Risk control callback
The second review of the withdrawal order
$url = "http://*****/withdrawal/order/check";
$header = [
'Content-Type:application/json',
];
$params = [
"data" => [
"amount" => 2.00000000,
"coin_symbol" => "USDT_TRC20",
"address" => "TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi",
"user_id" => "1",
"order_id" => "1394934189494173697",
"timestamp" => 1621493658
],
"sign" => "dLtK+uiPcnxt2ACKMbBqQ6wI5ttAvesOHzK5ybVID1R6hqYPDTkagl7Tsjr5iLJafehcSLTZyJLtCRI8O2CtIWQUUroGXBneHZC486NUi/4FMOQs0FaAgm17pWlbhX5/96cWXXXMVeoe3IZFKaFNYSWaA14v3RcdDU6QDE/9ixGiSJ0DIxm9NKA0+RkbIFbyYeuFn8d63OcjmUhv7tsOE6rKCc3Q2yi7Qe9i6BNAQFYMFATztb18MsxsBHKUxNqklqyVnl0ofETAHmQhfOHLmungOJQnOqAAuwfmRtg50Qci5F+R2mXeqjmIXko/u3E+DLYW1ygDBp3afKZmU4PwmA=="
];
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_POSTFIELDS, $params);
curl_setopt($ch, CURLOPT_HTTPHEADER, $header);
$return = curl_exec($ch);
print_r($return);
var url = "http://*****/withdrawal/order/check"
data := map[string]interface{}{
"data": map[string]string{
"amount":"2.00000000",
"coin_symbol":"USDT_TRC20",
"address":"TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi",
"user_id":"1",
"order_id":"1394934189494173697",
"timestamp":"1621493658",
},
"sign": "OTA8utI8y8G93p7RPCyb4qIilFQ0B4Aq4iUjhaXWK9m2kgektqlHOASDKXT2VE7NPNysrGycYlVfjDR2WGZn1G66phHo3qa9CcCNpG9klOBEuBEMjiVbb/d8AXcxEzvQr9OCwNsikyxonyzLiY/lsNHeGm9cC5eRvlNLdUSVBipH+ajPd0lDHCayZPs1eCMfbm/xnf8e2lfy6z0UPOpHGfyX/0+hz99Ir5Xnx+0sBBzyZZJxKm4ROid5aDv/9m9guILpURae+Yw/IrkYF4uAKGX+/44cBvtTRQSdX76CAOBSiywZa6BAgDYBLRtkAPM+i+vwNzFBovqHUvI+4Ponaw==",
}
dataType, _ := json.Marshal(data)
resp, err := http.Post(url, "application/json", strings.NewReader(string(dataType)))
if err != nil {
fmt.Println(err)
}
defer resp.Body.Close()
body, err := ioutil.ReadAll(resp.Body)
if err != nil {
fmt.Println(err)
}
fmt.Println(string(body))
let HTTP = require('http')
let postData = {
"data": {
"amount":"2.00000000",
"coin_symbol":"USDT_TRC20",
"address":"TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi",
"user_id":"1",
"order_id":"1394934189494173697",
"timestamp":"1621493658",
},
"sign": "OTA8utI8y8G93p7RPCyb4qIilFQ0B4Aq4iUjhaXWK9m2kgektqlHOASDKXT2VE7NPNysrGycYlVfjDR2WGZn1G66phHo3qa9CcCNpG9klOBEuBEMjiVbb/d8AXcxEzvQr9OCwNsikyxonyzLiY/lsNHeGm9cC5eRvlNLdUSVBipH+ajPd0lDHCayZPs1eCMfbm/xnf8e2lfy6z0UPOpHGfyX/0+hz99Ir5Xnx+0sBBzyZZJxKm4ROid5aDv/9m9guILpURae+Yw/IrkYF4uAKGX+/44cBvtTRQSdX76CAOBSiywZa6BAgDYBLRtkAPM+i+vwNzFBovqHUvI+4Ponaw==",
};
let POST_OPTIONS = {
port: 80,
host: "api.xxxx.com",
path: "/withdrawal/order/check",
method: 'POST',
