Security

Authentication

Use the authentication method defined by each API product. The products do not share one invented authentication scheme.

Public Embed API

Approved public routes are unauthenticated where safe and remain rate-limited and visibility-filtered.

White Label Organization API

Public reads use a verified domain and public or campaign key. Private server requests use a domain-bound version 2 HMAC signature, timestamp and fresh nonce.

Reseller API

Reseller portal operations use an authenticated SparkGlim session and enforce account membership and permissions.

Organization HMAC signature

Join v2, the approved domain, idempotency key, optional campaign credential, timestamp, nonce, uppercase method, pathname, canonical query and SHA-256 body hash with a period. Compute HMAC-SHA256 over that string using the account secret and encode the result as lowercase hexadecimal.

v2.domain.idempotencyKey.campaignKey.timestamp.nonce.METHOD.pathname.canonicalQuery.bodyHash
  • Use the full path, including /api/white-label/v1, without a query string or trailing slash.
  • Sort query pairs by key, then value using JavaScript localeCompare. Encode each key and value with encodeURIComponent and join pairs with &.
  • For GET and HEAD, hash an empty string. For JSON mutations, hash the exact UTF-8 request body sent to the server.
  • Send x-white-label-domain, x-white-label-signature-version: 2, x-white-label-key-id, x-white-label-timestamp (milliseconds), x-white-label-nonce and x-white-label-signature. Generate a new nonce for each signed request.
  • For endpoints requiring idempotency, send X-Idempotency-Key and retain it for retries of the same business operation. A fresh signing nonce and a stable idempotency key serve different purposes.

Expired, replayed, disabled or insufficiently scoped credentials are rejected. Never put the secret or signing operation in a public client.