Secure every request and response

Open a protected request, verify who sent it, and return a protected response.

Every protected operation uses HTTPS, a fresh UTC timestamp, and an institutional ECDSA signature in the x-signature header. The message-encryption format, key exchange, request envelope, and decryption sequence are documented in How to Encrypt and Decrypt Data.

Headers on every protected request

Content-Type: application/json
Accept: application/json
x-timestamp: 2026-08-16T10:15:30.123Z
x-signature: <BASE64_SIGNATURE_OF_THE_EXACT_PLAINTEXT>
HeaderTypeRequiredWhat it meansHow to validate it
Content-TypeTextYesThe request body is JSON.Require application/json.
AcceptTextYesThe sender expects a JSON response.Require or accept application/json.
x-timestampUTC date-time textYesThe time at which this delivery was created.Parse it as UTC and enforce the agreed freshness window.
x-signatureBase64 textYesAn ECDSA signature over the exact plaintext JSON bytes.After the request has been opened using the encryption guide, verify the unchanged UTF-8 plaintext with the sender's P-256 public key.

The decoded x-signature value is a 64-byte IEEE P1363 signature: 32 bytes for r, followed by 32 bytes for s. Do not send the variable-length ASN.1 DER form returned by some libraries.

Key ownership

Each party keeps its private key secret and shares only its public key.

KeyOwnerPurpose
Blinc private keyBlincSigns Blinc messages and opens messages addressed to Blinc.
Blinc public keyBlincLets an institution verify Blinc signatures and encrypt messages for Blinc.
Institution private keyInstitutionOpens messages addressed to the institution and signs institution messages.
Institution public keyInstitutionLets Blinc encrypt messages for the institution and verify institution signatures.

All key pairs use the P-256 elliptic curve. For the exact request body format and the encryption/decryption examples, use How to Encrypt and Decrypt Data. Do not copy encryption details from older pages.

Processing order

  1. Validate the required HTTP headers and the timestamp.
  2. Open the request using the encryption procedure in How to Encrypt and Decrypt Data.
  3. Preserve the exact recovered plaintext and verify x-signature against it.
  4. Parse the business JSON only after signature verification succeeds.
  5. Apply the operation's business rules and return the documented result.

Do not log private keys, complete signatures, encrypted payloads, decrypted customer data, or full account identifiers.

Next

Continue with How to Encrypt and Decrypt Data, then open the guide for the operation you are implementing.


Did this page help you?