# API Overview

DailyPlay provides an API that allows **third-party applications** to programmatically create
one-time game sessions for their users. This is ideal for CRMs, marketing platforms, e-commerce
systems, and any application that wants to offer DailyPlay games to its end users in a controlled
way.

:::note[Business Tier Required]
The API feature is only available for organizations on the
**Business tier** or higher.
:::

:::caution[Enable "Require API Session Token"]
For session tokens to take effect, you must enable
the **"Require API Session Token"** setting on each game or stream in the **Configuration** tab.
Without this setting enabled, games will be playable without any token restrictions.
:::

## How It Works

The integration flow follows a simple pattern:

1. **Your server** creates a one-time session token using your API key
2. **Your app** redirects the end user to the game URL with the token
3. **DailyPlay** validates and consumes the token — the user plays once
4. The token is single-use and cannot be replayed

```
Your App                          DailyPlay
────────                          ─────────
   │
   │  1. Create session (x-api-key)
   ├─────────────────────────────────►  POST /api/org-api-keys/sessions
   │                                        │
   │  2. Receive one-time token             │
   ◄────────────────────────────────────────┘
   │
   │  3. Redirect user with token
   ├─────────────────────────────────►  Player opens game URL
   │                                    with ?session_token=<token>
   │
   │                                   4. Token validated & consumed
   │                                   5. User plays the game
   │                                   6. Token cannot be reused
```

## Key Concepts

### API Keys

API keys authenticate your server when calling the DailyPlay API. Each key:

- Belongs to an organization
- Can be scoped to specific games or streams
- Has configurable rate limits
- Can be revoked instantly

See [API Keys](/api/api-keys/) for setup and management details.

### Session Tokens

Session tokens are one-time-use tokens that grant a single play. They:

- Are created via your API key
- Expire after a configurable duration (default: 24 hours)
- Can only be consumed once
- Carry optional metadata for tracking

See [Session Tokens](/api/session-tokens/) for the full lifecycle and API reference.

## Use Cases

- **E-commerce**: Reward customers with a game play after purchase
- **CRM campaigns**: Send personalized game links to segmented audiences
- **Loyalty programs**: Grant a daily game play to loyalty members
- **Event marketing**: Distribute one-time game access at events or via QR codes

## Quick Example

```bash
# 1. Create a session token from your server
curl -X POST https://app.dailyplay.ai/api/org-api-keys?action=create-session \
  -H "Content-Type: application/json" \
  -H "x-api-key: dpk_YOUR_API_KEY" \
  -d '{
    "game_id": 42,
    "external_ref": "user-12345",
    "expires_in_minutes": 60
  }'

# Response:
# {
#   "success": true,
#   "data": {
#     "token": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
#     "game_id": 42,
#     "expires_at": "2026-02-17T12:00:00.000Z"
#   }
# }

# 2. Redirect the user to:
# Game Page in DailyPlay
# https://app.dailyplay.ai/game/42?session_token=a1b2c3d4-e5f6-7890-abcd-ef1234567890
#
# Iframe friendly game page with no DailyPlay UI
# https://app.dailyplay.ai/embed/42?session_token=a1b2c3d4-e5f6-7890-abcd-ef1234567890
#
# Stream Page
# https://app.dailyplay.ai/stream/<org-slug>/<stream_id>?session_token=a1b2c3d4-e5f6-7890-abcd-ef1234567890
```

## MCP for AI Agents

The same API keys can power a remote **MCP server** so agents in Cursor, Claude, and other clients
can create games, manage streams, generate assets, manage gallery media and vouchers, read reports,
and mint sessions. Enable MCP scopes on the key, then point your client at
`https://app.dailyplay.ai/api/mcp`.

See [MCP Server](/api/mcp/) and the [MCP Tools Reference](/api/mcp-tools/).

For the same capabilities inside the dashboard (no API key required), see the
[in-app Assistant](/assistant/overview/).

## Next Steps

- [Create an API Key](/api/api-keys/) from the DailyPlay dashboard
- [Learn the session token lifecycle](/api/session-tokens/)
- [Connect an AI agent via MCP](/api/mcp/)
- [Use the in-app Assistant](/assistant/overview/)
- [Browse the API reference](/api/reference/)