Morphosis HMAC v2 authenticates every public Payment API request. Webhook delivery still uses callback HMAC v1 — see Webhooks.

Morphosis HMAC v2

Each API request proves possession of a merchant signing secret without sending that secret over the network. Generate the signature from the exact request bytes before transmission.

Required headers

POST /v2/payments also requires Idempotency-Key. That header is signed as the sixth canonical line. GET /v2/payments/{payment_id} must not send Idempotency-Key; if present, the gateway returns 400. Duplicate values for any signed header are rejected.

Canonical request

Join these seven values with a single line-feed character and no trailing LF:
Line rules:
  1. Version string v2
  2. Uppercase HTTP method
  3. Raw path and query exactly as transmitted (/v2/payments, not a full URL)
  4. Unix timestamp in whole seconds
  5. Unique nonce
  6. Raw Idempotency-Key for create, or an empty line for retrieve
  7. Lowercase hexadecimal SHA-256 of the exact raw request body bytes
Encode the canonical string as UTF-8. Sign with HMAC-SHA-256. Encode the signature as unpadded base64url.

Compute the signature

JSON formatting changes the body bytes. Serialize once, sign those bytes, and send the same bytes. Do not parse and reserialize the body after signing. Body digests use lowercase hex — not base64url.

Retrieve signing

For GET /v2/payments/{payment_id}:
  • Omit Idempotency-Key
  • Use an empty sixth canonical line
  • Hash an empty body (SHA-256 of zero bytes) as the seventh line

Replay resistance

  • Generate a cryptographically random nonce for every request.
  • Send current Unix time in whole seconds.
  • Never reuse a nonce, even when another field changes.
  • Keep merchant clocks synchronized.
  • Compare signatures in constant time in any verification tooling.

Credential handling

Store the key identifier and signing secret in a managed secret store or local environment variables excluded from version control. Never place a live secret in browser code, mobile applications, logs, screenshots, support tickets, or documentation.