Open WebSocket connection
curl --request GET \
--url https://api.skinshark.gg/ws \
--header 'api-key: <api-key>'import requests
url = "https://api.skinshark.gg/ws"
headers = {"api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'api-key': '<api-key>'}};
fetch('https://api.skinshark.gg/ws', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.skinshark.gg/ws",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.skinshark.gg/ws"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.skinshark.gg/ws")
.header("api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.skinshark.gg/ws")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"event": "connected",
"data": {
"userId": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"ts": 123
}WebSocket
Open WebSocket connection
Auth context: sub-user — token from POST /auth/ws-token.
Open with wss://api.skinshark.gg/ws?token=<wsToken>. The token is
verified at upgrade; on failure the server closes with code 4001 Invalid token.
Protocol
- Read-only. Any client → server frame closes the socket with code
4002 Read-only. - Heartbeat. The server sends WS pings; respond with pongs to keep the connection alive (handled automatically by most clients).
- First frame. Immediately after upgrade, the server sends
WsConnectedEventwith the resolveduserId. - Subsequent frames. All push events conform to
WsEvent— a discriminated union keyed by the top-leveleventfield.
Close codes
| Code | Reason | Cause |
|---|---|---|
| 4001 | Missing token | No ?token= query string |
| 4001 | Invalid token | Bad signature, expired, or wrong purpose |
| 4002 | Read-only | Client sent any frame after upgrade |
Events
Each frame has the shape { event, data, ts } where ts is Unix epoch
ms. See the WsEvent schema below for the full union — the deposit
events differ between gateway-hosted (gatepay/onramp) and self-hosted
crypto deposits even though they share event names.
GET
/
ws
Open WebSocket connection
curl --request GET \
--url https://api.skinshark.gg/ws \
--header 'api-key: <api-key>'import requests
url = "https://api.skinshark.gg/ws"
headers = {"api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'api-key': '<api-key>'}};
fetch('https://api.skinshark.gg/ws', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.skinshark.gg/ws",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.skinshark.gg/ws"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.skinshark.gg/ws")
.header("api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.skinshark.gg/ws")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"event": "connected",
"data": {
"userId": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"ts": 123
}Authorizations
Your raw API key. Generate, rotate, and revoke keys from the merchant
dashboard. Keys can optionally be bound to one or more allowed source
IPs — requests from any other IP are rejected with API_KEY_IP_DENIED.
Query Parameters
Minimum string length:
1Response
Switching Protocols — WebSocket handshake completed.