Introduction
iGregulator is a REST API for verifying iGaming operator licences
against the public registers of seven regulators, each with a short API
code — UKGC (UK Gambling Commission), MGA (Malta Gaming Authority),
CW (Curaçao Gaming Authority, post-LOK), KH (Kahnawake Gaming
Commission), AN (Anjouan Gaming Authority), TGC (Tobique Gaming
Commission), and IOM (Isle of Man Gambling Supervision Commission).
Every register is read daily; each status shows when we last read it.
Live per-register freshness:
igregulator.io/status (Tobique’s site
currently blocks most automated reads).
Kahnawake, Tobique and the Isle of Man publish no licence number. For
those three, the license_number we return (KH/IG/…, KH/CSPA/…,
TGC/B2C/…, IOM/OGRA/…) is an iGregulator reference that identifies the
record in our API — not a number the regulator issued, and not something to
quote to the regulator.
Building with AI? → /docs/for-ai-agents covers MCP, structured errors,
_metaprovenance, and machine-readable resources (llms.txt, OpenAPI) for LLM integrations.
What you can do with it
Section titled “What you can do with it”- Verify a domain — hit
GET /v1/check?domain=Xand get averdict(licensed,licensed_provisional, or why not), a sentence to quote, and the operator + licence behind it in one round-trip. Dual-licensed brands come back with every (operator, jurisdiction) pair; where the regulator runs a per-domain verification page (Curaçao, Tobique),verification_urllinks straight to the primary source. - Look up an operator — search by name, registered name or slug via
GET /v1/operators/search?q=…and drill into licences, domain portfolios, and regulatory actions. - Pull a whole jurisdiction — paginate
GET /v1/jurisdictions/:code/operatorsfor every operator that has held a licence in that jurisdiction, whatever its status — the list has no status field, so check each operator’s licencestatusviaGET /v1/operators/:slug; onlyactiveis licensed now. - Track regulatory actions — enforcement decisions (fines, warnings,
licence revocations) surface via
GET /v1/operators/:slug/regulatory-actions.
Data coverage (as of 2026-10-01)
Section titled “Data coverage (as of 2026-10-01)”| Jurisdiction | Licences (active) | Source | Cadence |
|---|---|---|---|
UKGC (UK Gambling Commission) | 3,739 (2,796) | Public register ZIP | Daily 03:00 UTC |
MGA (Malta Gaming Authority) | 322 (313) | Playwright-scraped SPA | Daily 03:15 UTC |
CW (Curaçao Gaming Authority) | 703 (547) | OGL PDF + /token registry | Daily 03:30 UTC |
KH (Kahnawake Gaming Commission) | 65 (57) | Interactive Gaming + CSPA HTML | Daily 03:45 UTC |
AN (Anjouan Gaming Authority) | 1,586 (1,539) | Embedded JSON on register page | Daily 04:00 UTC |
TGC (Tobique Gaming Commission) | 196 (186) | Static HTML table (via CF Worker proxy) | Daily 04:15 UTC |
IOM (Isle of Man Gambling Supervision Commission) | 53 (53) | Register HTML page (+ its .xlsx as a cross-check) | Daily 04:25 UTC |
Across those registers: 6,664 licence records (5,491 of them active),
5,702 operators, and 10,421 domains currently linked to a licence — 4,619 of
them backed by the regulator’s own per-domain verification page (Curaçao
certificate / Tobique seal), re-read on a rolling schedule (every
Tobique seal nightly, each Curaçao certificate every 2–3 days) and
surfaced as
verification_url on /v1/check. These figures are
/v1/stats on 2026-10-01 — it serves the
current counts, each with its definition, and the per-jurisdiction rows above.
Live freshness per register at
/v1/health/coverage;
how coverage is measured at
coverage methodology. Which regulator page
sets each status, the evidence we keep and how we correct mistakes: our
methodology.
Who it’s for
Section titled “Who it’s for”Four buyer profiles drive the product today:
- Affiliate sites — verify that a brand they’re promoting is still licensed before writing reviews and paying out referral payments.
- Compliance + AML teams — weekly sweeps of their operator counterparties for status changes and enforcement actions.
- Payment providers — merchant onboarding checks + ongoing KYB.
- Investment intelligence — correlate licence churn, enforcement fines, and domain-expiry signals into early-warning scores.
Start here
Section titled “Start here”- Getting started — first curl call in under a minute.
- Authentication — when you graduate from the public 10 req/hr limit.
- Confidence scoring — how the
/v1/checkendpoint picks betweenhigh,medium, andlow. - API playground — try any endpoint interactively.
- Full endpoint reference — detailed schemas for every route.