API Keys
To enable API key access for your account (sandbox and production), contact the BLOX team. API keys authenticate your requests. Each key is linked to your account and to a registered signing public key.
[!IMPORTANT] Give a signing public key when BLOX creates your API key. You must do this. BLOX uses this key to verify the signatures on all write requests (POST, PUT, PATCH, DELETE).
Key facts
| Fact | Detail |
|---|---|
| Format | Keys start with blox_pk_ |
| Display | BLOX shows the secret one time only, when it creates the key. Store the secret securely. |
| Active keys | A maximum of 5 active keys for each account |
| Signing algorithms | ed25519, ecdsa-p256-sha256, ecdsa-secp256k1-sha256 |
Environments
- Sandbox keys: for development and tests on
api.sandbox.blox.my - Production keys: for live traffic on
api.blox.my
To get the two types of key, contact the BLOX team.
Authentication Methods
Header Authentication
Use the blox-api-key header (recommended):
curl https://api.sandbox.blox.my/v1/health \
-H "blox-api-key: YOUR_API_KEY"BLOX also accepts Authorization: Bearer YOUR_API_KEY.
Request Headers
| Header | Required | Description |
|---|---|---|
blox-api-key | Yes (or Bearer) | Your API key secret |
Content-Type | Yes (for JSON bodies) | application/json |
Content-Digest | Yes (signed requests with a body) | sha-256=:BASE64: of the canonicalized body |
Signature-Input | Yes (POST/PUT/PATCH/DELETE) | The RFC 9421 signature metadata |
Signature | Yes (POST/PUT/PATCH/DELETE) | The RFC 9421 signature |
GET requests need only the API key. Write requests must also have a signature. Refer to Request Signature.
Testing Authentication
curl https://api.sandbox.blox.my/v1/health \
-H "blox-api-key: YOUR_API_KEY"{
"success": true,
"message": "API key is valid",
"account": {
"id": "9f21ab04-6c3e-4d90-b1a7-8e5f2c0d4416",
"name": "Your Business Name",
"type": "BUSINESS",
"status": "ACTIVE"
}
}