Developers
Everything the browser does, you can script
The arena, daily challenge, duels, market and explorer all run on one JSON API. Interactive docs: /api/docs, schema: /api/openapi.json. Authenticate with Authorization: Bearer fist_…. API-key calls need no cookies or CSRF header.
Your API keys
Play once (no signup) to get an account, then create keys here.
Go to the arenaYour bots
Play once to create bots.
Copy this key now. It won't be shown again:
Endpoints
| Method | Path | What |
|---|---|---|
| GET | /api/me | your account, balance, entry options, active run |
| POST | /api/runs | start a house run ({"entry": "auto|fee|free|burn", "client_seed"}) |
| POST | /api/runs/{id}/throw | {"move": "rock|paper|scissors"} → outcome + revealed seed |
| POST | /api/runs/{id}/continue · /claim | risk it or bank the tier |
| GET | /api/runs/{id}/proof | commits + seeds, feed it to verify_fist.py |
| POST | /api/arena/queue | bots: join the ranked queue (poll until matched) |
| POST | /api/duels/spar | instant practice duel vs SparringBot |
| GET | /api/duels/{id} | duel state; also applies passed deadlines |
| POST | /api/duels/{id}/commit · /reveal | {"commitment"} then {"move", "salt"} |
| GET | /api/market · POST /api/market/list | listings, floors, reference prices; list a token |
| GET | /api/portfolio | holdings, valuation, 30-day history, risk stats |
| GET | /api/leaderboard?board=all|week|daily|teams|duels|bots | every ladder |
| GET | /api/chain/blocks · /tx/{hash} · /verify | the FistChain explorer, raw |
curl
KEY=fist_...
curl -s -H "Authorization: Bearer $KEY" https://www.playfist.app/api/me
curl -s -X POST -H "Authorization: Bearer $KEY" \
-H 'Content-Type: application/json' -d '{}' https://www.playfist.app/api/runs
Limits & rules
- 240 requests/min per IP; a 250 ms minimum between throws.
- Up to 5 keys per account; up to 3 bots per player.
- Everything is virtual $FIST with no cash value. There's nothing to farm.
- We never execute submitted code. Your bot is your process.