IP2 platform requires that both the transport layer and message are secured to ensure that your message is not tampered with.

Securing the transport layer.

Both IP2 sandbox and production endpoints use the https protocol with a certificate from a recogonized authority.
If you are calling the IP2 from a web client e.g. if your using web checkout, you are also required to use https.

Securing the message

The intelworld IP2 REST API uses a custom HTTP scheme based on a keyed-HMAC (Hash Message Authentication Code) for authentication. To authenticate a request, you first concatenate selected elements of the request to form a string.You then use your IP2 API Key and API Password to calculate the HMAC signature of that string. Finally, you add this signature as a parameter of the request.

Below are the steps to create the HMAC signature

  1. Concatenate the following items into a string.
    SubscriptionId, AccountId, RequestId, BatchId, Amount, PaymentMethodId, ProductId, CurrencyCode, CountryCode, Memo, ChannelId,Reference
    Please note that the order of concatenation matters
  2. Make the string lowwer case
  3. Create a representation by appending the current date time in UTC timestamp format: dddd, dd MMMM YYYY HH:mm:ss e.g. Thursday, 18 June 2015 07:30:19 GMT
  4. Hash your API Key using base64 MD5
  5. Create an HMAC from the hashed password and then create a signature by hashing the representation
  6. Add the following to your HTTP Headers
Key Value Example
X-ApiAuth-ApiKey [YOUR_API_KEY] 4QTUV/bjPn1KU/gjvNGoCIEFlVkd==
X-Date UTC timestamp Thursday, 18 June 2015 07:30:19 GMT
X-Content-Type Content type application/json; charset=utf-8
Content-MD5 [Explanation from Mubtx] d/oWFSCrf6dkFWY9ixULzg==

Sample code

See below sample code in different programming languages that you can use to send secure messages to IP2 platform

If you have questions about this documetation you can send us an email on or chat with us on skype (Skype names allan.rwakatungu and mubtx)