Required Headers
Include both of the following headers on every authenticated API call:Your API key is generated inside the Finrock control panel under API Users. Each API user has its own key and its own associated RSA public key that you upload during setup.
JWT Payload Fields
Build the JWT payload using the following fields before signing. Every field is required on every request.string
required
The URI path of the request being made, without the domain. For example:
/dac/v1/transactions or /dac/v1/wallets.string
required
A unique value for this specific request. Use a UUID v4 or a cryptographically random string. Never reuse a nonce — the platform rejects requests with a previously seen nonce.
integer
required
The time at which the JWT was issued, expressed as seconds since the Unix Epoch (e.g.
1715933300). Use your system clock and ensure it is synchronised with NTP.integer
required
The expiry time of the JWT, expressed as seconds since the Unix Epoch. This value must be less than
iat + 30. Tokens with a longer window are rejected with 401.string
required
Your API key — the same UUID value you pass in the
x-api-key header. For example: 4466c45a-7b28-4c50-a0f7-198f8d7f34c5.string
required
The hex-encoded SHA-256 hash of the raw HTTP request body. For GET requests with no body, hash an empty string. For POST requests, hash the raw JSON string exactly as it will be sent — before any encoding or transformation.
Computing the bodyHash
ThebodyHash is the lowercase hex-encoded SHA-256 digest of the raw request body string. For requests with no body (such as GET requests), compute the hash of an empty string "".
Example — POST request body:
Generating an RSA-4096 Key Pair
You need an RSA-4096 key pair to sign your JWTs. Generate one locally with OpenSSL, then upload the public key to the Finrock control panel when creating your API user. Keep the private key secret and never share it.private_key.pem— used by your application to sign JWTs. Never expose this file.public_key.pem— uploaded to the Finrock control panel so the platform can verify your signatures.