How to Generate and Verify a Signature

📘

Prerequisite

You must generate a 256-bit elliptic curve keypair (EC-256), also known as NIST P-256, secp256r1, or prime256v1, and share the public key with Blinc.

The private key must be generated and securely stored in PKCS#8 format within your environment. Never share the private key with Blinc.

We recommend using separate keypairs for test and live/production environments.

For a Blinc request that requires a signature, sign its plaintext JSON payload before encryption. Send the signature in the x-signature header.

Signing requirements

ItemRequirement
AlgorithmECDSA with SHA-256
CurveNIST P-256 (secp256r1)
SignatureBase64-encoded, 64-byte IEEE P1363 (32-byte r followed by 32-byte s)
Public keyBase64-encoded X.509 SubjectPublicKeyInfo DER bytes registered with Blinc
Private keyMatching ECDSA P-256 private key, stored securely in your system and never shared with Blinc
MessageUTF-8 bytes of compact JSON converted to uppercase using locale-independent casing

Keep the private key on your backend. Share only the public key with Blinc, without PEM header or footer lines. Use a separate key pairs for sandbox and production.

//Sample public key
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE3G+eSLh2rQ6zxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxdQpCOOJw==

Build the message to sign

Start with the plaintext object. This generic example uses a single key1/value1 pair. Serialize it as a compact JSON, preserving the property order:

{"key1":"value1"}

Convert the entire JSON string to uppercase, then encode it as UTF-8:

{"KEY1":"VALUE1"}

Sign those bytes with your private key using ECDSA P-256 and SHA-256. Base64-encode the P1363 signature.

Send the request

Send Content-Type: application/json and x-signature: <Base64 P1363 signature> in the request header, on a request that requires signing.

Sample Code Snippet for generating a signature

using System.Security.Cryptography;
using System.Text;
using System.Text.Json;

var request = new { key1 = "value1" };
var message = JsonSerializer.Serialize(request).ToUpperInvariant();
using var signer = ECDsa.Create(ECCurve.NamedCurves.nistP256);
signer.ImportPkcs8PrivateKey(Convert.FromBase64String(privateKeyBase64), out _);
var signature = signer.SignData(Encoding.UTF8.GetBytes(message), HashAlgorithmName.SHA256);
var signatureBase64 = Convert.ToBase64String(signature);

Verifing a signature

To verify a signed payload, repeat the compact-JSON, uppercase, and UTF-8 steps on the plaintext. Decode the Base64 signature and verify its P1363 bytes with blinc's public key using ECDSA P-256 with SHA-256. Reject the request if verification fails.

Sample Code snippet for verifing a signature

using System.Security.Cryptography;
using System.Text;

static bool Verify(string compactJson, string signatureBase64, string publicKeyBase64)
{
    try
    {
        byte[] signature = Convert.FromBase64String(signatureBase64);
        if (signature.Length != 64) return false;
        using var verifier = ECDsa.Create(ECCurve.NamedCurves.nistP256);
        verifier.ImportSubjectPublicKeyInfo(Convert.FromBase64String(publicKeyBase64), out _);
        if (verifier.KeySize != 256) return false;
        return verifier.VerifyData(
            Encoding.UTF8.GetBytes(compactJson.ToUpperInvariant()),
            signature,
            HashAlgorithmName.SHA256);
    }
    catch (Exception error) when (error is FormatException or CryptographicException or ArgumentException)
    {
        return false;
    }
}



Did this page help you?