Secure every request and response
Open a protected request, verify who sent it, and return a protected response.
Every protected operation uses HTTPS, a fresh UTC timestamp, and an institutional ECDSA signature in the x-signature header. The message-encryption format, key exchange, request envelope, and decryption sequence are documented in How to Encrypt and Decrypt Data.
Headers on every protected request
Content-Type: application/json
Accept: application/json
x-timestamp: 2026-08-16T10:15:30.123Z
x-signature: <BASE64_SIGNATURE_OF_THE_EXACT_PLAINTEXT>| Header | Type | Required | What it means | How to validate it |
|---|---|---|---|---|
Content-Type | Text | Yes | The request body is JSON. | Require application/json. |
Accept | Text | Yes | The sender expects a JSON response. | Require or accept application/json. |
x-timestamp | UTC date-time text | Yes | The time at which this delivery was created. | Parse it as UTC and enforce the agreed freshness window. |
x-signature | Base64 text | Yes | An ECDSA signature over the exact plaintext JSON bytes. | After the request has been opened using the encryption guide, verify the unchanged UTF-8 plaintext with the sender's P-256 public key. |
The decoded x-signature value is a 64-byte IEEE P1363 signature: 32 bytes for r, followed by 32 bytes for s. Do not send the variable-length ASN.1 DER form returned by some libraries.
Key ownership
Each party keeps its private key secret and shares only its public key.
| Key | Owner | Purpose |
|---|---|---|
| Blinc private key | Blinc | Signs Blinc messages and opens messages addressed to Blinc. |
| Blinc public key | Blinc | Lets an institution verify Blinc signatures and encrypt messages for Blinc. |
| Institution private key | Institution | Opens messages addressed to the institution and signs institution messages. |
| Institution public key | Institution | Lets Blinc encrypt messages for the institution and verify institution signatures. |
All key pairs use the P-256 elliptic curve. For the exact request body format and the encryption/decryption examples, use How to Encrypt and Decrypt Data. Do not copy encryption details from older pages.
Processing order
- Validate the required HTTP headers and the timestamp.
- Open the request using the encryption procedure in How to Encrypt and Decrypt Data.
- Preserve the exact recovered plaintext and verify
x-signatureagainst it. - Parse the business JSON only after signature verification succeeds.
- Apply the operation's business rules and return the documented result.
Do not log private keys, complete signatures, encrypted payloads, decrypted customer data, or full account identifiers.
Next
Continue with How to Encrypt and Decrypt Data, then open the guide for the operation you are implementing.
Updated 3 days ago