
"defaultRotationNumbers": true,
"displayRotationNumbers": true,
"viewOddsWithCommission": true,
"defaultExpiry": 123,
"defaultOffer": 123,
"defaultSendOrderMessage": true,
"sportsbookMinimumDisplay": 123,
"showChatLastMessage": true,
"yesNoSummary": true,
"accessCode": "<string>",
"code": "<string>",
"p2pCode": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"emailConfirmation": true,
"auth": "<string>",
"email": "[email protected]",
"passwordSecurityChecks": {}
}
}
}{
"error": "<string>"
}No API keys. 4casters does not issue API keys yet. Log in with your account’s username and password, exactly as you would on the website, and use the returned token. See the Authentication overview for how the token is used across all three APIs and how to handle its 30-day lifetime.
Log in
POST /user/login
curl -X POST https://api.4casters.io/user/login \
-H "Content-Type: application/json" \
-d '{"username": "your_username", "password": "your_password"}'
{
"username": "your_username",
"password": "your_password"
}
Request
string
required
Account username (or email).
string
required
Account password.
Response
The token is returned both asdata.user.auth and as a signed auth cookie (Set-Cookie). For most server-side integrations you’ll want to capture data.user.auth and discard the cookie.
{
"data": {
"user": {
"id": "5fe37acbb5a23600123662c1",
"username": "your_username",
"auth": "5cd551d6...",
"type": "p2p",
"oddsFormat": "american",
"displayBalance": 1250.50,
"creditLimit": 500,
"liability": -125.00,
"commissionCharged": 0.01,
"hasMarketMakerAccess": false,
"isPro": false,
"createdAt": "2020-12-23T17:14:09.000Z"
}
}
}
User in the OpenAPI schema for every field.
Error responses
| Status | Meaning |
|---|---|
400 | username and password are required. |
401 | Username or password is incorrect. |
403 | Account banned, locked, or closed. |
429 | Login rate-limit exceeded. |
Authorizing requests
Pass the token fromdata.user.auth on every subsequent request. Three header / payload formats are accepted, in this order of preference:
- Authorization header (recommended)
- Cookie
- Body field (POST only)
curl https://api.4casters.io/user/getMe \
-H "Authorization: Bearer 5cd551d6..."
Bearer prefix is optional — passing the bare token also works.The signed
auth cookie set by /user/login is honored automatically on every endpoint when reused on the same client.{ "token": "5cd551d6...", "...": "..." }
401 InvalidCredentials.
Token rotation
Authenticated requests with tokens older than 30 days automatically rotate to a new token. When this happens, the new token is returned in theX-Auth-Token response header (and as an updated signed auth cookie). The old token stops working immediately; the request that triggered the rotation still succeeds, but every later request with the old value returns 401. Long-lived integrations should watch for this header and persist the new value, or simply log in again on any 401.
Logging out
POST /user/logout invalidates the token used to make the call. Subsequent requests with that token return 401; other tokens held for the same account are unaffected.
Two-factor authentication
Two-factor authentication protects withdrawals, not login.POST /user/login never requires a code, regardless of the account’s 2FA setting.Was this page helpful?