Prove
Callback came from Slotsgateway and is not replayed
Window
timestamp must be within the last 30 seconds
Signature
md5(timestamp + saltkey)
Fail
{ "error": 2, "balance": 0 } — still HTTP 200
Salt
Unique per API key; rotate it in the backoffice
Signature
JavaScript
md5(timestamp + saltkey);PHP
md5($timestamp . $saltkey);Steps
- Read
timestampandkey - Reject if older than 30 seconds
- Recreate
md5(timestamp + saltkey) - Compare with the received
key - On mismatch, reject
Invalid signature / timestamp
{
"error": 2,
"balance": 0
}