DOKU Malaysia API Reference
Home
Products
Products
  • Checkout
  • Payment
  • Cards Payment
DOKU Docs
Home
Products
Products
  • Checkout
  • Payment
  • Cards Payment
DOKU Docs
  1. Signature - Cards Payment API
  • Introduction
  • Getting Started
    • Create Account
    • Authentication & API Keys
    • Make your first API call
  • Checkout
    • Overview
    • Create Checkout
      POST
    • Retrieve Checkout Status
      GET
  • Payment
    • Overview
    • Create Payment
    • Get Bank List - FPX
    • Retrieve Payment Status
  • Cards Payment
    • Overview
    • Payment Form
      • Request Payment
    • Host-to-Host Payment
      • Check Three D Secure
      • Charge Payment
      • Capture Authorized Payment
    • Request Refund
    • Unbind Token
    • Check Status
  • Notification
    • Overview
    • Setup Notification URL
    • Retry Notification
    • Sample Notification - Global
    • Sample Notification - Cards
  • Technical Reference
    • Authentication & Integrity
    • Idempotency
    • Data Type
    • Order & Transaction Status
    • Postman Collection
    • Response Code
      • Error Code
    • API Version
      • Create Checkout
      • Create Payment
      • Get Bank List - FPX
      • Retrieve Checkout
      • Retrieve Payment
    • Signature
      • Signature - Global
        • Signature
      • Signature - Cards Payment API
        • Signature Component from Request Header
        • Signature Component from Response Header
        • Signature from API Get Method
        • Sample Code
  1. Signature - Cards Payment API

Signature Component from Response Header

To validate a signature in response header, merchant need to see and check these components.

Component Explanation#

NoComponent NameDescription
1Client-idRetrieved from the Request Header
2Request-idRetrieved from the Request Header
3Response-TimestampRetrieved from the Response Header
4Request-TargetThe path of the endpoint that will be hitted e.g: /credit-card/v1/payment-page.
5DigestEncoded (base64) value of hashed (SHA-256) JSON body. This component only applied for POST Method.

Preparation#

Before validating Signature, merchant need to prepare all the component required.
Set Client-Id, Request-Id, Response-Timestamp.
Use the Client-Id, Request-Id, Response-Timestamp that is placed on the Response Header.
Set Request-Target
The Request-Target is depending on who is sending the request:
1.
When merchant hits DOKU endpoints: The Request-Target is the path of the DOKU API that merchant hits.

Validating Signature#

After merchant send request to DOKU and generate signature in request header, DOKU will send response and generate signature in response header. Then merchant can verify this response is coming from DOKU by Signature.
1.
Arrange the signature components to one component and its value per line by adding escape character. Don't add at the end of the string. Sample of the raw format:
This is how merchant see it:
2.
Calculate HMAC-SHA256 base64 from all the components above using the Secret Key from DOKU Back Office
3.
Put encoded value and prepend HMACSHA256= to the Signature. Sample:
INFO!
To make sure every response API from DOKU, just verify in Signature that you get from Response Header!
Modified at 2026-02-02 04:41:55
Previous
Signature Component from Request Header
Next
Signature from API Get Method
Built with