# Licence badge

URL: https://igregulator.io/docs/badge/
Markdown: https://igregulator.io/docs/badge.md

> An embeddable SVG badge that shows a domain's gambling-licence status as iGregulator last read it — what every state says, why it is honest, embed code, caching.

A live badge for any domain: the licence status `/v1/check` returns for it, drawn
as a small SVG you can put on a review page, an affiliate listing or an operator's
own footer. It links back to the domain's page on iGregulator, where every fact is
cited to the regulator page it came from.

```
https://app.igregulator.io/badge/<domain>.svg
```

<img src="https://app.igregulator.io/badge/stake.com.svg" alt="Licence status of stake.com, checked by iGregulator" height="20" />

Free for everyone — no key, no account, not counted against any API quota.
It is there to be used.

## Embed it

Every brand page on [app.igregulator.io](https://app.igregulator.io/brands) has an
**Embed this badge** box with the code for that domain and a copy button. By hand:

```html
<a href="https://app.igregulator.io/brands/stake.com"><img src="https://app.igregulator.io/badge/stake.com.svg" alt="Licence status of stake.com, checked by iGregulator" height="20"></a>
```

```md
[![Licence status of stake.com, checked by iGregulator](https://app.igregulator.io/badge/stake.com.svg)](https://app.igregulator.io/brands/stake.com)
```

Use the bare hostname, lowercase, as the register lists it (`kwiff.com`, not
`https://www.kwiff.com/`). A `www.` or other subdomain resolves the way
`/v1/check` resolves it.

The alt text names the image and deliberately does **not** repeat the verdict:
you paste the snippet once, and an alt that said "active" would keep saying it
after the badge itself had changed.

**Two-line card.** Add `?style=large` for a 36 px card with the domain on the
first line and the licence (with its number, where the regulator publishes one)
on the second:

```
https://app.igregulator.io/badge/stake.com.svg?style=large
```

## What it can say

The badge always names the domain it is about — so it cannot be lifted onto
another site and read as that site's licence — and, whenever it describes a
record, the date of our last read of it. (The examples use placeholder domains:
a status printed in a document goes out of date; the badge does not.)

| State | Example | Colour |
| --- | --- | --- |
| Active licence, domain listed | `casino.example · UKGC licence · active · verified 2026-09-30` | green |
| Our last read is older than the register's freshness target | `casino.example · UKGC licence · active · last verified 2026-09-28` | amber |
| Curaçao licence the register reads "Assessment in progress" | `casino.example · Curaçao licence · provisional · verified 2026-09-30` | amber |
| The licence behind a listed domain is not active | `casino.example · UKGC licence · surrendered · checked 2026-09-30` — also `expired`, `revoked`, `suspended`, `pending`, `not in register`, `status unknown` | grey |
| The regulator no longer lists the domain under that licence | `casino.example · no longer listed by Anjouan · checked 2026-09-30` | grey |
| No licensed record for the domain | `casino.example · not found in the 7 registers we cover` | grey |

- **Only green means licensed now**, and only for an `active` licence on a domain
  link the regulator currently lists — the same two fields `/v1/check` answers
  with (`status`, `domain_status`). Which licence, when a domain is linked to
  several, is the one `/v1/check` reports as `match`.
- **Every other status is named as what it is.** `surrendered` is the operator
  giving the licence up; `not in register` is the register no longer listing it
  with no reason published. Neither is a revocation, and the badge never says
  one. It never says "unlicensed", and it has no red.
- **A miss is scoped.** "Not found in the 7 registers we cover" is exactly
  `/v1/check`'s `match_absence_reason` + `checked_jurisdictions`: we read seven
  registers, and a domain licensed somewhere else is not in them. A match by
  company or trading name alone (`confidence: medium` / `low` on `/v1/check`) is
  not a record of this domain, so the badge says "not found" for it too.
- **"Last verified" in amber** when our latest read of the record is older than
  the register's freshness target — 24 h for UKGC, Anjouan, Tobique and the Isle
  of Man, 48 h for MGA, Curaçao and Kahnawake, the rule
  [`/v1/health/coverage`](https://igregulator.io/docs/coverage-methodology/) applies. A green badge
  never rests on a stale read.
- **Kahnawake, Tobique and the Isle of Man publish no licence number.** The
  badge names the regulator and never prints the reference we use internally.
- **Provisional** is a Curaçao licence past its stated term whose register entry
  reads "Assessment in progress": the CGA keeps it in force until it decides, so
  it is `active` with a qualifier (`status_qualifier:
  provisional_under_assessment` on `/v1/check`), and the badge says so.

A URL that does not end in a hostname answers **400** with a badge that says
"not a valid hostname". If we cannot read our own database for a moment, the
badge says "status unavailable right now" (HTTP 503, not cached) rather than
anything about the licence.

## How fresh it is

We read every register nightly. The badge is built from those reads, cached for
an hour on our side, and served with `Cache-Control: public, max-age=3600,
s-maxage=3600`, so Cloudflare and browsers keep a copy for up to an hour. A
change we read reaches the badge within about an hour; a browser that showed it
just before may keep its copy a little longer. It changes by itself: when the
regulator's listing changes, the badge does — nothing to update on your side.

## What it is not

The badge is not an endorsement, a rating or a certification by iGregulator, and
not an opinion about the site. It reports what one regulator's public register
said at our last read, with the date. For the evidence behind it, follow the link
to the brand page, or ask [`/v1/check`](https://igregulator.io/docs/getting-started/) yourself.

## Who embeds it

When a badge is fetched from another site, we record that site's hostname (from
the `Referer` header — the host only, no path, nothing about the visitor), the
domain, when we first and last saw the pair, and a count of fetches that reached
us. That is how we know where badges are used; nothing else is kept.
