> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapyd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> The X-API-KEY, X-TIMESTAMP and X-SIGNATURE headers, the HMAC-SHA256 signing string, the base URL for each module, and a test vector.

Every API request must include three signed headers.

| Header | Description |
| - | - |
| `X-API-KEY` | Your API key (per environment). |
| `X-TIMESTAMP` | Current Unix time in **seconds**. Must be within 300 seconds of server time. |
| `X-SIGNATURE` | Base64-encoded HMAC-SHA256 of the signing string, keyed with your API secret. |

## Signing string

```text theme={"theme":{"light":"css-variables","dark":"css-variables"}}
canonical_body = request JSON, keys sorted at every level, separators "," and ":", non-ASCII escaped as \uXXXX
                 GET requests and empty bodies sign "{}"
message        = X-API-KEY + "|" + X-TIMESTAMP + "|" + canonical_body
X-SIGNATURE    = Base64( HMAC-SHA256( API secret, message ) )
```

In Python this is exactly `json.dumps(body, sort_keys=True, separators=(",", ":"))`. [Widget Initialize](/api-reference-exchange/endpoint/widget/initialize) is the one exception: it signs `rawBody + timestamp` and hex-encodes the result.

**Test vector:** key `3f1b2c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d`, secret `test-secret-do-not-use`, timestamp `1735689600`, GET request (signs `{}`) → `6sCtVSRQjU9+2/af8gdwUAvY1l6Ii6ENcbRfanPkhY0=`.

## Base URLs

| Module | Sandbox | Production |
| - | - | - |
| Customer, KYC, bank, wallet | `https://sandbox.zapyd.com/cms/api/v1` | `https://api.zapyd.com/cms/api/v1` |
| Payin | `https://sandbox.zapyd.com/pis/api/v1` | `https://api.zapyd.com/pis/api/v1` |
| Payout, remittance | `https://sandbox.zapyd.com/pos/api/v1` | `https://api.zapyd.com/pos/api/v1` |
| Limits & EDD | `https://sandbox.zapyd.com/ren/api/v1` | `https://api.zapyd.com/ren/api/v1` |
| Organization | `https://sandbox.zapyd.com/org/api/v1` | `https://api.zapyd.com/org/api/v1` |

<Card title="Authentication guide" icon="book-open" href="/guides/development-and-testing/authentication">
  Node.js, Python and Java helpers, the full test vector, and `AUTH_*` error codes.
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.