Skip to main content

Transaction Signature

For the purpose of system security, it is required to include the following parameters in the header when sending a transaction request:

HeaderContent
Content-Typetext/plain
X-Transaction-Signature{transaction_signature}

Required Parameters​

  1. Transaction Secret: Obtained from the merchant backend ℹ️Log in to the merchant portal, go to the 'API docking' page to obtain 'QRPh Transaction Secret'
  2. Request Body: Content of the transaction request.

Generation Steps​

  1. Apply the HMAC algorithm to sign (hash) the Request Body using the Transaction Secret as the key.
  2. Encode the resulting signature using base64.
function transcation_signature(string $request_body, string $transaction_secret): string
{
return base64_encode(hash_hmac('sha256', $request_body, $transaction_secret, true));
}