Free API

Collapse
X
 
  • Time
  • Show
Clear All
new posts

  • bnl
    replied
    Originally posted by Betfair Developers Program View Post
    Hi,
    @bnl - please contact BDP@betfair.com if you are experiencing different behavior from that described above and we'll investigate further.
    And suddenly I feel so stupid.
    As writing a mail to bdp, and giving examples,
    I discover that the bot also reads the AppKey from a file.

    So it does turn out that I am wrong.
    And that the accounts actually uses one AppKey per account.

    My apologies to all of you that tried to convince me that I was wrong.

    @Neil: since I was wrong, there won't be a mail from me regarding this topic.

    /Björn

    Leave a comment:


  • BetfairDeveloperProgram
    replied
    App Key Rules & Configuration

    Hi,

    I'd just like to clarify how App Keys are configured from Betfair's perspective:
    • When first created via createDeveloperAppKeys both the delayed and live App Keys are associated with a single Betfair account only
    • Users with more than one Betfair account must create a new App Key for each account.
    • App Keys require an account to be subscribed to them by default.
    • If an account isn't subscribed to an App Key and attempts to make a request to API-NG, the error INVALID_APP_KEY will be returned
    • Only licensed vendors can use the Vendor Services API to subscribe additional customers to use their App Key (Application).


    @bnl - please contact BDP@betfair.com if you are experiencing different behavior from that described above and we'll investigate further.

    Thanks

    Neil

    Leave a comment:


  • bnl
    replied
    Yes, I don't think we're in disagreement on this.

    the developer AppKey is linked to the application, but it is also linked to the account.
    I'm sorry but I do disagree here

    For example if I gave one of my own Apps to someone else, they wouldn't be able to use it
    Wrong, this is exactly what I do


    because, although they would be able to log-in to Betfair with it using their BF credentials, API_NG would refuse it access using the SSOID created by their log-in because their account would not be associated with the 'embedded' appKey.
    Hmm, yes perhaps, but why would the application
    use my ssoid, when it is running under my friends account ?


    The only way I could let someone use my App would be for them to generate their own appKey (via the visualiser), and for me to substitue their appKey for my appKey.
    Wrong.

    Somehow I think I have not been clear enough.
    For simplicty say that I have 1 bot.
    That is one (1) executable file into which I have
    compiled the AppKey for this bot.

    Upon start on my machine, it reads user/pwd from a file, say login.ini.

    It logs in (using the interactive method)
    and retrives a ssoid.

    It can now interact with Betfair, ask for markets and
    do betting stuff. In my account.

    Now, my friend, who has a copy of this binary, also starts
    the bot. It reads MY FRIEND'S login.ini and logs in to
    Betfair, using his account. But STILL the same hardcoded AppKey

    His bot will now get ANOTHER ssoid, and can, just as mine,
    interact with betfair.

    Effectively it would be a new application.
    No, it would not. It is THE SAME EXECUTABLE
    RUNNING DIFFERENT ACCOUNTS.

    If I want to allow others to use to use my App without changing the appKey, the only way I can do this is by obtaining Vendor certification from BF.
    No.

    Then I can use the Vendor Account API, and using that I can (idirectly) grant other people's accounts permission to access the api using my appKey as described at: https://api.developer.betfair.com/se...ices+in+API-NG
    Yes indeed, but that is something different

    I'm sorry if I have been unclear, but I've been running
    my own, and a friends account like this since API-ng started up.

    At first I logged in via API6, but the same thing there,
    get the ssoid and be happy. It does run with the same AppKey
    with different betfair accounts. It really does .
    /Björn

    Leave a comment:


  • gus
    replied
    Yes, I don't think we're in disagreement on this.

    Firstly, i think we have to distinguish betweeen 'developer' Apps and 'vendor' Apps.

    So, in discussing 'developer' Apps:

    the developer AppKey is linked to the application, but it is also linked to the account.

    For example if I gave one of my own Apps to someone else, they wouldn't be able to use it because, although they would be able to log-in to Betfair with it using their BF credentials, API_NG would refuse it access using the SSOID created by their log-in because their account would not be associated with the 'embedded' appKey.

    The only way I could let someone use my App would be for them to generate their own appKey (via the visualiser), and for me to substitue their appKey for my appKey.

    Effectively it would be a new application.

    If I want to allow others to use to use my App without changing the appKey, the only way I can do this is by obtaining Vendor certification from BF.

    Then I can use the Vendor Account API, and using that I can (idirectly) grant other people's accounts permission to access the api using my appKey as described at: https://api.developer.betfair.com/se...ices+in+API-NG

    Leave a comment:


  • bnl
    replied
    Unless the bot reads account info from a file
    or provides a login screen...

