Skip to main content
Every API request carries three headers. Zapyd recomputes the signature on its side and rejects the request if it does not match.
Get your API Key and API Secret from our support team. Sandbox and production credentials are separate and not interchangeable.

Required headers

string (UUID)
required
Your API key. Identifies your organization.
integer
required
Current Unix time in seconds. Requests more than 300 seconds away from server time are rejected, so keep your server clock in sync (NTP).
string
required
Base64-encoded HMAC-SHA256 of the signing string, keyed with your API secret.

Signature algorithm

The canonical body must match exactly what Zapyd produces when it re-serializes the JSON you sent:
Send the exact canonical_body string you signed as the request body. Then what you signed and what you sent can never drift apart.

Code examples

Do not use JSON.stringify(body, Object.keys(body).sort()). The replacer array drops nested keys that aren’t also top-level keys, and it doesn’t escape non-ASCII characters, so the signature fails.

Test vector

Check your implementation against these fixed values before calling the API. If your output matches, your signing is correct.

Example request

For a GET request, sign an empty body and send no body:

Widget Initialize uses a different signature

Widget Initialize is served by the widget service and verifies a different signature. It uses the same three headers, but:
  • The raw body bytes exactly as sent, with no re-sorting, followed directly by the timestamp. There’s no API key and no | separator.
  • Hex-encoded, not Base64.
  • The timestamp window is also 300 seconds.
Test vector: secret test-secret-do-not-use, timestamp 1735689600, body {"flow_type":"buy","fiat_amount":"1000"} → 26241a01db912ebb26d7f7099958a11ebc50af14937df9d1797a9e89959e7c87.

Authentication errors

Auth failures return HTTP 401 with an err_code:

Security

  • Keep the API secret on your server. Never ship it to browsers or mobile apps.
  • Generate a fresh timestamp and signature for every request.
  • Rotate credentials immediately if you suspect a leak.