Skip to content
Get Started

Authentication

Farmsky uses API-key authentication. Create and rotate keys in the Console under API Keys. Each key carries scopes that gate which endpoints it can call.

Request headers

HeaderValueRequiredDescription
AuthorizationBearer {CLIENT_ID}:{CLIENT_SECRET}YesYour API client id and secret, joined by a colon. Manage credentials in the Console.
x-api-key{API_KEY}NoAlternative single-value secret key header (equivalent to X-Api-Secret). Never expose it in client-side code.
Content-Typeapplication/jsonYesAll request bodies are JSON unless the endpoint accepts multipart/form-data (file uploads).

Optional request signing (HMAC-SHA256)

For banking-grade integrations you can also sign requests. The base string is ${timestamp}.${nonce}.${METHOD}.${PATH}.${sha256(body)}, HMAC-SHA256 with your secret, hex-encoded. Each nonce is single-use and the timestamp must be within 5 minutes.

HeaderValueDescription
X-Timestamp{UNIX_MS}Request time in unix milliseconds. Must be within a 5-minute window.
X-Nonce{RANDOM}Unique per-request random string (single-use, replay-protected).
X-Signature{HMAC_SHA256}HMAC-SHA256(secret, `${ts}.${nonce}.${METHOD}.${PATH}.${sha256(body)}`), hex.

Scopes

identity:read credit:read credit:write statements:write customer:read customer:write transactions:write