# Lucky Cart > Lucky Cart is a French retail-media and smart-commerce company that turns grocery > retailers' first-party transactional data into targeted, gamified shopper activations > for CPG brands. Its integration surface is a set of HTTP APIs consumed through three > first-party SDKs (web, iOS, Android): a shopper-event ingest, a banner/promotion > displayer, a cart-to-ticket endpoint, and a hosted game experience. Lucky Cart itself > publishes no /llms.txt, no OpenAPI, no /.well-known/ documents and no public API > reference; this file is generated by API Evangelist from the company's own public > website and the source of its own SDK repositories. GENERATED BY: API Evangelist (https://apievangelist.com) — not published by Lucky Cart. METHOD: generated from apis.yml plus the artifacts in this repository. DATE: 2026-08-12 NOTE FOR AGENTS: Lucky Cart's APIs are NOT open. Credentials (an AUTH_KEY / siteKey and, for signed calls, an AUTH_SECRET) are issued manually by the Lucky Cart integration team to contracted retailers. There is no self-service signup, no free tier, no sandbox, and no published rate limit. Do not attempt to call these endpoints without a commercial relationship. ## APIs - [Lucky Cart Core API](https://api.luckycart.com): Cart-to-ticket submission and game-data retrieval. POST /cart/ticket is the only signed endpoint (HMAC-SHA256 over a timestamp, sent as auth_sign with auth_v 2.0). Game data is read back at /{siteKey}/game/{cartId} or /{siteKey}/game/cust/{shopperId}, optionally suffixed with the device. - [Shopper Events API](https://shopper-events.luckycart.com/v1): POST /event ingests shopper events (pageViewed, cartValidated) as {shopperId, siteKey, eventName, payload}. - [Shopper Experience API](https://shopper-experience.luckycart.com/v1): GET /experiences returns the experiences available to a shopper, filtered by experienceType. - [Game Experience API](https://game-experience-api.luckycart.com/v1): GET /game-experiences-access returns the games a shopper may access, bounded by a count parameter. - [Displayer API](https://displayer.luckycart.com): GET /{siteKey}/{shopper}/banner|banners/{platform}/{pageType}/{format} returns the promotional banner selected for the current page context. - [Promo Matching](https://promomatching.luckycart.com): banner image and click-through ("jump") host, and the banner selection host used by the web SDK. - [Experiences](https://experiences.luckycart.com): hosted game frames, embedded by siteKey, customerUid, cartUid and ticketCode. ## SDKs - [JavaScript SDK](https://github.com/lucky-cart/luckycart-js-sdk): browser SDK loaded by script tag. Last commit 2022-08-26. Its documented CDN loader URL returned 404 in 2026. - [iOS SDK](https://github.com/lucky-cart/lucky-cart-ios): Swift Package, tag 1.0.0, last commit 2023-03-01. - [Android SDK](https://github.com/lucky-cart/lucky-cart-android): Kotlin, distributed via JitPack, release 1.0.18 published 2023-01-09. - [iOS sample app](https://github.com/lucky-cart/lucky-cart-client-sample-ios) - [Android sample app](https://github.com/lucky-cart/lucky-cart-client-sample-android) ## Specs Lucky Cart publishes no OpenAPI, AsyncAPI, JSON Schema, GraphQL SDL, MCP server or A2A agent card. All of the following returned 404 on every Lucky Cart host: /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /.well-known/agent-card.json, /.well-known/agent.json, /.well-known/openid-configuration, /.well-known/oauth-authorization-server, /.well-known/api-catalog, /.well-known/ai-plugin.json, /.well-known/security.txt, /llms.txt. ## API Evangelist artifacts - [Authentication](authentication/lucky-cart-authentication.yml): site key plus HMAC-SHA256 request signing; no OAuth, no bearer tokens, no scopes. - [Conventions](conventions/lucky-cart-conventions.yml): versioning, error envelope, pagination, tracing and retry semantics read from SDK source. - [Packages](packages/lucky-cart-packages.yml): the three first-party SDKs and their currency. - [Components](components/lucky-cart-components.yml): the embeddable banner and game surfaces. - [Conformance](conformance/lucky-cart-conformance.yml): ISO 9001 certified; 14 API standards measured absent. - [Lifecycle](lifecycle/lucky-cart-lifecycle.yml): no status page, no deprecation policy, no SLA. - [Rate limits](rate-limits/lucky-cart-rate-limits.yml): none published. - [Plans and pricing](plans/lucky-cart-plans-pricing.yml): none published; enterprise sales only. - [Well-known](well-known/lucky-cart-well-known.yml): 99 probes, zero documents. - [Domain security](security/lucky-cart-domain-security.yml): TLS 1.3, HSTS, SPF and DMARC present; DMARC policy is none, no DNSSEC, no CAA. ## Company - [Website](https://www.luckycart.com/en) - [Our solution](https://www.luckycart.com/en/notre-solution) - [In practice / case studies](https://www.luckycart.com/en/en-pratique) - [News](https://www.luckycart.com/en/actualites) - [FAQ and glossary](https://www.luckycart.com/en/faq-glossaire) - [Certifications](https://www.luckycart.com/en/certifications): ISO 9001 - [Contact](https://www.luckycart.com/en/contact) - [GitHub organization](https://github.com/lucky-cart) - [Customer platform (login)](https://app.luckycart.com/) - [Help Centre](https://kb.luckycart.com/hc): access-restricted, returns HTTP 403 to the public - [Careers](https://luckycart.recruitee.com/) - [Privacy policy](https://www.luckycart.com/en/politique-de-confidentialite) - [Legal information](https://www.luckycart.com/en/mentions-legales)