Skip to main content
POST
Fx execute

Authorizations

ApiKey
string
header
required

The service account's API key.

Nonce
string
header
required

A GUID, single-use. A replayed nonce is rejected.

Signature
string
header
required

Base64 RSA/SHA-256 (PKCS#1 v1.5) signature over the canonical string: METHOD, path, canonical query, Timestamp, Nonce, API secret and the lowercase hex SHA-256 of the raw body, joined with LF. Sign the PUBLIC path exactly as called (e.g. /v1/webhooks), not any internal path.

Timestamp
string
header
required

Unix seconds. Rejected outside the server's tolerance window.

Body

application/json
previewId
string<uuid> | null
scaOperationId
string<uuid> | null
totpCode
string | null

Response

OK

reference
string
required
transactionId
integer<int64>
required