← Back to API overview

API Documentation

Complete endpoint reference, authentication and signing rules, constant definitions, and event callbacks to help you integrate fast.

API Call Description

API call description

Host

  • Sandbox:https://api.sandbox.veskre.com
  • Production:https://api.veskre.com

Version

v1

Limit

When calling an API, the same request URL is subject to a concurrency limit: among simultaneous calls only one succeeds, and the rest return error 10004 (currently too many requests, try again later).

Http Method

HTTP GET|POST

Common Header

FieldTypeRequiredDescription
timestamplongYesCurrent UTC timestamp, in UTC+0. If the timestamp is outside the allowed range, the API returns error code 10003 (request time exceeded limit)
signaturestringYesSign the parameters with the signature algorithm to obtain the signature string; see the Sign section.
traceidstringNoUnique request ID, optional; recommended to set the trace ID and keep it unique.

Common Param

FieldTypeRequiredDescription
customer_idlongYesCustomer ID; obtained after the customer is verified on the Global platform.
app_idlongYesApplication ID; created on the Global platform.
keystringYesAuthorization key; created on the Global platform and bound to the application ID.

Sign

Sign the parameters using HMAC-SHA256

Note: distinguish apiKey from "key" in Common Param — they are two different fields. The "key" in Common Param is used for app_id authorization, while signing uses apiKey (the signing secret).

Java

import javax.crypto.Mac;
import javax.crypto.spec.SecretKeySpec;
import java.math.BigInteger;
import java.nio.charset.StandardCharsets;

public class SignatureTest {

    public static String sha256Sign(String apiKey, String data) throws Exception {
        Mac mac = Mac.getInstance("HmacSHA256");
        mac.init(new SecretKeySpec(apiKey.getBytes(StandardCharsets.UTF_8), "HmacSHA256"));
        byte[] hashBytes = mac.doFinal(data.getBytes(StandardCharsets.UTF_8));
        return String.format("%064x", new BigInteger(1, hashBytes));
    }

    public static void main(String[] args) throws Exception {
        String timestamp = "1697696752";
        String param = "{\"min\":0,\"max\":1000}";
        String apiKey = "716aeaeb89a41a9a929096584a244e38";

        String data = param + timestamp;
        String signature = sha256Sign(apiKey, data);
        // Result: 7ce4442d4fcc66513e0d38d696c6478d46cbf738f6dd7ac5fc1e0b9c984f08c5
    }
}

Go

package main

import (
	"crypto/hmac"
	"crypto/sha256"
	"encoding/hex"
	"fmt"
)

func Sha256Sign(apiKey, data string) string {
	h := hmac.New(sha256.New, []byte(apiKey))
	h.Write([]byte(data))
	return hex.EncodeToString(h.Sum(nil))
}

func main() {
	timestamp := "1697696752"
	param := `{"min":0,"max":1000}`
	apiKey := "716aeaeb89a41a9a929096584a244e38"

	data := param + timestamp
	signature := Sha256Sign(apiKey, data)
	fmt.Println(signature)
	// Result: 7ce4442d4fcc66513e0d38d696c6478d46cbf738f6dd7ac5fc1e0b9c984f08c5
}

PHP

<?php

function sha256Sign($apiKey, $data)
{
    $hash = hash_hmac('sha256', $data, $apiKey, true);
    return bin2hex($hash);
}

$timestamp = '1697696752';
$param = '{"min":0,"max":1000}';
$apiKey = '716aeaeb89a41a9a929096584a244e38';

$data = $param . $timestamp;
$signature = sha256Sign($apiKey, $data);
// Result: 7ce4442d4fcc66513e0d38d696c6478d46cbf738f6dd7ac5fc1e0b9c984f08c5

Common error codes

Error codeDescription
10001param error
10002signature error
10003request time exceeded limit
10004currently too many requests, try again later
10005system error