DOKU Malaysia API Reference
Home
Products
Products
  • Checkout
  • Payment
  • Cards Payment
DOKU Docs
Home
Products
Products
  • Checkout
  • Payment
  • Cards Payment
DOKU Docs
  1. Technical Reference
  • Introduction
  • Getting Started
    • Create Account
    • Authentication & API Keys
    • Make your first API call
  • Checkout
    • Overview
    • Create Checkout
      POST
    • Retrieve Checkout Status
      GET
  • Payment
    • Overview
    • Create Payment
    • Get Bank List - FPX
    • Retrieve Payment Status
  • Cards Payment
    • Overview
    • Payment Form
      • Request Payment
    • Host-to-Host Payment
      • Check Three D Secure
      • Charge Payment
      • Capture Authorized Payment
    • Request Refund
    • Unbind Token
    • Check Status
  • Notification
    • Overview
    • Setup Notification URL
    • Retry Notification
    • Sample Notification - Global
    • Sample Notification - Cards
  • Technical Reference
    • Authentication & Integrity
    • Idempotency
    • Data Type
    • Order & Transaction Status
    • Postman Collection
    • Response Code
      • Error Code
    • API Version
      • Create Checkout
      • Create Payment
      • Get Bank List - FPX
      • Retrieve Checkout
      • Retrieve Payment
    • Signature
      • Signature - Global
        • Signature
      • Signature - Cards Payment API
        • Signature Component from Request Header
        • Signature Component from Response Header
        • Signature from API Get Method
        • Sample Code
  1. Technical Reference

Signature

Why Sign API Requests and Responses?#

While HTTPS (TLS) encrypts data in transit and prevents eavesdropping, it primarily ensures confidentiality and basic integrity during the network hop. Adding a signature layer provides additional security guarantees:
Integrity: Guarantees that the request or response content has not been tampered with or altered by any intermediary (e.g., proxy, load balancer, malicious actor) between the sender and the receiver.
Authenticity/Non-Repudiation (Sender): For requests, it cryptographically proves that the request genuinely originated from an authorized client and prevents the client from denying they sent a specific request.
Authenticity/Non-Repudiation (Server): For responses, it cryptographically proves that the response genuinely originated from your API server and has not been forged or altered. This is crucial for critical confirmations.
Tamper Detection: Allows immediate detection if any part of the request or response (body or specific headers) has been modified.
Signature for Cards
Currently Cards will have different signature with other APIs since Cards use different API Specifications
In the future, Cards channel will have the same API Specification with other Channels.
Modified at 2026-02-02 08:44:15
Previous
Retrieve Payment
Next
Signature
Built with