๐
Signed requests
Every v2 call is signed with your RSA key over method, URL, timestamp, nonce and payload. Replays and cross-environment reuse are rejected.
How signing works
Accept bank-transfer and DuitNow QR deposits, send withdrawals, and receive signed postbacks โ over a request-signed v2 API.

| Environment | API base URL |
|---|---|
| Production | https://oapi.dmcpay.net |
| Staging | https://staging-oapi.dmcpay.net |
Build and test against staging first, then switch the base URL (and your keypair) for production.