headers: {
"Content-Type": "application/json; charset=utf-8"
}
};
const REQUEST = HTTP.request(POST_OPTIONS,function (res) {
let data = []
res.on('data', chunk => {
data.push(...chunk)
})
res.on('end', () => {
let _date = JSON.parse( new TextDecoder().decode(new Uint8Array(data)))
console.log(_date)
})
});
REQUEST.setTimeout(6000)
REQUEST.write(JSON.stringify(postData), 'utf8')
REQUEST.end()
public static void main() {
String priKey = "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCtdgvcfozY7fe/x6UlXR/Fff8+wX++CiG05YVRafDe90O8y5KJAMZ156TgajEUXSRyKZqASz7iVoMAcu5FqfK1KuOOdjTAg0LFe/twIZvKmAqHcCSS2pjUXk0fTpZEgQ5lmDCK12Mg07YXvr+BeHjF+kBpwRJMPMG/+DGBDYNFNeRSJqWyopt6yyF528soAykHIUQ7TTultJV5IPCrvjRQQrGdJ/QtCdE0vZg+tA09nFN7AqgraU99kIvzyS0sqysj+pP1SJRmTRSGtlVAO3mILfkXOekZl1KD60G7CF+7BIaaW83FPD55tZhAGhnbLMYyiq7OiIyU61LTRcNSaJ0tAgMBAAECggEBAIGgGKcSzxCBbMYdXLV6TPbZ/HeaRGrwyVWUu7cmc0E8CJu6iWvmb2jGzbiCwuCT5luF6ZZ8JKchvU4FlTfsE5r9TQY2IZ/Ht4s65qBaDUEts5iY3kv8HX9+ZSXDJZpV0ztqqsPmx4ZNj+NYwWXwcFiKdb5R8OmV8bgSsnPddD6wFhwewglUOBPRAjropHE4sqk1Vam6q1MlFq5kiekMn/CItyFYFFzST/ruqAtVTp7YIvazAMrfCKH+pvXWk6pYNHZmL/JZey0GglRyJ1nItiqL33X8Lji056FcbAclidq022h/KPLEJpZk6irWqYdqYZeF6YMLHtdZFDkTZ/hXY+UCgYEA5i794UTQ1Kd6K+iui/S8K5H8nGdiXb3+uZ5j5VKYfbRmzXhAdVYisYe8czeTECxhH+MeHgM4tLR4ifx9q60ylvZxl9Fav1p6EaE36YcvGVmpm7Gm3q6QDDBa4gB+X9u7CxCS4LpotV917YS1QvOIF9lnRonSj1zNzFtbXkywrN8CgYEAwOpx/mR40ZvgZxNCq9DsIdrSZYAFFKpw0xy0OtF1PpuwMaREoRabnlVw6Bb3Hofg50XA3JxemzAX6fB92ee+NfXfeL4UtC4vG1K9JyiXHtHq8p9Uw2W03ehIEeNa3xdoRRnLmD4VUpyfL19ViE2+7TM1Gd3TogjDT+AMOCSuq3MCgYBsurPH7gaq/LVT+mRAzgj4l8v4YUlwuGeTbIMJdvt7HXUWB4CDLH3U2CYnUpAQKrZyJok6ahEmIr1xiKggKP7lmmHL8eNo0icpHrtXfzi7Q8Q/PCpzs4dtioXTjaIkS5nNvzVyG/uL+RyuZmpsxrZ5dYM4KbAhchfwORMutxEZhwKBgQC5zpVw4jCEItBmNuTWO+nTScGvxTgfiXIVw+XLaQa2AJoZlhAL34yPWdffko79tv3lgweY9HsimZXO2rU8dbp8mo5c6ydhy8HPXUeWOcAkDSdv/ApWENW9jgYsRIC3swHY3Fl+Dv3Wjce8huQI3mjwaYvRmBhIToxfmHnscVhTBQKBgB9uciEHfz8hMI7ePrPo2PkyK/RbJDm3HnuWE2lFBp7MOUMlh53MXwv4dIRaYMbRrFuN1UIKEFxuKhWwTHSzZJufk/UENrha/81fpj2BoFsAKkEunKeETvaIh6fZSjec16h2+zxbzwkdS6b+yIYkSlaoAxmDYrMtae0C8G4e0YS9";
String pubKey = "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArXYL3H6M2O33v8elJV0fxX3/PsF/vgohtOWFUWnw3vdDvMuSiQDGdeek4GoxFF0kcimagEs+4laDAHLuRanytSrjjnY0wINCxXv7cCGbypgKh3AkktqY1F5NH06WRIEOZZgwitdjINO2F76/gXh4xfpAacESTDzBv/gxgQ2DRTXkUialsqKbesshedvLKAMpByFEO007pbSVeSDwq740UEKxnSf0LQnRNL2YPrQNPZxTewKoK2lPfZCL88ktLKsrI/qT9UiUZk0UhrZVQDt5iC35FznpGZdSg+tBuwhfuwSGmlvNxTw+ebWYQBoZ2yzGMoquzoiMlOtS00XDUmidLQIDAQAB";
rsaSigner signer = new rsaSigner();
Map<String, Object> data = new HashMap<>();
