Keys
Every workspace has two kinds of keys, shown in the console on the workspace’s page.
A workspace can hold several secret keys so you can rotate without downtime: any of them signs requests. See Workspaces and keys.
Signing a request
Send two headers on every request:METHODis upper case:POST,GET.pathincludes the version and no host:/v1/verifications.- The query string, when there is one, is appended after a
?, with its parameters sorted by name and encoded as RFC 3986 (spaces as%20, a comma as%2C).GET /v1/verifications?status=approved,declined&limit=20is signed asGET/v1/verifications?limit=20&status=approved%2Cdeclined. - The body is the exact bytes you send. A
GEThas an empty body.
File uploads
Amultipart/form-data request, such as a media upload, is not signed over its raw body. Its canonical string has three lines:
type=selfie:
Code
fields; if you send nested form fields, sort each level the same way.
Creating without a signature
POST /v1/verifications also accepts a request with only X-API-Key, so a page can start a verification with the public key alone. Such a request cannot tie the verification to your user: the API drops external_id and callback_url from it. Create verifications on your backend, signed, whenever you need to know whose verification it is. Every other endpoint requires the signature.
Authentication errors
The body is
{"error": {"code": "…", "message": "…"}}. All codes are on Errors.
When the signature does not match
- Sign the exact bytes you send. Serialise the JSON once, sign that string, and send that string; a client that re-encodes the body after signing changes it.
- Use the path with
/v1and without the host. - Include the query string, with its
?, sorted by parameter name. - Use a secret key of the same workspace as the public key: a test key does not sign for a live workspace.
- Send the signature as lowercase hex.
Keep the secret key secret
- Sign on your server only. Browser and mobile code should call your backend, which calls ProofAge.
- Keep keys in environment variables or a secrets manager, never in source control.
- Rotate by adding a new secret key, deploying it, then deleting the old one. See Workspaces and keys.