Skip to content

Getting started ​

This guide walks you through integrating with the DMC Pay v2 API: one-time key setup, authenticating, signing requests, and receiving postbacks.

Environments ​

EnvironmentAPI base URL
Productionhttps://oapi.dmcpay.net
Staginghttps://staging-oapi.dmcpay.net

Make the base URL a config value

The URL is part of every request signature, so a request signed for staging will be rejected by production (and vice versa). Never hard-code one URL across environments.

How an integration fits together ​

  1. Get an access token — POST /api/v2/auth/token with your vendor account email and password. → Authentication
  2. Sign and send a request — e.g. create a deposit with POST /api/v2/transaction/init. → Request signing
  3. Redirect your customer — a deposit returns a transaction_link for the customer to complete payment.
  4. Receive the postback — we POST the final status (SUCCESS / FAILED) to your registered webhook. → Postbacks

One-time setup ​

Generate your RSA keypair ​

Do this yourself, offline. Minimum 2048-bit — anything smaller is rejected.

bash
openssl genrsa -out vendor_private.pem 2048
openssl rsa -in vendor_private.pem -pubout -out vendor_public.pem

Treat vendor_private.pem like a database password

  • Never commit it to git
  • Never put it in a frontend or mobile app
  • Store it in a secret manager (Vault, AWS Secrets Manager, Kubernetes Secret, …)
  • Restrict file permissions: chmod 600 vendor_private.pem

We strongly recommend a separate keypair per environment, so a staging-key compromise can't affect production.

Send us your public key ​

Email your account manager the contents of vendor_public.pem:

txt
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
-----END PUBLIC KEY-----

Once it's uploaded, your v2 endpoints are live.

Send us your server IP addresses ​

Our API only accepts requests from allowlisted IP addresses. Send your account manager the public outbound IPs of every server that will call the API (staging and production). Requests from other IPs are rejected with HTTP 403.

(Optional) Opt in to signed postbacks ​

If you'd like the postbacks we send you to be signed — so you can verify they really came from us — tell your account manager. We'll enable signing for your account and email you our public key.

From then on, postbacks arrive with the same three headers (X-Timestamp, X-Nonce, X-Signature), which you verify against our public key. If you don't opt in, postbacks keep arriving in the existing unsigned format. → Verifying postbacks

Need help? Contact your DMC Pay account manager.