Get Started
Authentication
Farmsky uses API-key authentication. Create and rotate keys in the Console under API Keys. Each key carries scopes that gate which endpoints it can call.
Request headers
| Header | Value | Required | Description |
|---|---|---|---|
Authorization | Bearer {CLIENT_ID}:{CLIENT_SECRET} | Yes | Your API client id and secret, joined by a colon. Manage credentials in the Console. |
x-api-key | {API_KEY} | No | Alternative single-value secret key header (equivalent to X-Api-Secret). Never expose it in client-side code. |
Content-Type | application/json | Yes | All request bodies are JSON unless the endpoint accepts multipart/form-data (file uploads). |
Optional request signing (HMAC-SHA256)
For banking-grade integrations you can also sign requests. The base string is ${timestamp}.${nonce}.${METHOD}.${PATH}.${sha256(body)}, HMAC-SHA256 with your secret, hex-encoded. Each nonce is single-use and the timestamp must be within 5 minutes.
| Header | Value | Description |
|---|---|---|
X-Timestamp | {UNIX_MS} | Request time in unix milliseconds. Must be within a 5-minute window. |
X-Nonce | {RANDOM} | Unique per-request random string (single-use, replay-protected). |
X-Signature | {HMAC_SHA256} | HMAC-SHA256(secret, `${ts}.${nonce}.${METHOD}.${PATH}.${sha256(body)}`), hex. |
Scopes
identity:read credit:read credit:write statements:write customer:read customer:write transactions:write
Updated recently