4D results API documentation
This page provides the technical 4d api documentation for Lotto4D MY, which covers 11 houses across Malaysia and Singapore. Developers can read the complete specifications for our 4d results api, including authentication headers, request formats, response payloads, endpoint parameters and webhook signatures. Every section covers how to retrieve live and historical lotto data.
Base address and keys
The API base address is https://lotto4dmy.biz/v1/ and every request sends a key in the X-Api-Key header. To inspect output before connecting your software, you can check the live lotto 4d results board on the main site. Authentication relies on two kinds of key depending on where the call originates. A secret key starting with sk_live_ works only from your server, from the IP addresses you register, and is refused if it is sent from a browser.
To show results on public pages, call the API from the browser with your public key. A public key starting with pk_live_ works in the browser and only on domains whose ownership you have verified. Domain verification is completed by adding a DNS TXT record that starts with lotto4dmy-site-verification= followed by your token, or with the file /.well-known/lotto4dmy-verification.txt on your web server.
Keys are stored as SHA-256 hashes, not as plain text, so they cannot be read back from the database.
Endpoints
The lotto 4d api offers structured paths to fetch current numbers, historical records, system dates, games, metadata and account statistics. History covers the past 30 days for every house, allowing applications to display recent results or verify winning tickets.
Developers query /v1/latest to return the newest draw of all 11 houses, or append ?operator= to target one house. To inspect past draws within the 30-day window, /v1/results?date= returns one day of draw data. The /v1/dates endpoint lists the days that have results available in the system. When building search forms, /v1/search?number= runs the number check across records. With box=1 the number check also matches every order of the same digits, simplifying permutation searches.
For structural metadata, /v1/operators lists houses and games supported across the platform. The /v1/version endpoint is a cheap check for new data so client applications can verify changes without incurring heavy processing overhead. Account monitoring is handled through /v1/usage, which shows the quota used for the billing cycle. The /v1/usage endpoint only answers a secret key, preventing public visitors from viewing your internal consumption metrics. All data routes return JSON.
| Endpoint | Parameters | Returns |
|---|---|---|
| /v1/latest | operator (optional) | Newest draw of all 11 houses or one house |
| /v1/results | date | One day of results |
| /v1/dates | n/a | Days that have results |
| /v1/search | number, box=1 (optional) | Number check; box=1 also matches every order of the same digits |
| /v1/operators | n/a | Houses and games |
| /v1/version | n/a | Cheap check for new data |
| /v1/usage | n/a | Quota used, answers a secret key only |
The result object
Results are served as JSON over HTTPS through a REST API. This documentation describes the exact JSON schema returned for standard 4D games and the other game types. A 4D result holds the 1st, 2nd and 3rd prize, 10 special (starter) numbers and 10 consolation numbers, with the draw date and draw number. Jackpot amounts are included where the house publishes them, giving operators full prize pool information in a single payload.
Additional lottery games follow distinct availability rules. Toto 5D, Toto 6D and the Toto jackpot games (6/50, 6/55 and 6/58) are available as latest and live results only, without the 30-day history. Because these jackpot formats do not retain historical records in the archive endpoints, applications requiring data for Toto 5D, Toto 6D or the 6/50, 6/55 and 6/58 games should capture and store the live payloads as draws finalize.
Live draws
During draw periods, the platform reads numbers from its sources. Magnum 4D, Da Ma Cai, Sports Toto, Sabah 88, Sandakan STC, Sarawak Cashsweep, Grand Dragon Lotto, Perdana and Lucky HariHari update number by number while the draw is running. With the live JSON feed, clients can show each number as soon as it is drawn.
During a draw window the system checks the source every 10 seconds and stops for that house once every number is in. Singapore 4D is not live: its result appears after the draw ends. Systems tracking Singapore 4D should expect the complete payload as a single update once the draw concludes rather than a continuous stream of individual prizes.
Quota, headers and errors
Usage is counted per account per calendar month in Malaysia time, shared by its secret and public keys. Responses carry the X-Quota-Limit and X-Quota-Used headers, and an account over its limit gets HTTP 429 until the next month.
Client integrations should monitor the X-Quota-Limit and X-Quota-Used values returned in response headers to track consumption across both secret and public keys before reaching the monthly boundary. When an account exceeds the allocated monthly quota, all subsequent requests receive HTTP 429 until the reset occurs at the start of the next calendar month in Malaysia time. A public key is limited to 120 requests per minute per visitor to protect browser endpoints.
| HTTP | When it happens |
|---|---|
| 401 | Missing or invalid key |
| 402 | The subscription has expired |
| 403 | Secret key used in a browser, a server IP that is not registered, a missing or unverified domain, or a feature outside the plan |
| 404 | Unknown path |
| 429 | Monthly quota or per-visitor rate exceeded |
Embedding the widget
Publishers who want drop-in lottery displays can integrate the pre-rendered client script across their verified web domains.
- Create a container element on your web page and specify an id attribute for the placement.
- Load the widget script from /v1/widget.js using a script tag that carries data-key with your pk_live_ key and data-target with the id of the element to fill.
- Allow the script to render the component, which shows the latest results, past days and the number check directly on your page.
- On the widget, results are written into the page HTML before it reaches the browser, so search engines can read the numbers.
Webhook
Automated payout systems and content networks can receive draw updates without running repetitive background polling tasks. The webhook sends an HTTPS POST to your address when a draw result is complete, signed with an X-Signature header. Receiving servers use the X-Signature header to validate incoming payloads before triggering internal database updates or automated reconciliation routines.
Webhook delivery is supported on specific subscription packages. For growing operations, Business costs $120 per month (about RM530): 10 domains, 500,000 requests per month, everything in Pro plus a webhook when a result is complete, a white-label widget and priority support. For single-site deployments, Lifetime Pro is a one-time payment of $910 (about RM4,000): locked to 1 domain, white-label widget, 150,000 requests per month, live number-by-number updates and webhook. Both packages provide automated notifications as soon as a draw result is complete.
To review complete quota allowances and licensing terms, see the plans and prices before configuring your webhook endpoint.
FAQ
What is the difference between sk_live_ and pk_live_ keys?
A secret key starting with sk_live_ works only from your server and registered IP addresses, and is refused if it is sent from a browser. A public key starting with pk_live_ works in the browser on verified domains, confirmed via a DNS TXT record starting with lotto4dmy-site-verification= or the file /.well-known/lotto4dmy-verification.txt.
What happens when my account goes over its monthly requests?
An account over its limit gets HTTP 429 until the next month. Responses carry the X-Quota-Limit and X-Quota-Used headers so you can track consumption before the monthly reset.
How do I find the days that have results?
You can call /v1/dates, which lists the days that have results available in the system. This endpoint allows your application to check valid draw dates before querying specific day results with /v1/results?date= or inspecting the newest draw of all 11 houses through /v1/latest.