data.put("amount", "2.00000000");
data.put("coin_symbol", "USDT_TRC20");
data.put("address", "TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi");
data.put("user_id", "1");
data.put("order_id", "1394934189494173697");
data.put("timestamp", "1621493658");
try {
Map<String, Object> params = new HashMap<>();
params.put("data", data);
params.put("sign", signer.genSign(data, priKey));
Gson gson = new GsonBuilder().create();
System.out.println("params = " + gson.toJson(params));
String res;
// platform request shop callback API
// res = doPost("http://api.shophost.com/withdrawal/order/check", gson.toJson(params));
// if (null == res) {
// throw new RuntimeException("http error");
// }
// mock response from shop callback API
{
res = """
{
"status":200,
"data":{
"status_code": 200,
"timestamp":1620617260,
"order_id":"202105101123221335892766889804"
},
"sign":"YbRyMoUmsCxLbWopD2JD5EZqkT+pIRARsdTSFo+WyhebOMP/TZ96zV/vy4CYn+9gk6nJ55acFnqSO78N4/uemiOyBgE+a8SaIjutc+kFCWGaCorboy9alFBFUbYPvHvFFKHNFJx19Z2cyv9uceGdOdz09g0OBgp8bTyfkCUNrhbUmut2M2S2ixSH3wSefqUq2SUpohb5hlD6tOsyO3JfZr7M/16aiRGcEye2XglsOMFTO5XRkj4hwHKB+nHacttvuZKnGH67ELyoajCc+ef1DkmzmO3P7vFLIuVtVXQ2FPlXVkzCR/+VesyDOpYogHwqyR1BzCCSzxpbZ/aFc/uANg=="
}
""";
}
System.out.println("response = " + res);
JsonParser jp = new JsonParser();
JsonObject resEle = jp.parse(res).getAsJsonObject();
boolean retSignOK = signer.verifySign(resEle.get("data"), resEle.get("sign").getAsString(), pubKey);
if (!retSignOK) {
throw new RuntimeException("verify response sign fail");
}
} catch (Exception e) {
e.printStackTrace();
}
System.out.println("OK");
}
Example of return result:
{
"status":200,
"data":{
"status_code": 200,
"timestamp":1620617260,
"order_id":"202105101123221335892766889804"
},
"sign":"YbRyMoUmsCxLbWopD2JD5EZqkT+pIRARsdTSFo+WyhebOMP/TZ96zV/vy4CYn+9gk6nJ55acFnqSO78N4/uemiOyBgE+a8SaIjutc+kFCWGaCorboy9alFBFUbYPvHvFFKHNFJx19Z2cyv9uceGdOdz09g0OBgp8bTyfkCUNrhbUmut2M2S2ixSH3wSefqUq2SUpohb5hlD6tOsyO3JfZr7M/16aiRGcEye2XglsOMFTO5XRkj4hwHKB+nHacttvuZKnGH67ELyoajCc+ef1DkmzmO3P7vFLIuVtVXQ2FPlXVkzCR/+VesyDOpYogHwqyR1BzCCSzxpbZ/aFc/uANg=="
}
- 2nd risk control review for merchant withdrawal order API
- Note: The platform assigns a separate risk control public key to the merchant (different from the deposit/withdrawal public key)
HTTP Request
POST The specific callback URL is provided by the merchant to the platform side
request parameters
| parameter name | required | type | description |
|---|---|---|---|
| data | no | string | as follows |
| data.order_id | Yes | string | The unique ID of the merchant transaction (trade_id when withdrawing) |
