API archive entry · source-reported

Sessions API

The William Hill Sessions API uses a central authentication service (CAS*) on all resources that require access to a customer’s account or betting functionality. To authenticate, you’ll need to supply a sportsbook username and password, in return you will be given an authentication ticket, which you can use on the majority of requests found within our services. The Sessions API should be used whenever you want to login a customer and: continue to use the William Hill API for that customer’s transactions use other CAS-enabled William Hill services outside the suite of APIs CAS is an enterprise Single Sign-On solution for web services (see https://wiki.jasig.org/display/CAS/Home). It is used by many William Hill services. Note: all requests must be executed over HTTPS and include an API key and secret. Authentication Ticket Expiration Times When a customer is logged in using the Sessions API, they are given an Authentication Ticket; using this ticket on subsequent API requests gives you access to account activities (such as placing a bet, deposits, etc). However, this ticket is only valid for a given period of time depending on how it is used. If the ticket is used and then has a per

Provider / source website

Plan the first integration safely

The access fields below come from the connected directory. Their likely implementation impact is explained without assuming provider-specific behavior.

Authentication

OAuth is reported. Confirm flows, scopes, consent, token lifetime, and refresh rules.

Transport

HTTPS is not confirmed. Do not send credentials or production data until secure transport is verified.

Browser access

CORS is unknown. Treat direct browser access as unconfirmed and test before choosing a client-only architecture.

First-request sequence

  1. Identify the current base URL, version, and endpoint for the use case.
  2. Confirm how credentials are issued and where they may be stored.
  3. Test success, invalid input, throttling, unavailable data, and timeouts.
  4. Record response fields, pagination, caching, and error shapes.
  5. Add monitoring, retries with backoff, and an appropriate fallback.

Questions to resolve before production

Pricing and quotas

Confirm current plans, free-tier limits, overages, and request ceilings.

Endpoint coverage

Check that the operations and response fields match the intended workload.

Reliability

Look for uptime history, a status page, support routes, and service commitments.

Data and privacy

Review retention, licensing, regional processing, and compliance requirements.

Versioning

Confirm the active version, change policy, deprecation window, and migration guidance.

Developer experience

Validate SDKs, examples, error formats, pagination, and test environments.

Source reference

APIs.guru OpenAPI Directory

This page separates source-reported facts from questions that need live provider verification.