    I read from file, and trust the os to not reveal it anyone else.

    I do run several accounts like this on one machine.
    But the account owners could run their own set of processes,
    on their own machine, with their username/password.

    Still, it is the same AppKey, since it is the same bot ...
    /Björn

    Leave a comment:


  • gus
    replied
    You can use the app on two different accounts because the accounts are both yours, so you know the Usernames and Passwords, but if you wanted to make your app available to someone else then they wouldn't be able to use it (unless they knew your Username and Password, and were therefore using it on your account).

    Leave a comment:


  • bnl
    replied
    Originally posted by gus View Post
    On bnl's post, as I said the procedure for Vendors, whilst retaining the account/appKey/SSOID relatiship, is different, and quite a bit more complicated. It's decribed here:

    https://api.developer.betfair.com/se...ices+in+API-NG
    and step 3 states

    The Vendor’s web site server then calls the Account API-NG operation getApplicationSubscriptionToken, passing in the Vendor’s app key, a valid session token for the Vendor’s Betfair account (to prove that they own that App Key) and the length of the subscription required (365 days in this scenario).
    That is, the vendor does not re-apply for a new AppKey
    for each new customer account

    /Björn

    Leave a comment:


  • bnl
    replied
    Nope, that's not how it works.
    The developer appKey that you create via the visualiser IS linked to your Betfair account
    ...
    that's why you have to provide a Session Cookie (SSOID) when you are creating an appKey.
    ...
    So you can create any number of apps,
    so long as they all use the same developer appKey that you
    created in the Visualiser, but they can only be used on the account
    that the appKey was created on, unless you change the appKey (in the code, as above).
    So if this is _how it works_ then
    1 - why is it called AppKey ? And not AccountKey?
    2 - why does it indeed work to have a bot running on several Accounts
    in parallel with the AppKey Hardcoded into the app?

    As I said, I've got THE SAME EXECUTABLES running ON THE SAME MACHINE
    with DIFFERENT ACCOUNTS. No problem.

    Because the AppKey and the Account used to log in is all that is needed.
    Then you get a ssoid, and from that moment on,
    the SAME AppKey with an unique ssoid is all that is needed
    to trace you back to the account. The ssoid alone is really enough for that,
    the AppKey states the App. Not the account.

    /Björn

    Leave a comment:


  • gus
    replied
    On bnl's post, as I said the procedure for Vendors, whilst retaining the account/appKey/SSOID relatiship, is different, and quite a bit more complicated. It's decribed here:

    https://api.developer.betfair.com/se...ices+in+API-NG

    Leave a comment:


  • gus
    replied
    Nope, that's not how it works.

    The developer appKey that you create via the visualiser IS linked to your Betfair account ... that's why you have to provide a Session Cookie (SSOID) when you are creating an appKey.

    For example, If I'm helping another person to create an API-NG application, they obviously don't want me to have access to their account, so I would develop the application using my own developer appKey (the same kind that anyone can create using the Visualiser), hardcoded into the app, and then when the app is ready for them to use, they have to create their own developer appKey, with a unique appName, (again using the visualiser).

    They then let me know their appKey, and I replace my appKey in the code with theirs, and then they can use the app on their account.

    I can't use the version that has their appKey (bcause I don't know their Username/Password) and they couldn't use mine.

    So you can create any number of apps, so long as they all use the same developer appKey that you created in the Visualiser, but they can only be used on the account that the appKey was created on, unless you change the appKey (in the code, as above).

    I should emphasize that's the procedure for 'one-off' developer Apps. The procedure for Vendor apps is different and quite a bit more complicated!

    Leave a comment:


  • bnl
    replied
    You would need to generate a live App Key/delayed App Key for account A and another separate live App Key/delayed App Key for account B.
    No, I do not think so. Imagine the Betfair iPhone App.
    Do you _really_ think there is one AppKey for each user that
    downloaded the app? To what purpose?

    From a security point of view, if your Bot is accessing 2 accounts,
    Sorry, I was perhaps not clear enough. My bot(system) is running
    in parallel. One instance is stuck to one account.

    At no time is a single process connected to more that one account.

    However, there are always 6-10 processes connected to
    Betfair per account. They all log in, with the same AppKey,
    and same account, and get a token each, which they use
    and maintain via KeepAlive. But they are all part
    of the same 'Application'
    /Björn

    Leave a comment:


  • betdynamics
    replied
    My understanding...

    The AppKey relates to the application NOT the user.

    There is no need to generate another AppKey for the software to be used by another user. If you have two Betfair accounts, then you should be able to use the app using the same AppKey.

    If you have two Betair accounts, you can generate different AppKeys per account, but they should be used for different applications.

    Leave a comment:


  • smilerdude
    replied
    You're correct that the App Key and Account is a unique combination.

