WAIJA

Callbacks / Validation

Callback Validation

Every callback carries key and timestamp. Verify both before you touch the wallet.

Prove

Callback came from Slotsgateway and is not replayed

Window

timestamp must be within the last 30 seconds

Signature

md5(timestamp + saltkey)

Fail

{ "error": 2, "balance": 0 } — still HTTP 200

Salt

Unique per API key; rotate it in the backoffice

Signature

JavaScript

md5(timestamp + saltkey);

PHP

md5($timestamp . $saltkey);

Steps

  1. Read timestamp and key
  2. Reject if older than 30 seconds
  3. Recreate md5(timestamp + saltkey)
  4. Compare with the received key
  5. On mismatch, reject

Invalid signature / timestamp

{
  "error": 2,
  "balance": 0
}