World Business HubWORLD BUSINESS HUBWEBSITE DESIGN & HOSTINGINTEGRATION OVERVIEW

GTA WORLD · WORLD BUSINESS HUB

Your world connected.How our integration works.

An overview of GTA World sign-in, company access and in-character banking for our web design and hosting service.

01 · INTEGRATION GUIDE

Purpose

World Business Hub provides staff-built websites and hosting for in-character GTA World businesses. Consultations, contracts, design approvals, account management and renewals take place in-character. The standard fee is 15,000 in-game currency per website per month, including maintenance and its Discord bot. Administrators may agree discounts or free hosting.

02 · INTEGRATION GUIDE

GTA World OAuth

Registered redirect: https://gtabusinesshub.world/auth/gta-world/callback

  1. The visitor starts from the central Hub login page. The server creates a short-lived, single-use state record and a matching browser cookie, then redirects to GTA World.
  2. GTA World returns an authorization code and state. The server validates the state and expiration before exchanging the code server-side using the application's client ID and secret.
  3. The server fetches the authenticated account and its characters, then stores the GTA World account ID and character IDs/names. It creates a server-side session with a hashed session identifier and an HttpOnly cookie.
  4. Users link Discord with separate, explicit consent for identification and joining the Hub server. The app stores the linked Discord ID; Discord access/refresh tokens are not retained by this linking flow.
  5. The visitor returns to the requested Hub workspace or an allowed company destination. Company redirects are checked against the published website and verified active domain records; arbitrary external redirects are rejected.

Authentication stays on the central Hub domain. Company login links use this central service. Company ranks and permissions are scoped to the individual business; owning one business does not grant access to another. Staff management, editing, banking and bot actions have separate server-side permission checks. Hub administrators have separately authorized platform access.

The app does not collect GTA World passwords or request email addresses. Additional records include in-character phone/routing numbers, consultations, applications, company content, session and audit records. Hosting/proxy logs are separate from the application database; operators must configure their retention and handling to meet GTA World requirements.

Directly visiting the callback displays an information page. It does not authenticate a visitor. Invalid or expired real authentication callbacks are rejected.

03 · INTEGRATION GUIDE

Banking and company payments

Registered payment notification URL: https://gtabusinesshub.world/api/gta-world/payments/callback

The integration uses the Fleeca v2 merchant API at https://banking.gta.world/api/v2. Platform hosting fees use the Hub merchant key. Company customer invoices and payroll use that company's own merchant key and routing details. Company merchant credentials are stored encrypted and handled only by the server.

Hosting invoices, customer invoices and payroll records require authorized actions. Hosted payment links are created through POST /payment and saved with their payment ID, amount, merchant scope and sandbox/live mode. A browser visit or redirect alone never marks an invoice as paid.

For POST callbacks, the current implementation expects a JSON body and X-Fleeca-Signature in sha256=<hex> format, calculated as HMAC-SHA256 over the raw body using the corresponding merchant key. It finds the saved payment and verifies payment_id, amount, mode and status before updating its invoice within a database transaction. Unknown or unsigned payments are rejected; an already paid invoice cannot be downgraded by a later callback. Sandbox success is recorded separately from live payment.

This signature contract and payload must be confirmed against the credentials and current documentation issued by GTA World before accepting live payments. No successful end-to-end banking test has yet been completed.

Authorized staff can reconcile a saved hosted payment using GET /payments/{payment_id}. Payroll uses POST /transfers only after explicit confirmation of a saved outgoing transfer. Uncertain transfer outcomes are flagged for bank-history review instead of being blindly retried. There are no automatic customer debits or automatic overdue suspensions.

Callback responses: 200 accepted notification; 400 invalid or mismatched payload; 401 unknown payment or invalid signature; 503 missing banking configuration. GET shows the public information page and does not alter payment records.

04 · INTEGRATION GUIDE

Discord and ongoing operation

Each business can configure its own bot and notification destinations for applications, orders, bookings and job adverts. Hub consultations use the Hub's private staff channels. Credentials are kept private and notifications contain in-character business information. Website and bot processes require continuous server operation.