Skip to content

Introduction

iGregulator is a REST API for verifying iGaming operator licences against the public registers of seven regulators, each with a short API code — UKGC (UK Gambling Commission), MGA (Malta Gaming Authority), CW (Curaçao Gaming Authority, post-LOK), KH (Kahnawake Gaming Commission), AN (Anjouan Gaming Authority), TGC (Tobique Gaming Commission), and IOM (Isle of Man Gambling Supervision Commission). Every register is read daily; each status shows when we last read it. Live per-register freshness: igregulator.io/status (Tobique’s site currently blocks most automated reads).

Kahnawake, Tobique and the Isle of Man publish no licence number. For those three, the license_number we return (KH/IG/…, KH/CSPA/…, TGC/B2C/…, IOM/OGRA/…) is an iGregulator reference that identifies the record in our API — not a number the regulator issued, and not something to quote to the regulator.

Building with AI? → /docs/for-ai-agents covers MCP, structured errors, _meta provenance, and machine-readable resources (llms.txt, OpenAPI) for LLM integrations.

  • Verify a domain — hit GET /v1/check?domain=X and get a verdict (licensed, licensed_provisional, or why not), a sentence to quote, and the operator + licence behind it in one round-trip. Dual-licensed brands come back with every (operator, jurisdiction) pair; where the regulator runs a per-domain verification page (Curaçao, Tobique), verification_url links straight to the primary source.
  • Look up an operator — search by name, registered name or slug via GET /v1/operators/search?q=… and drill into licences, domain portfolios, and regulatory actions.
  • Pull a whole jurisdiction — paginate GET /v1/jurisdictions/:code/operators for every operator that has held a licence in that jurisdiction, whatever its status — the list has no status field, so check each operator’s licence status via GET /v1/operators/:slug; only active is licensed now.
  • Track regulatory actions — enforcement decisions (fines, warnings, licence revocations) surface via GET /v1/operators/:slug/regulatory-actions.
JurisdictionLicences (active)SourceCadence
UKGC (UK Gambling Commission)3,739 (2,796)Public register ZIPDaily 03:00 UTC
MGA (Malta Gaming Authority)322 (313)Playwright-scraped SPADaily 03:15 UTC
CW (Curaçao Gaming Authority)703 (547)OGL PDF + /token registryDaily 03:30 UTC
KH (Kahnawake Gaming Commission)65 (57)Interactive Gaming + CSPA HTMLDaily 03:45 UTC
AN (Anjouan Gaming Authority)1,586 (1,539)Embedded JSON on register pageDaily 04:00 UTC
TGC (Tobique Gaming Commission)196 (186)Static HTML table (via CF Worker proxy)Daily 04:15 UTC
IOM (Isle of Man Gambling Supervision Commission)53 (53)Register HTML page (+ its .xlsx as a cross-check)Daily 04:25 UTC

Across those registers: 6,664 licence records (5,491 of them active), 5,702 operators, and 10,421 domains currently linked to a licence — 4,619 of them backed by the regulator’s own per-domain verification page (Curaçao certificate / Tobique seal), re-read on a rolling schedule (every Tobique seal nightly, each Curaçao certificate every 2–3 days) and surfaced as verification_url on /v1/check. These figures are /v1/stats on 2026-10-01 — it serves the current counts, each with its definition, and the per-jurisdiction rows above. Live freshness per register at /v1/health/coverage; how coverage is measured at coverage methodology. Which regulator page sets each status, the evidence we keep and how we correct mistakes: our methodology.

Four buyer profiles drive the product today:

  • Affiliate sites — verify that a brand they’re promoting is still licensed before writing reviews and paying out referral payments.
  • Compliance + AML teams — weekly sweeps of their operator counterparties for status changes and enforcement actions.
  • Payment providers — merchant onboarding checks + ongoing KYB.
  • Investment intelligence — correlate licence churn, enforcement fines, and domain-expiry signals into early-warning scores.
  1. Getting started — first curl call in under a minute.
  2. Authentication — when you graduate from the public 10 req/hr limit.
  3. Confidence scoring — how the /v1/check endpoint picks between high, medium, and low.
  4. API playground — try any endpoint interactively.
  5. Full endpoint reference — detailed schemas for every route.