Skip to main content
proofage/php-sdk is the framework-neutral PHP client: request signing, every endpoint, streaming media downloads and webhook verification. Its only runtime dependencies are PHP 8.1+, ext-curl, ext-json and the psr/http-message interfaces. On Laravel, use the Laravel SDK, which wraps this one.

Install

Configure

Create a verification

Methods return the decoded JSON as an array.

Read results

downloadMediaTo() streams an image to a file and only writes it after a 2xx.

Receive webhooks

Give the verifier the workspace’s active secret key: webhooks are signed with it. The timestamp tolerance is 300 seconds (the constructor’s third argument). Failures carry a code: MISSING_SIGNATURE, MISSING_TIMESTAMP, MISSING_AUTH_CLIENT, INVALID_AUTH_CLIENT, TIMESTAMP_TOO_OLD or INVALID_SIGNATURE.

Everything else

Errors and retries

A GET is retried after a transport failure, a 429 or a 5xx. A POST is retried only when the connection failed before sending, or on a 429 with Retry-After; a 5xx or a timeout on a POST is thrown at once, because the server may already have acted. Dumping a client or an exception with print_r() or var_dump() never shows the secret key.