Skip to main content
The 4casters REST API lets you log in, query games and the orderbook, place / edit / cancel orders, and read your bet history programmatically. It is the same API that powers the 4casters web app.

Base URL

All endpoints in this section are rooted at:

Conventions

  • Transport: HTTPS only.
  • Encoding: JSON. Send Content-Type: application/json on every request that has a body.
  • Response envelope: With a couple of well-marked exceptions (/affiliate/getAffiliateCommission, /exchange/getOddsForAveragePrice), every successful response is wrapped: { "data": <payload> }.
  • Identifiers: Game ids, participant ids, and order ids are MongoDB ObjectID strings (24-character hex).
  • Odds: All odds are American format (negative for favorites, positive for underdogs) unless noted otherwise.
  • Time: All timestamps are ISO 8601 with Z (UTC).

Authentication

Almost every endpoint requires authentication. Log in once via POST /user/login, then send the returned auth token on every request — see Authentication for details.

Per-order errors vs HTTP errors

The “place” and “edit” endpoints accept batches and return per-order results. A successful HTTP 200 response can still contain individual order failures inside data.createdSessions[i]. See the per-order error shape on each endpoint page. HTTP-level errors (4xx, 5xx) are returned as { "error": "<message>" }.

Rate limiting

Three layers of rate limiting apply:
  • Global, per IP — every request to the API counts against a per-IP budget of 3,000 requests per rolling 60-second window (a sustained ~50 requests/second). Exceeding it returns 429 with a Retry-After header (seconds) and body { "error": "Too many requests. Please try again later." }.
  • Authentication routes (/user/login, password reset, signup) have additional per-IP and per-account throttling.
  • Place / edit / cancel routes are additionally rate-limited per account.
Read endpoints have no per-account limit — only the global per-IP ceiling applies.

Timeouts

Requests that take longer than 15 seconds server-side are aborted and return 503 with body { "error": { "message": "Network Error", "code": 503 } }.

Real-time updates

The REST API pairs with the WebSocket Streaming API for real-time orderbook ticks and per-account fill / settle events. The auth token returned by /user/login works for both.

Endpoint index

Authentication

Log in and obtain an auth token.

User

Account info, balance, bets, and orders.

Orders

Place, edit, look up, and cancel orders.

Markets

Browse leagues, games, participants, and the orderbook.

Affiliate

Affiliate commission.

Legacy Postman collection

The previous documentation lived as a Postman collection. It is preserved for reference, but these Mintlify docs are now the source of truth — the Postman collection may lag behind for new endpoints, parameters, or response shapes.

4Casters API — Postman collection

View the legacy Postman documentation