1. Introduction
API
English
  • Español
  • English
  • Introduction
    • Kambia API
    • Credentials
    • Authentication
    • Verification
      POST
  • Services
    • Code catalog
    • Payout
      • Notifications
      • Create payout
      • Get payout
    • Direct debit
      • Affiliation
      • Charge
  1. Introduction

Authentication

Authentication is simple and the same for every Kambia service.
👉 You will need your credentials.

Base URL + version#

The Kambia API has two environments and one public version (v1):
1. Development
https://sandbox.kambia.app/v1
2. Production
https://api.kambia.app/v1

Headers#

To verify the authenticity and integrity of each request, send these 3 headers:
HeaderDescription
x-merchant-keyYour public key
x-merchant-signatureHMAC-SHA256 signature of the request
x-merchant-timestampRequest timestamp (in milliseconds)

How to sign the request#

1
Build the string to sign
Concatenate these values, in this order:
FieldDescription
merchant_idYour unique identifier at Kambia
JSON(body)Request body as JSON
timestampRequest timestamp (in milliseconds)
The JSON must be compact (no spaces), with accented letters and ñ as they are, not escaped, just as JSON.stringify produces it.
2
Generate the HMAC-SHA256 signature
Use your private key merchant-secret to generate a hex-encoded HMAC SHA-256:

Examples#

Here are 3 examples of how to generate the authentication headers:
JavaScript
Python
PHP
🤔 Questions?
Send a message to josue@kambia.app and I'll be glad to help.
Modified at 2026-10-02 17:56:35
Previous
Credentials
Next
Verification
Built with