Skip to content
LogoLogo

API Keys

To enable API key access for your account (sandbox and production), contact the BLOX team. API keys authenticate your requests. Each key is linked to your account and to a registered signing public key.

[!IMPORTANT] Give a signing public key when BLOX creates your API key. You must do this. BLOX uses this key to verify the signatures on all write requests (POST, PUT, PATCH, DELETE).

Key facts

FactDetail
FormatKeys start with blox_pk_
DisplayBLOX shows the secret one time only, when it creates the key. Store the secret securely.
Active keysA maximum of 5 active keys for each account
Signing algorithmsed25519, ecdsa-p256-sha256, ecdsa-secp256k1-sha256

Environments

  • Sandbox keys: for development and tests on api.sandbox.blox.my
  • Production keys: for live traffic on api.blox.my

To get the two types of key, contact the BLOX team.

Authentication Methods

Header Authentication

Use the blox-api-key header (recommended):

curl https://api.sandbox.blox.my/v1/health \
  -H "blox-api-key: YOUR_API_KEY"

BLOX also accepts Authorization: Bearer YOUR_API_KEY.

Request Headers

HeaderRequiredDescription
blox-api-keyYes (or Bearer)Your API key secret
Content-TypeYes (for JSON bodies)application/json
Content-DigestYes (signed requests with a body)sha-256=:BASE64: of the canonicalized body
Signature-InputYes (POST/PUT/PATCH/DELETE)The RFC 9421 signature metadata
SignatureYes (POST/PUT/PATCH/DELETE)The RFC 9421 signature

GET requests need only the API key. Write requests must also have a signature. Refer to Request Signature.

Testing Authentication

curl https://api.sandbox.blox.my/v1/health \
  -H "blox-api-key: YOUR_API_KEY"
{
  "success": true,
  "message": "API key is valid",
  "account": {
    "id": "9f21ab04-6c3e-4d90-b1a7-8e5f2c0d4416",
    "name": "Your Business Name",
    "type": "BUSINESS",
    "status": "ACTIVE"
  }
}