| data.user_id | yes | string | user the order belongs to |
| data.coin_symbol | yes | string | lowercase coin name, subject to the coin provided by the platform |
| data.address | yes | string | withdrawal address |
| data.amount | yes | decimal(20,8) | withdrawal amount |
| data.timestamp | yes | int | current timestamp in second |
| sign | yes | string | signature, only the parameters in data are signed |
Response parameter description
| parameter name | type | description |
|---|---|---|
| status | int | 200 passed, 2001 awaiting review, 5400 failed signature verification, 5401 time is less than 30s, 5402 order number does not exist, 5001 platform order_id is different, 5002 amount is wrong, 5003 user uid is wrong, 5004 address is wrong, 5005 currency The symbol is wrong, 5006 order rejection, 5007 other, the description information can be expanded by yourself |
| data | jsonObject | |
| data.timestamp | int | current timestamp in second |
| data.status_code | int | order status, same as status value, after 2021-12-10, this parameter is required |
| data.order_id | String | Order Id |
| sign | string | signature - the signature of the content of the data field in the response parameter |
- status=200; the order passed directly
- status in (2001,5400); the order will put into the retry queue. Please return status code of 2001 if the exception happen otherwise the respond wll be categories as rejected order.
- status=other; the order is directly rejected
2nd review for exchange order
$url = "http://*****/exchange/order/check";
$header = [
'Content-Type:application/json',
];
$params = [
"data" => [
"amount" => "2.00000000",
"source_coin" => "eth",
"target_coin" => "usdt_erc20",
"user_id" => "1",
"trade_id" => "1394934189494173697",
"time" => 1621493658
],
"sign" => "dLtK+uiPcnxt2ACKMbBqQ6wI5ttAvesOHzK5ybVID1R6hqYPDTkagl7Tsjr5iLJafehcSLTZyJLtCRI8O2CtIWQUUroGXBneHZC486NUi/4FMOQs0FaAgm17pWlbhX5/96cWXXXMVeoe3IZFKaFNYSWaA14v3RcdDU6QDE/9ixGiSJ0DIxm9NKA0+RkbIFbyYeuFn8d63OcjmUhv7tsOE6rKCc3Q2yi7Qe9i6BNAQFYMFATztb18MsxsBHKUxNqklqyVnl0ofETAHmQhfOHLmungOJQnOqAAuwfmRtg50Qci5F+R2mXeqjmIXko/u3E+DLYW1ygDBp3afKZmU4PwmA=="
];
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_POSTFIELDS, $params);
curl_setopt($ch, CURLOPT_HTTPHEADER, $header);
$return = curl_exec($ch);
print_r($return);
var url = "http://*****/exchange/order/check"
data := map[string]interface{}{
"data": map[string]string{
"amount":"2.00000000",
"source_coin":"eth",
"target_coin":"usdt_erc20",
"user_id":"1",
"trade_id":"1394934189494173697",
"time":"1621493658",
