Validation
Reference guide and implementation details for validation.
Every callback carries key and timestamp. Verify both before you touch the wallet.
| Item | Details |
|---|---|
| Prove | Callback came from Slotsgateway and is not replayed |
| Window | timestamp must be within the last 30 seconds |
| Signature | md5(timestamp + saltkey) |
| Fail | { "error": 2, "balance": 0 } — still HTTP 200 |
| Salt | Unique per API key; rotate it in the backoffice |
Security Requirement Reject callbacks older than 30 seconds with error 2. Always HTTP 200.
Signature
JavaScript
md5(timestamp + saltkey);
PHP
md5($timestamp . $saltkey);
Steps
- Read
timestampandkey - Reject if older than 30 seconds
- Recreate
md5(timestamp + saltkey) - Compare with the received
key - On mismatch, reject
Invalid signature / timestamp
{
"error": 2,
"balance": 0
}