Developer API
REST API /v1: WN8, player history, tank statistics, marks of excellence thresholds, clans and sessions. Data source: Lesta Games.
Quick start
A key, the SDK and one request. Responses are JSON, errors carry a machine-readable code.
Create a key
Sign in and create a key in the developer dashboard. The secret is shown once.
Install the SDK
bun add @otmetki/sdk— types, retries and webhook verification. From any other language, send theX-API-Keyheader.Send a request
A nickname or an account id returns a summary with WN8, EFF, Броня-Индекс and recent periods.
https://api.triotmetki.ruimport { createOtmetkiClient, getPlayer } from '@otmetki/sdk';
const client = createOtmetkiClient({
apiKey: process.env.OTMETKI_API_KEY,
baseUrl: 'https://api.triotmetki.ru'
});
const { data: player } = await getPlayer({ client, path: { idOrNick: 'Tanker' }, throwOnError: true });
console.log(player.summary.nickname, player.summary.overall.wn8.value);API reference
Every /v1 endpoint with parameters, response schemas and request samples, in the interactive reference on the API server.
Webhooks
The server sends a POST to your URL when a followed player earns a mark, finishes a session or a clan roster changes.
Events
A player earned a new mark of excellence. Fires for followed players and members of followed clans.
{
"id": "6f1c2a4e-8d3b-4c7a-9e21-3b5f0d8a7c10",
"event": "mark.gained",
"createdAt": "2026-09-24T19:42:07.000Z",
"data": {
"accountId": 12345678,
"nickname": "Tanker",
"tankId": 7249,
"marks": 3,
"previousMarks": 2,
"percent": 95.12,
"source": "mod"
}
}Headers
- webhook-signature
- Space-separated signatures, each «v1,» followed by base64: HMAC-SHA256 with the webhook secret (base64 after the whsec_ prefix) over «id.timestamp.body», per the Standard Webhooks spec.
- webhook-timestamp
- Send time in Unix seconds. Part of the signature.
- X-Otmetki-Event
- Event name, same as the event field.
- webhook-id
- Delivery id: part of the signature, use it for idempotency.
Verifying the signature
import { verifyWebhook } from '@otmetki/sdk';
app.post('/otmetki', async (request, reply) => {
try {
const { event, data } = verifyWebhook({
secret: process.env.OTMETKI_WEBHOOK_SECRET,
body: request.rawBody,
headers: request.headers
});
return reply.code(204).send();
} catch {
return reply.code(401).send();
}
});- Reject deliveries older than 5 minutes — it guards against replays.
- A failed delivery is retried up to 6 times with growing backoff.
- After 20 failures in a row the webhook is switched off; turn it back on in the dashboard.
Limits
The API is free for everyone. A Plus subscription raises your personal limits, and open free community projects get higher limits on request.
| Limit | Free | Plus | Community |
|---|---|---|---|
| Requests per day | 10,000 | 50,000 | 2,000,000 |
| Requests per second | 5 | 10 | 100 |
| Webhooks | 1 | 5 | 50 |
| How to get it | Right away, with any key | With a Plus subscription, for personal non-commercial use | Free for open free projects — contact us |
API terms
- The public API is free: anyone can get a key, and the API has no paid plans.
- Plus limits are for personal non-commercial use: your own bots, widgets and scripts.
- Open free community projects can get Community limits at no cost — contact us about your project.
- Reselling access to our API or putting its data behind a paywall is forbidden.
- Part of the data comes from the Lesta API, so Lesta Games’ terms apply too: credit the data source and do not use it commercially.