},
"sign": "OTA8utI8y8G93p7RPCyb4qIilFQ0B4Aq4iUjhaXWK9m2kgektqlHOASDKXT2VE7NPNysrGycYlVfjDR2WGZn1G66phHo3qa9CcCNpG9klOBEuBEMjiVbb/d8AXcxEzvQr9OCwNsikyxonyzLiY/lsNHeGm9cC5eRvlNLdUSVBipH+ajPd0lDHCayZPs1eCMfbm/xnf8e2lfy6z0UPOpHGfyX/0+hz99Ir5Xnx+0sBBzyZZJxKm4ROid5aDv/9m9guILpURae+Yw/IrkYF4uAKGX+/44cBvtTRQSdX76CAOBSiywZa6BAgDYBLRtkAPM+i+vwNzFBovqHUvI+4Ponaw==",
}
dataType, _ := json.Marshal(data)
resp, err := http.Post(url, "application/json", strings.NewReader(string(dataType)))
if err != nil {
fmt.Println(err)
}
defer resp.Body.Close()
body, err := ioutil.ReadAll(resp.Body)
if err != nil {
fmt.Println(err)
}
fmt.Println(string(body))
let HTTP = require('http')
let postData = {
"data": {
"amount":"2.00000000",
"source_coin":"eth",
"target_coin":"usdt_erc20",
"user_id":"1",
"trade_id":"1394934189494173697",
"time":"1621493658",
},
"sign": "OTA8utI8y8G93p7RPCyb4qIilFQ0B4Aq4iUjhaXWK9m2kgektqlHOASDKXT2VE7NPNysrGycYlVfjDR2WGZn1G66phHo3qa9CcCNpG9klOBEuBEMjiVbb/d8AXcxEzvQr9OCwNsikyxonyzLiY/lsNHeGm9cC5eRvlNLdUSVBipH+ajPd0lDHCayZPs1eCMfbm/xnf8e2lfy6z0UPOpHGfyX/0+hz99Ir5Xnx+0sBBzyZZJxKm4ROid5aDv/9m9guILpURae+Yw/IrkYF4uAKGX+/44cBvtTRQSdX76CAOBSiywZa6BAgDYBLRtkAPM+i+vwNzFBovqHUvI+4Ponaw==",
};
let POST_OPTIONS = {
port: 80,
host: "api.xxxx.com",
path: "/exchange/order/check",
method: 'POST',
headers: {
"Content-Type": "application/json; charset=utf-8"
}
};
const REQUEST = HTTP.request(POST_OPTIONS,function (res) {
let data = []
res.on('data', chunk => {
data.push(...chunk)
})
res.on('end', () => {
let _date = JSON.parse( new TextDecoder().decode(new Uint8Array(data)))
console.log(_date)
})
});
REQUEST.setTimeout(6000)
REQUEST.write(JSON.stringify(postData), 'utf8')
REQUEST.end()
public static void main() {
String priKey = "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCtdgvcfozY7fe/x6UlXR/Fff8+wX++CiG05YVRafDe90O8y5KJAMZ156TgajEUXSRyKZqASz7iVoMAcu5FqfK1KuOOdjTAg0LFe/twIZvKmAqHcCSS2pjUXk0fTpZEgQ5lmDCK12Mg07YXvr+BeHjF+kBpwRJMPMG/+DGBDYNFNeRSJqWyopt6yyF528soAykHIUQ7TTultJV5IPCrvjRQQrGdJ/QtCdE0vZg+tA09nFN7AqgraU99kIvzyS0sqysj+pP1SJRmTRSGtlVAO3mILfkXOekZl1KD60G7CF+7BIaaW83FPD55tZhAGhnbLMYyiq7OiIyU61LTRcNSaJ0tAgMBAAECggEBAIGgGKcSzxCBbMYdXLV6TPbZ/HeaRGrwyVWUu7cmc0E8CJu6iWvmb2jGzbiCwuCT5luF6ZZ8JKchvU4FlTfsE5r9TQY2IZ/Ht4s65qBaDUEts5iY3kv8HX9+ZSXDJZpV0ztqqsPmx4ZNj+NYwWXwcFiKdb5R8OmV8bgSsnPddD6wFhwewglUOBPRAjropHE4sqk1Vam6q1MlFq5kiekMn/CItyFYFFzST/ruqAtVTp7YIvazAMrfCKH+pvXWk6pYNHZmL/JZey0GglRyJ1nItiqL33X8Lji056FcbAclidq022h/KPLEJpZk6irWqYdqYZeF6YMLHtdZFDkTZ/hXY+UCgYEA5i794UTQ1Kd6K+iui/S8K5H8nGdiXb3+uZ5j5VKYfbRmzXhAdVYisYe8czeTECxhH+MeHgM4tLR4ifx9q60