Use your client API key to pull sports odds, casino tables, score cards, and the custom Live TV player.
Base URL: https://api.mahakalexchange.cloud
API key is secret. Use it only from your backend (or secure server code) — never put it in frontend HTML, JS, or iframe URLs. Anyone can copy a key from DevTools.
/v1/sports, odds, casino data): header X-Api-Key: YOUR_KEY onlycurl -H "X-Api-Key: mk_xxx" https://api.mahakalexchange.cloud/v1/sports
Your package controls sports/casino feeds, media toggles, TV domains, IP allow list, expiry and hit limits.
Every request made with your key (or from your whitelisted media domain) counts as 1 hit. Your package may have a monthly and/or daily hit limit. When a limit is reached the API returns HTTP 429 with a message until the period resets (daily at 00:00 IST, monthly on the 1st). Cache responses on your server and poll sensibly (e.g. casino data every 1–3 s, odds every 1–2 s) to stay within your plan.
HTTP/1.1 429
{"success": false, "message": "Monthly hit limit reached (1000000/1000000). Contact Mahakal Exchange to upgrade."}
| Method | Path | Notes |
|---|---|---|
| GET | /v1/sports | Sport catalogue (filtered to your package) |
| GET | /v1/tree | Competition / event tree |
| GET | /v1/odds?gmid=&sid= | Market odds for an event. sid defaults to 4 (Cricket) |
| GET | /v1/allSportid | All sport ids (Diamond-style path) |
| GET | /v1/esid?sid= | Live + upcoming matches for one sport |
| GET | /v1/getPriveteData?gmid=&sid= | Match odds, bookmaker and fancy for one match (Diamond-style path) |
GET /v1/odds?gmid=787327544&sid=4 Header: X-Api-Key: mk_xxx
| Method | Path | Notes |
|---|---|---|
| GET | /v1/casino/tables | Tables available to your package |
| GET | /v1/casino/data?type= | Live runners / round for a table type (e.g. teen20) |
| GET | /v1/casino/tableid | Casino table ids (Diamond-style path) |
| GET | /v1/casino/result?type= | Recent results for a table (see Results) |
| GET | /v1/casino/detail_result?type=&mid= | Full result of one round (see Results) |
| GET | /v1/score?gmid= | Score iframe — domain whitelist only. Uses gmid (match event id). |
| GET | /v1/casino/tv?type= | Casino Live TV iframe — domain whitelist only, no API key |
GET /v1/casino/data?type=teen20 Header: X-Api-Key: mk_xxx
<iframe src="https://api.mahakalexchange.cloud/v1/casino/tv?type=teen20" style="width:100%;height:360px;border:0;background:#000" allow="autoplay; fullscreen"></iframe>
Works only when the page domain is in your TV domain whitelist and Casino Live TV is ON.
All result endpoints need the X-Api-Key header (server-side only).
| Method | Path | Notes |
|---|---|---|
| GET | /v1/casino/result?type= | Last results of a table: data.results[] with round id and winner win. Use it for the result strip under the game. |
| GET | /v1/casino/detail_result?type=&mid= | Full detail of one round (cards, winner, sub-results). Pass the round id from /v1/casino/result as mid. |
GET /v1/casino/result?type=teen20
Header: X-Api-Key: mk_xxx
{"success": true, "data": {"results": [{"id": "102261010152039", "win": "2"}, ...]}}
GET /v1/casino/detail_result?type=teen20&mid=102261010152039
Header: X-Api-Key: mk_xxx
Settle casino bets when a round's id appears in /v1/casino/result, using the winner from detail_result.
detail_result always returns the official winner (win). If the response has "source": "snapshot", the cards were recorded from the live table; cards is empty when the full deal was not captured.
{"success": true, "data": {"available": true, "win": "1", "cards": "9SS,QHH,2SS,3DD,9DD,10CC", "source": "snapshot"}}
| Method | Path | Notes |
|---|---|---|
| POST | /v1/placed_bets | Register a market your users bet on, so the provider tracks its result. Call once per market when the first bet is placed. |
| POST | /v1/get-result | Result of one market (match odds, bookmaker or fancy). Poll until declared. |
| GET | /v1/get_placed_bets?event_id= | Results of all registered markets for an event |
Body for placed_bets and get-result (JSON, Content-Type: application/json):
POST /v1/get-result
Header: X-Api-Key: mk_xxx
Content-Type: application/json
{
"event_id": 787327544,
"event_name": "India v Australia",
"market_id": 123456789,
"market_name": "Match Odds",
"market_type": "MATCH_ODDS",
"sport_id": 4
}
market_type: MATCH_ODDS, BOOKMAKER or FANCY. sport_id is optional for get-result; placed_bets needs event_id, event_name, market_id, market_name, market_type. Ids come from /v1/odds / /v1/getPriveteData.
GET /v1/get_placed_bets?event_id=787327544 Header: X-Api-Key: mk_xxx
Media embeds are domain-based — no API key in the iframe. Turn Match TV / Score / Casino TV ON in admin and add the client website to TV domain whitelist.
GET /v1/tv?event_id=EVENT_ID
Requires matchTv + whitelisted domain. Same iframe URL as before — we serve the player HTML here (no API key).
GET /v1/score?gmid=EVENT_ID
Requires score + whitelisted domain.
GET /v1/casino/tv?type=teen20
Requires casinoTv + whitelisted domain.
<iframe src="https://api.mahakalexchange.cloud/v1/tv?event_id=787327544" allow="autoplay; fullscreen; encrypted-media" style="width:100%;height:360px;border:0;background:#000" ></iframe> <iframe src="https://api.mahakalexchange.cloud/v1/score?gmid=787327544" style="width:100%;height:120px;border:0" ></iframe> <iframe src="https://api.mahakalexchange.cloud/v1/casino/tv?type=teen20" style="width:100%;height:360px;border:0;background:#000" ></iframe>
Keep the API key on your server for odds/casino JSON. Never paste ?key= into frontend code.
Whitelist any host: production domain (wiin11.com), localhost, 127.0.0.1, or localhost:3000 — must be listed in admin before embeds work.
401 — missing / invalid / inactive key403 — package restriction (sports/casino/sport id/table/IP/domain/expiry)400 — missing required params (gmid, type, event_id)Health (no key): GET /health and GET /v1/health?key=…
{ "success": false, "message": "Sport not in package" }
/v1/sports with X-Api-Key from your backend.gmid, poll /v1/odds for prices (server-side key)./v1/score and /v1/tv iframes without a key (domain must be whitelisted)./v1/casino/tv?type= with no key.const KEY = "mk_xxx";
const base = "https://api.mahakalexchange.cloud/v1";
const sports = await fetch(base + "/sports", {
headers: { "X-Api-Key": KEY }
}).then(r => r.json());
const odds = await fetch(base + `/odds?gmid=${gmid}&sid=4`, {
headers: { "X-Api-Key": KEY }
}).then(r => r.json());
Need a key? Contact Mahakal Exchange — keys are issued from the API admin panel with sports/casino package checklists.