Get your API Key and API Secret from our support team. Sandbox and production credentials are separate and not interchangeable.
Required headers
string (UUID)
required
Your API key. Identifies your organization.
integer
required
Current Unix time in seconds. Requests more than 300 seconds away from server time are rejected, so keep your server clock in sync (NTP).
string
required
Base64-encoded HMAC-SHA256 of the signing string, keyed with your API secret.
Signature algorithm
Code examples
- Node.js
- Python
- Java
Test vector
Check your implementation against these fixed values before calling the API. If your output matches, your signing is correct.Example request
Widget Initialize uses a different signature
Widget Initialize is served by the widget service and verifies a different signature. It uses the same three headers, but:- The raw body bytes exactly as sent, with no re-sorting, followed directly by the timestamp. There’s no API key and no
|separator. - Hex-encoded, not Base64.
- The timestamp window is also 300 seconds.
test-secret-do-not-use, timestamp 1735689600, body {"flow_type":"buy","fiat_amount":"1000"} → 26241a01db912ebb26d7f7099958a11ebc50af14937df9d1797a9e89959e7c87.
Authentication errors
Auth failures return HTTP401 with an err_code:
Security
- Keep the API secret on your server. Never ship it to browsers or mobile apps.
- Generate a fresh timestamp and signature for every request.
- Rotate credentials immediately if you suspect a leak.