API Signature Authentication
To enhance API security, Interlace supports Strict Access Token Mode, which requires signature authentication when generating or refreshing an access token.
When enabled, signature authentication is required for the following endpoints:
POST /open-api/v3/access-tokenPOST /open-api/v3/refresh-token
Each request must include the following HTTP headers:
X-Timestamp: The request timestamp in seconds (Unix timestamp).X-Signature: The signature generated using the POST body parameters andclient_secret.
Strict Access Token Mode
Strict Access Token Mode is enabled by default for new integrations. If it is not enabled for your integration, contact your Account Manager or Technical Support Engineer to enable it.
If you encounter authentication errors while generating or refreshing an access token, contact your Technical Support Engineer for assistance.
Step 1: Prepare the Timestamp
Obtain the current Unix timestamp (in seconds) and populate it in the X-Timestamp HTTP request header.
Header: X-Timestamp
Example: X-Timestamp: 1678886400
Note: The server will validate this timestamp. Typically, requests with a time deviation (e.g., more than 5 minutes) from the server time will be considered invalid to prevent replay attacks.
Step 2: Construct the String-to-Sign
This is the most critical step and must be followed strictly.
- Collect Parameters: Collect only the parameters from the POST Request Body.
Important: Query parameters in the URL (e.g., parameters after the ?, such as /open-api/v3/resource?debug=true) must not be included in the signature calculation.
-
Sort: Sort all parameters by their keys in lexicographical (dictionary) ascending order (A-Z).
-
Process Parameter Values:
JSON Handling: If a parameter value is a JSON object or array, it must be serialized into a compact JSON string (e.g., without any unnecessary spaces or line breaks).
URL Encoding: All parameter values (including the compact JSON strings from the step above) must be standard URL encoded (Percent-encoding).
-
Concatenate: Join the sorted keys and their encoded values in key=value format, separating each pair with an ampersand (&).
Step 3: Calculate the Signature (HMAC-SHA256)
- Key: Use your
client secret. - Message: Use the String-to-Sign generated in Step 2.
- Algorithm: Use the
HMAC-SHA256algorithm to generate the signature's raw binary digest.
Step 4: Submit the Signature (Base64)
Base64 encode the raw binary digest generated in Step 3.
Populate the X-Signature HTTP request header with the resulting Base64-encoded string.
Updated about 15 hours ago