DOKU Malaysia API Reference
Home
Products
Products
  • Checkout
  • Payment
  • Cards Payment
DOKU Docs
Home
Products
Products
  • Checkout
  • Payment
  • Cards Payment
DOKU Docs
  1. Technical Reference
  • Introduction
  • Getting Started
    • Create Account
    • Authentication & API Keys
    • Make your first API call
  • Checkout
    • Overview
    • Create Checkout
      POST
    • Retrieve Checkout Status
      GET
  • Payment
    • Overview
    • Create Payment
    • Get Bank List - FPX
    • Retrieve Payment Status
  • Cards Payment
    • Overview
    • Payment Form
      • Request Payment
    • Host-to-Host Payment
      • Check Three D Secure
      • Charge Payment
      • Capture Authorized Payment
    • Request Refund
    • Unbind Token
    • Check Status
  • Notification
    • Overview
    • Setup Notification URL
    • Retry Notification
    • Sample Notification - Global
    • Sample Notification - Cards
  • Technical Reference
    • Authentication & Integrity
    • Idempotency
    • Data Type
    • Order & Transaction Status
    • Postman Collection
    • Response Code
      • Error Code
    • API Version
      • Create Checkout
      • Create Payment
      • Get Bank List - FPX
      • Retrieve Checkout
      • Retrieve Payment
    • Signature
      • Signature - Global
        • Signature
      • Signature - Cards Payment API
        • Signature Component from Request Header
        • Signature Component from Response Header
        • Signature from API Get Method
        • Sample Code
  1. Technical Reference

Authentication & Integrity

Authentication#

To ensure secure access to DOKU’s APIs, all requests must be authenticated using an API key and Each environment uses its own set of API keys. Don’t expose this key on a website or embed it in a mobile application.
We require all API calls to include a valid authentication token checks. Think of this as the identity card and security seal of every request. With proper authentication, we can verify who is calling our API.

Integrity#

Several API might required advance security in terms of integrity request and response. This aspect ensuring the data has not been tempered with or altered during transit. This keeps your transactions safe from tampering and unauthorized access.
The integrity will be implement on the "Signature" attribute on request or response headers. Follow this section to know how to generate and how it works "Signature Headers".
Modified at 2026-02-02 03:38:06
Previous
Technical Reference
Next
Idempotency
Built with