Skip to content
Luís Gustavo edited this page Jun 30, 2018 · 96 revisions

Registration

To register to become developer, go here to register.

If your application is accepted you will receive custom credentials to access the API.


Credentials

To access the API you'll need your own set of credentials which consist of a developer id (devId) and an authentication key (authKey). The process of obtaining credentials should be a one-time activity.

Here are the credentials for a sample account:

DevId AuthKey
1004 23DF3C7E9BD14D84BF892AD206B6755C

Use your personal credentials to access the api via a Representational State Transfer (REST) web service hosted at http://api.realmroyale.com.

Note that the same DevId/AuthKey combination should work for SmiteAPI, PaladinsAPI and RealmRoyaleAPI, across all supported platforms.


Sessions

To begin using the API, you will first need to establish a valid Session.

To do so you will start a session (via the CreateSession method) and receive a Session. Sessions are used for authentication, security, monitoring, and throttling.

Once you obtain a Session, you will pass it to other methods for authentication.

Each session only lasts for 15 minutes and must be recreated afterward.


Signature

A MD5 hash of (devID + method + authKey + timestamp)

Actually the authKey isn't passed directly, but instead embedded and hashed in another parameter (signature).

It's a combination of devID, authKey, method (without the response format), and the Timestamp.

C# Sample:
private static string GetMD5Hash (string input) {
	using (var md5 = System.Security.Cryptography.MD5.Create ()) {
		var bytes = md5.ComputeHash (System.Text.Encoding.UTF8.GetBytes (input));
		var stringBuilder = new System.Text.StringBuilder ();
		foreach (byte b in bytes)
			stringBuilder.Append (b.ToString ("x2").ToLower ());
		return stringBuilder.ToString ();
	}
}
public string generateSignature (devId, method, authKey, timestamp) {
	return GetMD5Hash (devKey + method + authKey + timestamp);
}
var signature = generateSignature (1004, 'createsession', '23DF3C7E9BD14D84BF892AD206B6755C', getTimeStamp ());
Javascript Sample:
const md5 = require ('md5');
function generateSignature (devId, method, authKey, timestamp) {
	return md5 (`${devId}${method}${apiKey}${timestamp}`);
}
var signature = generateSignature (1004, 'createsession', '23DF3C7E9BD14D84BF892AD206B6755C', getTimeStamp ());
Python Sample:
from hashlib import md5 as getMD5Hash
def __encode__ (_input, encodeType: str = "utf-8"):
	return str (_input).encode (encodeType)
def generateSignature (devId, method, authKey, timestamp):
	return getMD5Hash (__encode__ (devId) + __encode__ (method) + __encode__ (authKey) + __encode__ (timestamp)).hexdigest ()
signature = generateSignature (1004, 'createsession', '23DF3C7E9BD14D84BF892AD206B6755C', getTimeStamp ());

Timestamp

The current UTC timestamp formatted to 'YYYYMMDDHHmmss'.

C# Sample:
public static string getTimeStamp (string format = "yyyyMMddHHmmss") {
	return System.DateTime.UtcNow.ToString (format); 
}
var timestamp = getTimeStamp ();
Javascript Sample:
const moment = require ('moment');
function getTimeStamp () {
	return moment.utc ().format ('YYYYMMDDHHmmss');
}
var timestamp = getTimeStamp ();
Python Sample:
def getTimeStamp (format = "%Y%m%d%H%M%S"):
	from datetime import datetime
	return datetime.utcnow ().strftime (format)
timeStamp = getTimeStamp ()

API Access Limits

To throttle API Developer access various limits have been setup to prevent over use of the API (either intentional, more likely unintentional “over use”).

Here are the default initial limitations for API Developers:

Concurrent Sessions Daily Sessions Session Time Daily Request
50 500 15 minutes 7500

Platform Endpoint Base URLs

To retrieve all information from the Realm Royale API, you will need to append all requests to the Realm Royale API endpoint, and all requests must begin with the method you're wanting to access concatenated with the response type you're wanting.

PC PS4 XBOX
http://api.realmroyale.com/realmapi.svc No yet No yet

Ret_msg

Except when using the CreateSession method, the ret_msg will not be null when you catch an error.

Message Error Description
Approved When you got a Session (session_id)
Error while comparing Server and Client timestamp
Exception - Timestamp
Failed to validate DeveloperId
Invalid date format
Exception - Timestamp Your signature: {signature} Your timestamp: {timestamp} Your session ID: {session_id}
Unauthorized Developer Id
Invalid signature
No Match Details:{match_id}
Maximum number of active sessions reached You've 25 Sessions active actually
Exception while validating developer access You've submit a wrong devID and/or authKey
Invalid session id You've an invalid or "died" session_id
Or if the ret_msg is containing: dailylimit (7500 requests reached) / 404 ""