Signature Generation
To ensure the security of transactions, iPaymu requires a signature header in every API request.
API ENVIRONMENT
Base URL
https://sandbox.ipaymu.com/api/v2Use credentials from the selected environment. Sandbox and Production credentials are separate.
To ensure the security of transactions, iPaymu requires a signature header in every API request. This signature is generated using your API Key and request details. Get your VA and API Key from the Integration menu in Production or Sandbox for the selected environment; generate the signature for each request instead of copying it from the dashboard.
How to Generate Signature
Signature Generation Process Flow
5 steps to construct and hash API request signatures
Prepare Signature Inputs
Prepare HTTP Method (POST/GET), VA Number, Body Request JSON, and your API Key.
Hash Request Body (SHA-256)
Stringify request body JSON and compute SHA-256 hash (lowercase hex format).
Construct String to Sign
Concat string using colon format: Method + ":" + VA + ":" + BodyHash + ":" + APIKey
Generate HMAC-SHA256
Compute HMAC-SHA256 signature from String to Sign using API Key as secret key.
Attach HTTP Request Header
Include generated signature string in "signature" HTTP request header.
The signature is generated using HMAC-SHA256 hashing.
Formula
String to Sign = Method + ":" + VA + ":" + RequestBody + ":" + APIKey
Signature = HMAC-SHA256(String to Sign, APIKey)Components
- Method: HTTP Method (e.g.,
GET,POST). - VA: Your Virtual Account number from the Integration menu.
- RequestBody:
- For GET requests: The JSON stringified query parameters.
- For POST requests: The SHA256 hash of the JSON body.
- APIKey: Your iPaymu API Key from the Integration menu in the same environment as the VA. Do not send the API Key as the
signatureheader.
Example Implementation
const crypto = require('crypto-js');
// Configuration
const apiKey = 'YOUR_API_KEY';
const va = 'YOUR_VA';
const method = 'POST'; // or 'GET'
// For POST Request Body
const body = {
product: ['T-Shirt'],
qty: ['1'],
price: ['100000'],
returnUrl: 'https://your-website.com/thank-you',
notifyUrl: 'https://your-website.com/notify',
cancelUrl: 'https://your-website.com/cancel',
referenceId: 'ID1234'
};
// 1. Stringify the body
const bodyJson = JSON.stringify(body);
// 2. Hash the body (SHA256)
const bodyHash = crypto.SHA256(bodyJson).toString(crypto.enc.Hex);
// 3. Construct String to Sign
const stringToSign = `${method}:${va}:${bodyHash}:${apiKey}`;
// 4. Generate Signature (HMAC-SHA256)
const signature = crypto.HmacSHA256(stringToSign, apiKey).toString(crypto.enc.Hex);
console.log('Signature:', signature);Ensure that the order of parameters in your JSON body matches exactly what you send in the request. It is recommended to sort keys alphabetically if your JSON serializer does not guarantee order, although iPaymu typically expects the raw string used in the request body.
Using the Signature
Once generated, include the signature in your request header:
signature: <generated_signature>
va: <your_va>
timestamp: <current_timestamp>