Authentication
98Pays authenticates API requests with project credentials and an HMAC signature.
Project Signature Authentication
Use this method for payment endpoints and all /v1/* endpoints.
Request Header
To authenticate your requests to the 98Pays API, you need to include the following headers
| Header Parameter | Description |
|---|---|
| X-Client-Key | Your unique API key. This key identifies your application and authorizes access to the API. |
| X-Client-Token | Your secret token. This token serves as a secret key to generate the signature. |
| X-Signature | The signature generated using the HMAC-SHA512 algorithm. It ensures the integrity and authenticity of the request. |
Please ensure that you include these headers in every API request to properly authenticate your application.
Signature
To generate the signature, you can use the following code snippet in your preferred programming language:
# Signature 98Pays For PHP Code
$encodedBody = empty($bodyPayload) ? '' : json_encode($bodyPayload);
$xSignature = hash_hmac('sha512', $ClientKey . $encodedBody, $ClientToken);
In this code, replace the following variables with the appropriate values:
$ClientKey: Your credential API key.$bodyPayload: The JSON-encoded request body.$ClientToken: Your credential secret token.
The JSON property order and values used to generate the signature must be identical to the request body sent to the API.
For GET requests, the request body is empty. Generate X-Signature from the project key only; query parameters are not included in the signature payload.
Environment
We currently offer two environments that you can utilize for your application:
Sandbox - Contact US
Production - Contact US
Please note that the above information is subject to change, and we recommend referring to the latest documentation for accurate details.
