Skip to main content
The widget talks to your page with browser postMessage events. Use them to update your UI, for example to close the widget when the player is done or show that a payment method was added. Cash out status changes don’t come through browser events. They reach your backend by webhook.

Listening for events

Take the trusted origin from the widget_url your backend received, and check both the origin and the source window on every message:
The ZBD_ prefix isn’t authentication. Don’t act on an event until you’ve checked both event.origin and event.source.

Events

Treat these events as UI signals. For anything that affects money, like a completed or failed payout, rely on the webhook your backend receives.

Commands you can send

After the same origin and source checks, your page can send these commands to the widget with postMessage:

Refreshing a session

When a session is about to expire, the widget sends ZBD_SESSION_REFRESH_REQUIRED with a request_id. Ask your backend to create a new session, then send the new token back with ZBD_SESSION_REFRESH_RESULT and the same request_id. The user stays where they are in the flow.