1. Examples of encryption and signature
English
  • Chinese
  • English
  • Open API Documentation
  • Payin
    • Payin Order - General
    • Payin Order - India
    • Payin Order - Philippines
    • Payin Order - Indonesia
    • Payin Order - Vietnam
    • Payin Order - Cryptocurrency
    • Payin Order - China
    • Payin Order - Malaysia
    • Payin Order - Pakistan
    • Payin Order - Thailand
  • Payout
    • Payout Order - General
    • Payout Order - India
    • Payout Order - Philippines
    • Payout Order - Indonesia
    • Payout Order - Vietnam
    • Payout Order - Cryptocurrency
    • Payout Order - Malaysia
    • Payout Order - Pakistan
    • Payout Order - Thailand
  • Callback Notification
    • Callback Description
    • Collection Callback
    • Payout Callback
  • Query API
    • Collection Order Query
    • Payout Order Query
    • Wallet Query
  • Examples of encryption and signature
    • Go Language Encryption and Signature Example
    • Python Encryption and Signature Example
    • PHP encryption and signature example
    • Node.js encryption and signature example
    • Environment variables and request body JSON example
    • Java encryption and signature example
  • Other instructions
    • Response Status Description
    • Order Status Description
    • Payment Method List
    • Bank Code List
    • Checkout iframe Copy Function Support Description
    • Backend Login Instructions
  1. Examples of encryption and signature

Node.js encryption and signature example

Dependencies#

Uses the Node.js standard library (crypto), no additional dependencies required.

Full Code#

Usage Instructions#

1.
Generate Signature: Use the generateSignature() method and pass in HTTP method, path, timestamp, nonce, and raw JSON body
2.
Encrypt Request Body: Use the encryptBody() method and pass in raw JSON, App ID, and apiDataKey
3.
Sort Query String: Use the sortQueryString() method to sort query parameters
4.
Generate Nonce: Use the generateNonce() method to generate a random string

Notes#

The body used in the signature must always be the original JSON string before encryption (even when X-Enc = aes-gcm-v1 is set)
apiDataKey must be a Base64-encoded 32-byte key
The timestamp must be a Unix timestamp in milliseconds (13-digit number)
Content-Type: use application/octet-stream for encrypted requests, and application/json for plaintext
In Node.js, cipher.getAuthTag() can only be retrieved after calling final()
Modified at 2026-05-29 14:27:44
Previous
PHP encryption and signature example
Next
Environment variables and request body JSON example
Built with