Open API
What should I do if API signature verification fails?
Answer: Confirm that the API Key, API Secret, and base URL belong to the same environment. Then check whether the timestamp is outside the allowed window; whether the Nonce is duplicated; whether the request body is normalized according to the documentation; whether the bodyHash matches; and whether the signature string uses LF line breaks and the correct Base64 encoding. In UAT, compare the normalized request body, bodyHash, and signature string step by step. Do not print the complete Secret in logs.
Can production and UAT credentials be mixed?
Answer: They should not be mixed and generally cannot be mixed. Production and UAT must use separate base URLs, API Keys, API Secrets, callback URLs, and configurations. Logs and test data must also be isolated. Complete integration testing and acceptance in UAT before switching to production credentials.
What should I do if a configured Webhook does not deliver transaction notifications?
Answer: Confirm that the callback URL is accessible over HTTPS. Check the Webhook configuration, event type, signature verification, server response time, and logs. The receiver should return a success response quickly and deduplicate events by event ID or business ID. A Webhook only provides notifications; verify critical statuses through the query API.
What should I do if an API call reports insufficient permissions or invalid credentials?
Answer: Confirm that the business has completed KYB and enabled Open API access, that the API Key and API Secret have not expired or been revoked, and that the request uses the correct production or UAT URL. Also check that the server sends the credentials in the correct request headers. If the issue continues, provide the environment, request time, endpoint path, and response error code, but never submit the complete Secret.