# Calculation of Signature

**URL:** <https://community.rapyd.net/t/calculation-of-signature/288>\
**Category:** 🙋🏽‍♀️🙋🏽‍♂️ Ask Questions\
**Created:** [May 25, 2021, 6:59pm UTC](https://community.rapyd.net/t/calculation-of-signature/288 "2021-05-25T18:59:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![drew.harris](https://sea2.discourse-cdn.com/flex016/user_avatar/community.rapyd.net/drew.harris/32/1259_2.png) [@drew.harris](https://community.rapyd.net/u/drew.harris)\
**Post date:** [May 25, 2021, 6:59pm UTC](https://community.rapyd.net/t/calculation-of-signature/288/1 "2021-05-25T18:59:25Z")

</div>

Here is a great doc on the [Request Signature](https://docs.rapyd.net/build-with-rapyd/reference/message-security#request-signatures) that will help.

Alternatively here is our sample [Postman Collection](https://docs.rapyd.net/build-with-rapyd/docs/make-your-first-api-call) that you can download and look at the Pre-request Script.

```
var timestamp = (Math.floor(new Date().getTime() / 1000) - 10).toString();
postman.setGlobalVariable("rapyd_request_timestamp", timestamp);

var signature_salt = CryptoJS.lib.WordArray.random(12);
postman.setGlobalVariable("rapyd_signature_salt", signature_salt);

var body = '';
if (JSON.stringify(request.data) !== '{}' && request.data !== '' && typeof request.data !=='object' ){
body = JSON.stringify(JSON.parse(request.data));
}

var secret = pm.environment.get('rapyd_secret_key');
var to_sign = request.method.toLowerCase() + request.url.replace('{{base_uri}}','/v1') + signature_salt + timestamp + pm.environment.get('rapyd_access_key') + secret + body;

console.log("to_sign " + to_sign);
var rapyd_signature = CryptoJS.enc.Hex.stringify(CryptoJS.HmacSHA256(to_sign, secret));
rapyd_signature = CryptoJS.enc.Base64.stringify(CryptoJS.enc.Utf8.parse(rapyd_signature));
console.log("rapyd_signature " + rapyd_signature);
postman.setGlobalVariable("rapyd_signature", rapyd_signature);
```

---

<div class="post-metadata">

**Author:** ![CharlesDorsett](https://sea2.discourse-cdn.com/flex016/user_avatar/community.rapyd.net/charlesdorsett/32/47_2.png) [@CharlesDorsett](https://community.rapyd.net/u/CharlesDorsett)\
**Post date:** [May 26, 2021, 2:39pm UTC](https://community.rapyd.net/t/calculation-of-signature/288/2 "2021-05-26T14:39:03Z")

</div>

Note the following points about the signature calculation:

- There is no signature on the API response.
- There is a small difference between the API request signature and the webhook signature: The HTTP method (get, post, put, delete) is present for the API request and not for the webhook.
- You need to run some tests with your Base64 algorithm to determine whether you have all the right settings.

---

<div class="post-metadata">

**Author:** ![Community\_Team](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@Community\_Team](https://community.rapyd.net/u/Community_Team)\
**Post date:** [November 2, 2022, 3:27pm UTC](https://community.rapyd.net/t/calculation-of-signature/288/4 "2022-11-02T15:27:31Z")

</div>

Hi @Berenberfin,

If you have checked the signature request above,

You can follow some of these videos

https://www.youtube.com/embed/IUqDc4Siq70?feature=oembed&wmode=opaque&list=PLZA21iLV3paQnWxnSAHcSI_1yiOILrHqn

or make sure you aren’t catching these mistakes

> [@How to verify Webhook Signature with PHP script](https://community.rapyd.net/t/how-to-verify-webhook-signature-with-php-script/1382/5):
>
> Just an update here - after asking around a lot, I discovered that there are 2 issues that can mess up the string that is hashed: All spaces and other whitespace outside of strings must be removed. Numbers should be sent in strings, not as numbers.

Here’s also our github you can use as well:

> **[GitHub - Rapyd-Samples/accept-payments: Explore top payment methods to learn...](https://github.com/Rapyd-Samples/accept-payments)**
>
> Explore top payment methods to learn how you can build with Rapyd in a single integration offering customers their preferred local payment features. - GitHub - Rapyd-Samples/accept-payments: Explo...
