AggregatorDeveloper PlatformAPI documentationv1
CallbacksValidation
Aggregator API · v1

Validation

Reference guide and implementation details for validation.

Every callback carries key and timestamp. Verify both before you touch the wallet.

ItemDetails
ProveCallback came from Slotsgateway and is not replayed
Windowtimestamp must be within the last 30 seconds
Signaturemd5(timestamp + saltkey)
Fail{ "error": 2, "balance": 0 } — still HTTP 200
SaltUnique per API key; rotate it in the backoffice

Security Requirement Reject callbacks older than 30 seconds with error 2. Always HTTP 200.

Signature

JavaScript

md5(timestamp + saltkey);

PHP

md5($timestamp . $saltkey);

Steps

  1. Read timestamp and key
  2. Reject if older than 30 seconds
  3. Recreate md5(timestamp + saltkey)
  4. Compare with the received key
  5. On mismatch, reject

Invalid signature / timestamp

{
  "error": 2,
  "balance": 0
}