API

Who's Bluffing runs on a small JSON API that the web game, the Slack and Discord apps and the classroom dashboard all use. This page starts with what anyone may read, then gives the full contracts: rounds (the game today) and the retired daily game.

Public API

Two endpoints are public reads: aggregate numbers with no ids in them, free to fetch from any site.

Both answer with the header Access-Control-Allow-Origin: *, so a page on another site can read them with a plain fetch. Send simple GET requests (no custom headers). No key and no account are needed.

The other endpoints (starting a round, answers, flags, the chat apps' calls) exist for the Who's Bluffing apps. Building on them is welcome, but expect them to change without notice, keep traffic low, and never send personal data.

Rate limits

Requests to /api/* are rate-limited per IP address (about 120 a minute); beyond that the API answers 429 for a minute. The numbers change at most once a minute (stats) or once a day (KPI), so cache them rather than polling.

Attribution

If you show these numbers, please credit Who's Bluffing with a link to whosbluffing.com. The KPI counts follow the definitions on the research page; please keep the note that someone who plays on two surfaces counts twice.

Open data

Answers are never available through the API. The release plan is fixed in the pre-registration: anonymous row-level data for both studies, with every exclusion flag kept, will be published on OSF, Hugging Face and Kaggle under CC BY-NC 4.0, each release with a data card that describes how it was collected, its sample bias and what it should not be used for. Classroom sessions are pooled without class codes. Details: Open data on the research page and the pre-registration.

Rounds API contract (replaces the daily-item loop for the viral game; the full assessment at /test keeps intervals)

All JSON. Dates are UTC YYYY-MM-DD. surface ∈ {web, slack, discord, room}. community is slack:<team hash>, discord:<guild hash> or room:<code>. A play = one completed round (10 answered) on web/room/discord, or one in-channel Slack or Discord answer to the daily question.

Daily-item endpoints (/api/daily/*) remain for the full assessment and existing data; the home page no longer uses them.

Clarifications (2026-10-03, after the Slack build):

Additions (2026-10-04, from the web build; all backward compatible):

Familiarity (2026-10-04): every item carries views_month (average monthly English Wikipedia pageviews by users over the last 3 full months); a pair's fame = the lesser of its two items'.

Daily API contract (web implements; Slack consumes)

Base: the web deployment (https://<host>/api). All JSON. Dates are UTC YYYY-MM-DD. surface ∈ {web, slack, classroom}.

Anonymous ids: web = random id in localStorage; Slack = hex sha256(team_id + ":" + user_id + ":" + SALT) computed in the Slack worker (SALT is a Worker secret that must never change); never the raw Slack ids. Server stores players(anon_id, surface, first_seen, last_seen, plays) and plays(anon_id, date, surface, hits, completed_at).

Surface notes: for surface=slack, rt_ms is the modal open-to-submit time divided by 5 (Slack gives no per-question timing) and is approximate; response-time exclusions in PREREG apply to the web surface only.

Source: web/docs/public-api.md, docs/api-rounds.md, docs/api-daily.md on GitHub.