Lewati ke konten utama

Authentication

API Key​

All V1 API requests require an API key sent in the X-API-Key header:

POST /v1/orders
X-API-Key: your-64-char-hex-api-key
Content-Type: application/json

The API does not accept a query-string API key. Send X-API-Key from your server on every request.

Your API key is available in the merchant dashboard under Settings → API Credentials.

waspada

Treat your API key like a password. Never expose it in client-side JavaScript or mobile app bundles. All API calls should be made from your server.

Request Signature for Order Creation​

When a Webhook Secret is configured for your merchant, POST /v1/orders requires X-Signature; an absent or invalid signature returns HTTP 401. If no secret is configured, the header is not required. The same secret signs outgoing V1 order webhooks.

Algorithm: HMAC-SHA256 of the raw request body using your webhook_secret.

Header format:

X-Signature: sha256=<lowercase-hex-digest>

Generating the Signature​

PHP
$body = json_encode($payload);
$secret = 'your-webhook-secret';
$signature = 'sha256=' . hash_hmac('sha256', $body, $secret);

curl_setopt($ch, CURLOPT_HTTPHEADER, [
'X-API-Key: ' . $apiKey,
'X-Signature: ' . $signature,
'Content-Type: application/json',
]);
Node.js
const crypto = require('crypto');

const body = JSON.stringify(payload);
const signature = 'sha256=' + crypto
.createHmac('sha256', webhookSecret)
.update(body)
.digest('hex');

fetch('https://api.flypay.asia/v1/orders', {
method: 'POST',
headers: {
'X-API-Key': apiKey,
'X-Signature': signature,
'Content-Type': 'application/json',
},
body,
});

Credential Rotation​

Ask your platform administrator to provision or rotate the API key and webhook secret. Coordinate rotation: update the signing secret on your order requests and webhook receiver together. Do not assume that a dashboard self-service rotation control exists.