Morphosis HMAC v2 authenticates every public Payment API request. Webhook
delivery still uses callback HMAC v1 — see Webhooks.
Morphosis HMAC v2
Each API request proves possession of a merchant signing secret without sending that secret over the network. Generate the signature from the exact request bytes before transmission.Required headers
POST /v2/payments also requires Idempotency-Key. That header is signed
as the sixth canonical line. GET /v2/payments/{payment_id} must not send
Idempotency-Key; if present, the gateway returns 400.
Duplicate values for any signed header are rejected.
Canonical request
Join these seven values with a single line-feed character and no trailing LF:- Version string
v2 - Uppercase HTTP method
- Raw path and query exactly as transmitted (
/v2/payments, not a full URL) - Unix timestamp in whole seconds
- Unique nonce
- Raw
Idempotency-Keyfor create, or an empty line for retrieve - Lowercase hexadecimal SHA-256 of the exact raw request body bytes
Compute the signature
JSON formatting changes the body bytes. Serialize once, sign those bytes, and
send the same bytes. Do not parse and reserialize the body after signing.
Body digests use lowercase hex — not base64url.
Retrieve signing
ForGET /v2/payments/{payment_id}:
- Omit
Idempotency-Key - Use an empty sixth canonical line
- Hash an empty body (SHA-256 of zero bytes) as the seventh line
Replay resistance
- Generate a cryptographically random nonce for every request.
- Send current Unix time in whole seconds.
- Never reuse a nonce, even when another field changes.
- Keep merchant clocks synchronized.
- Compare signatures in constant time in any verification tooling.