Add mystery packs to your platform. List tiers and their published odds, sell a pack, reveal the pull, then let the user cash out instantly or ship the card to their door, all against real graded inventory priced by the Card Data API. Every action is attributed to your partner key.
The Gacha API is rip.fun's own pack business exposed as an API. You design the packs and bring the players; rip.fun owns the cards, runs the reveal, funds the buyback and ships the physical card when a player asks for it. You earn a share of the net revenue you generate.
average_item_value are inventory-derived rather than a synthetic table, and
why a pull is priced against the same market data the Card Data API serves.Prepare the transactions, the end-user sends them from their own wallet, and you record the hash. You poll for the reveal — no funds to hold and no chain awareness beyond passing calldata through.
// 1. Show the packs you're selling
const { data } = await cardos.gacha.catalog.list({ game: 'pokemon' });
// 2. Hand the transactions to the user's wallet
const { data: prep } = await cardos.gacha.purchase.prepare({
wallet_address: userWallet,
tier_id: data.tiers[0].tier_id
});
const txHash = await userWallet.sendCalls(prep.calls);
// 3. Record it, then poll (or take the purchase.fulfilled webhook)
const purchase = await cardos.gacha.purchase.submit({ transaction_hash: txHash }); That is the whole integration for a working gacha loop. Everything below is the surface you grow into: buyback, physical redemption, and your revenue share.
| Environment | Origin | Notes |
|---|---|---|
| Sandbox (staging) | https://staging-service.rip.fun | Base Sepolia, which is what the "Try it" runners in these docs call |
| Production | https://api.getcardos.com | Base mainnet. Alias of https://service.rip.fun — both origins serve the
same API; older examples use the rip.fun name and either works. |
All endpoints live under the /api/v1 base path and require an X-API-Key.
_micros (or named price/amount/balance bare) are integer USDC micros as strings — "12500000" = 12.5 USDC. Fields
suffixed _usdc are the same value as a decimal string for display. Reveal
items' value_usd is a USD decimal string from market pricing (not micros).
Never parse any of them into a float you do arithmetic on.tier_id, purchase_id and other row ids are
JSON numbers (integers). token_id, request_id and card_id are strings. If any docs page shows tier_id quoted,
that's a docs bug — the wire type is a number.Prefer codegen? The full surface is published as an OpenAPI spec: gacha-openapi.yaml.
The Gacha API is limited to 240 requests per minute per key — a separate,
lower ceiling than the Card Data API's 300/min. On top of the per-minute 429,
the server bounds concurrent in-flight requests with global semaphores shared with
the Instant Pack API — 24 reads, 5 purchases, 10 writes, 10 wallet reads. A short burst
beyond those queues briefly (up to ~500ms) for a free slot; only a sustained overload sheds
with a 503 and Retry-After: 1. Size your client for sequential
calls with modest parallelism and honor Retry-After on both statuses.
Self-custody (default). The end-user holds their own funds and their own cards. The API returns the transactions to send (prepare), the end-user sends them from their own wallet, and you record the transaction (submit). CardOS never takes custody of either — which is also why only the card's own holder can sell it back.
Custodial. If your users don't have wallets, fund a per-user CardOS credits
wallet (deposit, then balance) and open packs server-side
with a single POST /mystery/purchase —
no signing, no browser wallet, one idempotent call per pull. The pulled cards are minted to a
CardOS-managed wallet keyed to your external_user_id.
Partner accounts settle on the TIER model: you sell rip.fun tiers, and
sell-backs and revenue share settle through /sellback, /revenue and /payouts — you earn a share of net revenue, paid in USDC, and are never billed
per item. (A legacy POOL model exists for a few grandfathered partners who
hold their own inventory; it is not offered to new partners, and its endpoints answer 403 not_pool_partner/not_tier_partner across models. Which model
your key is on is returned by GET /api/v1/info as mystery_partner.billing_model.)
Every endpoint page embeds a live runner: tweak the request inputs, press Run, and see
the real staging response (status + latency), plus a ready-to-copy curl snippet
that tracks your inputs. The partner API key stays on this demo's server, and the browser only
ever talks to a whitelisted proxy.
To see the whole product (connect a wallet, buy a pack, reveal the card, sell it back or redeem it physically) open the storefront demo.
FULFILLED, then show the
revealed items.The three multi-party sequences (who signs what, which webhooks fire) are spelled out in End-to-end flows.
To run the sandbox flows (buy a pack, sell it back, redeem it) your test wallet needs a little
Base Sepolia ETH for gas plus USDC to pay for packs. Staging's payment token is Circle's native
Base Sepolia USDC at 0x036CbD53842c5426634e7929541eC2318f3dCF7e, the same token
Circle's faucet dispenses.
Tier 1 on staging costs $1 USDC, so a single Circle claim covers ~20 test purchases.
The catalog above is the standard inventory. RIP.FUN will also buy and grade to your brief, be
that a chase list you pick, sealed product for a launch, or a one-off drop, and hold it all in
our own vault, insured until the day it ships. Contact us →