Skip to content
LogoLogo

Authentication

All BLOX merchant API requests must have authentication. This section tells you how to authenticate your API requests securely.

Wallet, Onramp (Checkout), and Payout use the same wire format. Payout has a different freshness and replay policy. Refer to Payout differences.

Overview

BLOX uses two layers of authentication:

  1. API Key: Identifies your application and gives access to the API.
  2. Request Signature: Uses RFC 9421 HTTP Message Signatures to prevent unauthorized changes to write requests (POST, PUT, and the other write methods).

Authentication Methods

Quick Reference

Required Headers

HeaderRequiredDescription
blox-api-keyAlwaysYour API key (secret)
Content-TypeIf the request has a bodySet it to application/json
SignatureWrite requestsThe RFC 9421 cryptographic signature
Signature-InputWrite requestsThe metadata of the signature
Content-DigestIf the request has a bodyThe RFC 9421 digest of the request body

Example Request (Read-only)

curl "https://api.blox.my/v1/health" \
  -H "blox-api-key: YOUR_API_KEY"

Next Steps

  1. Get API Keys. To enable access, contact the BLOX team.
  2. Learn request signing to make your API calls secure.
  3. Test in Sandbox before you use production.