Security
Authentication
Use the authentication method defined by each API product. The products do not share one invented authentication scheme.
Public Embed API
Approved public routes are unauthenticated where safe and remain rate-limited and visibility-filtered.
White Label Organization API
Public reads use a verified domain and public or campaign key. Private server requests use a domain-bound version 2 HMAC signature, timestamp and fresh nonce.
Reseller API
Reseller portal operations use an authenticated SparkGlim session and enforce account membership and permissions.
Organization HMAC signature
Join v2, the approved domain, idempotency key, optional campaign credential, timestamp, nonce, uppercase method, pathname, canonical query and SHA-256 body hash with a period. Compute HMAC-SHA256 over that string using the account secret and encode the result as lowercase hexadecimal.
v2.domain.idempotencyKey.campaignKey.timestamp.nonce.METHOD.pathname.canonicalQuery.bodyHash- Use the full path, including
/api/white-label/v1, without a query string or trailing slash. - Sort query pairs by key, then value using JavaScript
localeCompare. Encode each key and value withencodeURIComponentand join pairs with&. - For GET and HEAD, hash an empty string. For JSON mutations, hash the exact UTF-8 request body sent to the server.
- Send
x-white-label-domain,x-white-label-signature-version: 2,x-white-label-key-id,x-white-label-timestamp(milliseconds),x-white-label-nonceandx-white-label-signature. Generate a new nonce for each signed request. - For endpoints requiring idempotency, send
X-Idempotency-Keyand retain it for retries of the same business operation. A fresh signing nonce and a stable idempotency key serve different purposes.
Expired, replayed, disabled or insufficiently scoped credentials are rejected. Never put the secret or signing operation in a public client.