Docs

Cash · Guides

Sign requests with HMAC

Authenticate every Cash API call with X-Client-Id, X-Signature and X-Timestamp.

Every Cash API request is authenticated with an HMAC-SHA256 signature. You get your api_key and api_secret from Monato’s customer success team when your client is created.

Headers

Send these three headers on every request:

Header Value
X-Client-Id Your API key (32 hexadecimal characters)
X-Signature HMAC-SHA256 signature of timestamp + "." + requestBody, using your api_secret, hex-encoded
X-Timestamp Unix timestamp in seconds. It helps prevent replay attacks.

Build the signature

  1. Take the current Unix timestamp in seconds, as a string.
  2. Serialize the request body to a JSON string.
  3. Join them with a dot: timestamp + "." + requestBody.
  4. Compute HMAC-SHA256 of that string with your api_secret and hex-encode the result.
Formula
HMAC-SHA256(timestamp + "." + JSON.stringify(requestBody), api_secret)
Note:

Sign the same body string that you send in the request.

Examples

These examples sign the body of a Create Webhook request.

const crypto = require('crypto');

const timestamp = Math.floor(Date.now() / 1000).toString();
const requestBody = JSON.stringify({
  endpoint_url: "https://your-webhook-endpoint.com/webhooks"
});
const payload = `${timestamp}.${requestBody}`;
const apiSecret = "your_64_character_api_secret_here";

const signature = crypto
  .createHmac('sha256', apiSecret)
  .update(payload)
  .digest('hex');

Send the request

Signed request
curl -X POST "https://dev-api.finco.lat/api/v1/cash/webhooks" \
  -H "Content-Type: application/json" \
  -H "X-Client-Id: 4a8a08f09d37b73795649038408b5f33" \
  -H "X-Signature: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" \
  -H "X-Timestamp: 1705312200" \
  -d '{"endpoint_url":"https://your-webhook-endpoint.com/webhooks"}'

If authentication fails

An invalid X-Client-Id or a signature that does not verify returns 401:

401 Unauthorized
{
  "error": "Unauthorized"
}

Webhooks that Monato sends you are signed too. See Webhook events.