How it works
The following describes steps, required to authenticate request signature using HMAC-SHA1:
You construct an API request (for API calls)
You calculate a keyed-hash message authentication code (HMAC-SHA1) signature using your API secret
You include both the API key and the signature in the
Authorization
header, and then call the APIThe API uses your API key to look up your API secret
The API reconstructs the signature from the request data and the API secret with the same algorithm you used to calculate the signature you sent in the request
If the signature generated by Cryptopay matches the one you sent in the request, the request is considered authentic. If the comparison fails the request is discarded and Cryptopay returns
401
or403
error responses:
Last updated