Skip to main content

Request signature

Sending data to the Spaycial API​

Some requests to the Spaycial API need to be signed by providing Signature headers.

To be able to sign requests, you should provide dedicated public keys for both the sandbox and production environments - see RSA key generation. Those keys should be emailed to tech@spaycial.com.

The private key should be securely stored on your server. In case of a possible security breach, the private key should be regenerated and the public key emailed again.

Signature headers​

The following headers are required for the request to be considered signed:

  • Expires-at - request expiration time as a UNIX timestamp in UTC timezone. We suggest using +1 minute from the current time. The maximum value is 1 hour from now in UTC, otherwise a forbidden-request error with code invalidExpiresAtHeader is raised.
  • Signature - base64 encoded SHA256 signature of the string represented as Expires-at|request_method|original_url|post_body|, 4 parameters concatenated with a vertical bar |, signed with your private key.

The pseudocode to generate the signature looks like this:

base64(sha256_signature(private_key, "Expires-at|request_method|original_url|post_body|"))

The fields making up the signed string:

  • request_method - the uppercase HTTP method, for example GET, POST, PATCH, PUT, DELETE.
  • original_url - the full requested URL, with all its query parameters.
  • post_body - the request body. Left empty for a GET request, or when the body is empty.

Examples of the string used to generate the signature:

  • GET example: 1522249849|GET|https://api.transactionconnect.com/myResource?customerId=123||
  • POST example: 1522249849|POST|https://api.transactionconnect.com/myResource|{"customerId":"123"}|

Headers example:

Expires-at: 1413466421
Signature: 0o6LgMnlG7FX5tWLoKd6V5jlktodP8I/3vWqh1pOZvPgMn/WPq5YqZWPc0teey135RO2muFThcvuZJtcbaUje1UWFHyWhTh89guHJ47pgBB7w0LMkRw3XskEsafEUZketeTY/NtyeU7ETHHm2Tlw8IJho+gk51Rtp7JJPanw2OZG/6BElFcL0qGs4ohTmJUKKsdI1eo5jseFqF+sX0T4dRYqL7ebhDCD8YsYdsZ9zxlX88+YtUQnEqGbswOH4saGaQNH9NjxST2NS8MFtCU7uwZGybBk4i0l1wtbTJwfgaa+yb2L7l0ltIgxZFJzQOShpVOgI+o8fUg31lOblmMVkpyvXJ/n5Ed2u0nA1yMWkQUPpu03Xkh2RG7qbBOEq6+A374OnhUDwi5TUqYrY89paPwq/A7z2lc56Q84T+NrSLdi0x0aejpp6Cn90Yqpbs04dIio579+KyLm/8XoZ4p9k7vz6vTpDITyTAc93/KHnqeT1hTp7AWMaxuGfEI361fyZLDzkSvnHq4QzMkJOKhPELxSji99dm0LCSZpUiUhTTU3G09LvLBCEFLvbGJzxlO7NgqOGVPMlEc4fJqzU/jrTfkodn4DtzaOJghlXynithKIUBAkpNY9QGPOQIMvcbOZfhilm+bjWuYeNpeALvbqY3ONcibHLjc8ItAVMzORSFg=