Multi-operator platform
A platform connects several operators to Luxorr. Each operator’s gifts, orders and players stay separate.
One key per operator
Section titled “One key per operator”Each operator is its own tenant, and the platform holds one key per tenant. A key reaches only its own tenant’s data. No key spans operators.
| Operator | Luxorr tenant | Key |
|---|---|---|
| Operator A | Operator A | lxr_live_9fQ2… |
| Operator B | Operator B | lxr_live_Tm7c… |
Luxorr creates a tenant for each operator and issues the key to the platform or to the operator’s Administrator. Approval rules, brands, currency and campaigns are set per operator.
Routing
Section titled “Routing”Store each key with its operator, encrypted, and select it per request:
async function placeOrderFor(operatorId, order, idempotencyKey) { const key = await secrets.luxorrKeyFor(operatorId) return fetch(`${LUXORR_API}/orders`, { method: 'POST', headers: { Authorization: `Bearer ${key}`, 'Content-Type': 'application/json', 'Idempotency-Key': idempotencyKey, }, body: JSON.stringify(order), })}- Check the key with
GET /mewhen you store it.tenant.idandtenant.namemust match the operator. - Read settings per key.
locales,currency,approvalRequired,customFieldsandwebhookUrldiffer by operator. Do not reuse one operator’s custom field IDs or currency for another.
externalOrderIdis unique within one tenant. Two operators can use the same value.- A Luxorr ID from one tenant answers
404 not_foundwith another tenant’s key. Do not share cached IDs between operators. - Rate limits apply per key.
Webhooks
Section titled “Webhooks”Set a webhook URL on each key. Use one URL per operator, such as https://hooks.platform.example/luxorr/operator-a, or one shared URL.
Each key has its own webhook secret. A valid signature identifies the operator. data contains Luxorr IDs and your externalOrderId.
Adding an operator
Section titled “Adding an operator”- Send Luxorr the operator name, brands, delivery countries and approval setting.
- Luxorr creates the tenant, switches on API access and issues a sandbox key.
- Integrate in the sandbox, then receive a production key.
See onboarding.