Required Headers
Attach the following two headers to every authenticated API call:Step 1: Generate an RSA-4096 Key Pair
Finrock requires RSA keys with a minimum length of 4096 bits. Generate your key pair with OpenSSL:private_key.pem— your signing key; you keep this secret and use it to sign JWTspublic_key.pem— the key you upload to the Finrock control panel when creating an API User
Step 2: Register Your Public Key
Log in to the Finrock control panel and navigate to API Users. Create a new API User and upload the contents ofpublic_key.pem. Finrock stores your public key and associates it with the API key UUID that is generated. Copy this UUID — you will use it as both the x-api-key header value and the sub claim in your JWT payload.
Step 3: Build the JWT Payload
Each JWT you send must be freshly generated and scoped to the specific request it authenticates. The JWT payload must include all of the following fields:Computing bodyHash
ThebodyHash field is the lowercase hex-encoded SHA-256 hash of the raw request body string, exactly as it will be sent over the wire. For GET requests or requests with no body, hash an empty string.
Example body:
Compute the hash on the exact byte string you send as the request body, before any encoding or transformation. Do not pretty-print or reorder JSON fields between computing the hash and sending the body.
Step 4: Sign the JWT
Sign the payload with your RSA private key using the RS256 algorithm (RSASSA-PKCS1-v1_5 with SHA-256). The signed JWT is a standard three-part base64url-encoded string. Pass it in theAuthorization header as Bearer <JWT>.
Code Examples
The following examples show how to build and sign the JWT in several languages. Full, runnable source files are available in the official snippet repository at github.com/gofinrock/jwt-snippets.Complete Request Example
The following shows a fully authenticatedcurl request that creates a BTC wallet, illustrating how all authentication pieces come together:
Authentication Checklist
Use this checklist to verify your implementation before going to production:Authentication implementation checklist
Authentication implementation checklist
- RSA key pair generated with a minimum of 4096 bits
- Public key uploaded to the Finrock control panel and API key UUID copied
- Private key stored in a secrets manager, not in source code or environment variables in plain text
- JWT payload includes all six required fields:
uri,nonce,iat,exp,sub,bodyHash -
expis set to less thaniat + 30seconds -
nonceis unique per request (UUID v4 recommended) -
bodyHashis computed from the exact raw body string sent in the request - JWT is signed with RS256 (not HS256 or any other algorithm)
- Both
Authorization: Bearer <JWT>andx-api-keyheaders are present on every authenticated request - JWT is regenerated fresh for each request — do not reuse tokens
Troubleshooting
Nonce reuse errors
Nonce reuse errors
Each request must use a unique
nonce value. Using a UUID v4 generated fresh for each request is the simplest approach. Do not copy nonces from previous requests or log them for reuse.