DOKU Malaysia API Reference
Home
Products
Products
  • Checkout
  • Payment
  • Cards Payment
DOKU Docs
Home
Products
Products
  • Checkout
  • Payment
  • Cards Payment
DOKU Docs
  1. Signature - Global
  • Introduction
  • Getting Started
    • Create Account
    • Authentication & API Keys
    • Make your first API call
  • Checkout
    • Overview
    • Create Checkout
      POST
    • Retrieve Checkout Status
      GET
  • Payment
    • Overview
    • Create Payment
    • Get Bank List - FPX
    • Retrieve Payment Status
  • Cards Payment
    • Overview
    • Payment Form
      • Request Payment
    • Host-to-Host Payment
      • Check Three D Secure
      • Charge Payment
      • Capture Authorized Payment
    • Request Refund
    • Unbind Token
    • Check Status
  • Notification
    • Overview
    • Setup Notification URL
    • Retry Notification
    • Sample Notification - Global
    • Sample Notification - Cards
  • Technical Reference
    • Authentication & Integrity
    • Idempotency
    • Data Type
    • Order & Transaction Status
    • Postman Collection
    • Response Code
      • Error Code
    • API Version
      • Create Checkout
      • Create Payment
      • Get Bank List - FPX
      • Retrieve Checkout
      • Retrieve Payment
    • Signature
      • Signature - Global
        • Signature
      • Signature - Cards Payment API
        • Signature Component from Request Header
        • Signature Component from Response Header
        • Signature from API Get Method
        • Sample Code
  1. Signature - Global

Signature

Calculation DOKU Global API Signature#

Components#

DOKU Secret Key: is a unique string for each API Key created at DOKU. The secret key is like a password, and is transmitted only as part of the calculated signature.
Timestamp: The header time was generated (UTC ISO 8601 format) when send request or receive response. Used to prevent replay attacks.
Request Path: The path of the endpoint that will be hitted e.g: /v2/payment. NOTE: For the HTTP request from DOKU to merchant server, this will be the path of merchant URL. As for the Webhook Payment Request, this will be the path of merchant Webhook URL.
Digest: Encoded (base64) value of hashed (SHA-256) JSON body. This component only applied for http method POST, PATCH.

Construct The Component#

Define a strict order to construct signature component and separate it with a new line

Request Signature#

Response Signature#

Do & Don't#

Don't deserialized request body to build the digest (e.g: beutify the json), use request body as it is from DOKU.
Don't share secret key to anyone.
Don’t expose secret key on a website or embed it in a mobile application.
Do ensure secret key are encrypted prior to storage.
Modified at 2026-02-02 08:44:26
Previous
Signature
Next
Signature Component from Request Header
Built with