Reference

The rules every endpoint shares: environments, authentication, response shape and errors.

How it fits together

  1. 1

    Pick the environment

    Demo runs on https://testnet.trustsig.xyz and Production on https://mainnet.trustsig.xyz.

  2. 2

    Sign every request

    Send x-api-key, x-signature and x-timestamp. x-signature is the hex HMAC-SHA256 of timestamp|method|fullUrl|body, keyed with your secret.

  3. 3

    Read success first

    A successful call returns success: true, code: 0 and data. On failure, error is either a string or an object with code and message.

  4. 4

    Look up the code

    Match the numeric code or the HTTP status against Error Codes to find the cause and the fix.

Before you start

Errors come in two formats

401, 404 and 422 return error as a plain string. Business errors on 400 return { code, message }. Your client has to handle both.

Timestamps use two units

x-timestamp is in milliseconds (13 digits) on the calls you make, and in seconds (10 digits) on the webhooks you receive.

Webhooks use a different signature

A webhook signature is "sha256=" + HMAC-SHA256(x-timestamp + "." + JSON.stringify(data)), computed over the data object only.

How to verify a webhook

Not every code is confirmed yet

Codes marked VERIFIED were tested against testnet. Treat the rest as examples until the backend team confirms them.