Appearance
Getting started
This guide walks you through integrating with the DMC Pay v2 API: one-time key setup, authenticating, signing requests, and receiving postbacks.
Environments
| Environment | API base URL |
|---|---|
| Production | https://oapi.dmcpay.net |
| Staging | https://staging-oapi.dmcpay.net |
Make the base URL a config value
The URL is part of every request signature, so a request signed for staging will be rejected by production (and vice versa). Never hard-code one URL across environments.
How an integration fits together
- Get an access token —
POST /api/v2/auth/tokenwith your vendor account email and password. → Authentication - Sign and send a request — e.g. create a deposit with
POST /api/v2/transaction/init. → Request signing - Redirect your customer — a deposit returns a
transaction_linkfor the customer to complete payment. - Receive the postback — we POST the final status (
SUCCESS/FAILED) to your registered webhook. → Postbacks
One-time setup
Generate your RSA keypair
Do this yourself, offline. Minimum 2048-bit — anything smaller is rejected.
bash
openssl genrsa -out vendor_private.pem 2048
openssl rsa -in vendor_private.pem -pubout -out vendor_public.pemTreat vendor_private.pem like a database password
- Never commit it to git
- Never put it in a frontend or mobile app
- Store it in a secret manager (Vault, AWS Secrets Manager, Kubernetes Secret, …)
- Restrict file permissions:
chmod 600 vendor_private.pem
We strongly recommend a separate keypair per environment, so a staging-key compromise can't affect production.
Send us your public key
Email your account manager the contents of vendor_public.pem:
txt
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
-----END PUBLIC KEY-----Once it's uploaded, your v2 endpoints are live.
Send us your server IP addresses
Our API only accepts requests from allowlisted IP addresses. Send your account manager the public outbound IPs of every server that will call the API (staging and production). Requests from other IPs are rejected with HTTP 403.
(Optional) Opt in to signed postbacks
If you'd like the postbacks we send you to be signed — so you can verify they really came from us — tell your account manager. We'll enable signing for your account and email you our public key.
From then on, postbacks arrive with the same three headers (X-Timestamp, X-Nonce, X-Signature), which you verify against our public key. If you don't opt in, postbacks keep arriving in the existing unsigned format. → Verifying postbacks
