Reference
The rules every endpoint shares: environments, authentication, response shape and errors.
How it fits together
- 1
Pick the environment
Demo runs on https://testnet.trustsig.xyz and Production on https://mainnet.trustsig.xyz.
- 2
Sign every request
Send x-api-key, x-signature and x-timestamp. x-signature is the hex HMAC-SHA256 of timestamp|method|fullUrl|body, keyed with your secret.
- 3
Read success first
A successful call returns success: true, code: 0 and data. On failure, error is either a string or an object with code and message.
- 4
Look up the code
Match the numeric code or the HTTP status against Error Codes to find the cause and the fix.
Related pages
Before you start
Errors come in two formats
401, 404 and 422 return error as a plain string. Business errors on 400 return { code, message }. Your client has to handle both.
Timestamps use two units
x-timestamp is in milliseconds (13 digits) on the calls you make, and in seconds (10 digits) on the webhooks you receive.
Webhooks use a different signature
A webhook signature is "sha256=" + HMAC-SHA256(x-timestamp + "." + JSON.stringify(data)), computed over the data object only.
Not every code is confirmed yet
Codes marked VERIFIED were tested against testnet. Treat the rest as examples until the backend team confirms them.
