Authentication
All BLOX merchant API requests must have authentication. This section tells you how to authenticate your API requests securely.
Wallet, Onramp (Checkout), and Payout use the same wire format. Payout has a different freshness and replay policy. Refer to Payout differences.
Overview
BLOX uses two layers of authentication:
- API Key: Identifies your application and gives access to the API.
- Request Signature: Uses RFC 9421 HTTP Message Signatures to prevent unauthorized changes to write requests (POST, PUT, and the other write methods).
Authentication Methods
Quick Reference
Required Headers
| Header | Required | Description |
|---|---|---|
blox-api-key | Always | Your API key (secret) |
Content-Type | If the request has a body | Set it to application/json |
Signature | Write requests | The RFC 9421 cryptographic signature |
Signature-Input | Write requests | The metadata of the signature |
Content-Digest | If the request has a body | The RFC 9421 digest of the request body |
Example Request (Read-only)
curl "https://api.blox.my/v1/health" \
-H "blox-api-key: YOUR_API_KEY"Next Steps
- Get API Keys. To enable access, contact the BLOX team.
- Learn request signing to make your API calls secure.
- Test in Sandbox before you use production.