    On the API NG documentation page about Application Keys, the very first paragraph at the top of the page:

    Application Keys

    Added by Mark Levitt, last edited by Neil Thomas on May 13, 2014 (view change)
    Go to start of metadata


    In order to use the Betting API, you need to have an Application Key. The Application Key identifies your API client. Two App Keys are assigned to a single Betfair account, one live App Key and one delayed App Key.
    This would mean if you have 2 Betfair accounts, e.g. Account A and Account B.

    You would need to generate a live App Key/delayed App Key for account A and another separate live App Key/delayed App Key for account B.


    I was also going into the realms of session/connection management which the Session Tokens form part of. Yes Betfair generate the session tokens, the bot uses that unique session token for 20 minutes, before your Bot needs to request another one via the KeepAlive method call.

    From a security point of view, if your Bot is accessing 2 accounts, Betfair generates a session token for the connection/calls to Account A and generates another unique Session Token for the connection/calls to Account B. If Betfair isn't doing this, I would be very surprised. Hence my pseudo code for session/connection House Keeping when you're Bot connects to 2 accounts.

    I don't have 2 betfair accounts, so I could be wrong if this case, my bad.

    I'm just using my experience of developing Server/Client programs for the Banking/Electricity industries and having to read/understand detailed (sometimes vague) industry technical API documents for interfaces and message formats.
    Last edited by smilerdude; 28-05-2014, 12:22 PM.

    Leave a comment:


  • bnl
    replied
    4) If you have 2 Betfair accounts, you will need to generate a separate App Key for each account. Bots accessing each account will need to have the Session tokens to be associated correctly with the correct App Key.
    Why? Where did you read this?
    I'd say that the combination AppKey and Account is unique.
    The token is generated by Betfair and surely they can
    trace back the account a certain token was associated with.

    But it would be nice with a Betfair comment on intended use
    /Björn

    Leave a comment:


  • smilerdude
    replied
    This is my very simplistic understanding of App Keys from my developing of my bot and reading the documentation.

    If you are developing own Bot.

    1) For a bot to gain access to the API, it needs to be associated with a valid Betfair account, hence the App Key generation and the need to upload that App Key to Betfair.

    2) The App Key is sent in every request to the API along with a current valid session token.

    3) You can have many Bots as you want accessing a single Betfair account, as long as they pass the App Key with a valid session token.

    Note about session tokens, some markets require session token to be updated every 15 minutes, e.g. Italian Football markets. At the moment for most markets, the session token only needs to be updated every 24 hours. This generic time period can be altered without warning in future.

    Best practice is to run the Keep Alive call every 10-15 minutes to acquire a valid session token that can sent for any specific market calls.

    4) If you have 2 Betfair accounts, you will need to generate a separate App Key for each account. Bots accessing each account will need to have the Session tokens to be associated correctly with the correct App Key.

    I deal with this by creating a Shared Memory object which is populated at startup with data from a database. Each bot accesses the Shared Memory to update or get the requested session token and app key before each request to the API is sent


    Pseudo Code

    Code:
    class Acnt_Details {
        private int _default_int = -1;
        private int _id = _default_int;
        private string _username = "";
        private string _app_key = "";
        private string _delayed_app_key = "";
        private string _session_token = "";
    
        setSessionToken(string token) { _session_token = token; }
        
        string getSessionToken() { return (!isEmpty(_session_token)) ? _session_token : ""; }
        
        string getAppKey() { return (!isEmpty(_app_key)) ? _app_key : ""; }
    }
    
    class ShMem_Acnt_Details {
        private int _default_int = -1;
        private int _nbr_of_loaded_acnts = _default_int;
        private List _acnts <int, Acnt_Details>;
    
        int addAcntToShMem(Acnt_Details acnt) {
            int success = _default_int;
            try {
                ++_nbr_of_loaded_acnts;
                _acnts.add(acnt);
                success = 1;
            }
            catch exceptions {...}
    
            return success;
        }
    
        int updateAcntSessionToken(string app_key, string token) {
            int success = _default_int;
    
            try {
                if ((_nbr_of_loaded_acnts > _default_int) &&
                    (isString(app_key) && isString(token))) {
                    
                     foreach (acnt in _acnts) {
                        if (acnt.getAppKey() == app_key) {
                            acnt.setSessionToken(token);
                            success = 1;
                        }
                    }
                }
            }
            catch exceptions{...}
    
            return success;
        }
    }

    If you are needing information about Subscriber App Key, this is very specific for those people who are intending to be a Vendor, i.e sell their bots.

    If your are going down this route, then I can explain further.
    Last edited by smilerdude; 27-05-2014, 11:12 PM.

    Leave a comment:

Working...
X