ylvZxl9Fav1p6EaE36YcvGVmpm7Gm3q6QDDBa4gB+X9u7CxCS4LpotV917YS1QvOIF9lnRonSj1zNzFtbXkywrN8CgYEAwOpx/mR40ZvgZxNCq9DsIdrSZYAFFKpw0xy0OtF1PpuwMaREoRabnlVw6Bb3Hofg50XA3JxemzAX6fB92ee+NfXfeL4UtC4vG1K9JyiXHtHq8p9Uw2W03ehIEeNa3xdoRRnLmD4VUpyfL19ViE2+7TM1Gd3TogjDT+AMOCSuq3MCgYBsurPH7gaq/LVT+mRAzgj4l8v4YUlwuGeTbIMJdvt7HXUWB4CDLH3U2CYnUpAQKrZyJok6ahEmIr1xiKggKP7lmmHL8eNo0icpHrtXfzi7Q8Q/PCpzs4dtioXTjaIkS5nNvzVyG/uL+RyuZmpsxrZ5dYM4KbAhchfwORMutxEZhwKBgQC5zpVw4jCEItBmNuTWO+nTScGvxTgfiXIVw+XLaQa2AJoZlhAL34yPWdffko79tv3lgweY9HsimZXO2rU8dbp8mo5c6ydhy8HPXUeWOcAkDSdv/ApWENW9jgYsRIC3swHY3Fl+Dv3Wjce8huQI3mjwaYvRmBhIToxfmHnscVhTBQKBgB9uciEHfz8hMI7ePrPo2PkyK/RbJDm3HnuWE2lFBp7MOUMlh53MXwv4dIRaYMbRrFuN1UIKEFxuKhWwTHSzZJufk/UENrha/81fpj2BoFsAKkEunKeETvaIh6fZSjec16h2+zxbzwkdS6b+yIYkSlaoAxmDYrMtae0C8G4e0YS9";
String pubKey = "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArXYL3H6M2O33v8elJV0fxX3/PsF/vgohtOWFUWnw3vdDvMuSiQDGdeek4GoxFF0kcimagEs+4laDAHLuRanytSrjjnY0wINCxXv7cCGbypgKh3AkktqY1F5NH06WRIEOZZgwitdjINO2F76/gXh4xfpAacESTDzBv/gxgQ2DRTXkUialsqKbesshedvLKAMpByFEO007pbSVeSDwq740UEKxnSf0LQnRNL2YPrQNPZxTewKoK2lPfZCL88ktLKsrI/qT9UiUZk0UhrZVQDt5iC35FznpGZdSg+tBuwhfuwSGmlvNxTw+ebWYQBoZ2yzGMoquzoiMlOtS00XDUmidLQIDAQAB";
rsaSigner signer = new rsaSigner();
Map<String, Object> data = new HashMap<>();
data.put("amount", "2.00000000");
data.put("source_coin", "eth");
data.put("target_coin", "usdt_erc20");
data.put("user_id", "1");
data.put("trade_id", "1394934189494173697");
data.put("time", "1621493658");
try {
Map<String, Object> params = new HashMap<>();
params.put("data", data);
params.put("sign", signer.genSign(data, priKey));
Gson gson = new GsonBuilder().create();
System.out.println("params = " + gson.toJson(params));
String res;
// platform request shop callback API
// res = doPost("http://api.shophost.com/exchange/order/check", gson.toJson(params));
// if (null == res) {
// throw new RuntimeException("http error");
// }
// mock response from shop callback API
{
res = """
{
"status":200,
"data":{
"time":1620617260,
"trade_id":"202105101123221335892766889804"
},
"sign":"YbRyMoUmsCxLbWopD2JD5EZqkT+pIRARsdTSFo+WyhebOMP/TZ96zV/vy4CYn+9gk6nJ55acFnqSO78N4/uemiOyBgE+a8SaIjutc+kFCWGaCorboy9alFBFUbYPvHvFFKHNFJx19Z2cyv9uceGdOdz09g0OBgp8bTyfkCUNrhbUmut2M2S2ixSH3wSefqUq2SUpohb5hlD6tOsyO3JfZr7M/16aiRGcEye2XglsOMFTO5XRkj4hwHKB+nHacttvuZKnGH67ELyoajCc+ef1DkmzmO3P7vFLIuVtVXQ2FPlXVkzCR/+VesyDOpYogHwqyR1BzCCSzxpbZ/aFc/uANg=="
}
""";
}
System.out.println("response = " + res);
JsonParser jp = new JsonParser();
JsonObject resEle = jp.parse(res).getAsJsonObject();
boolean retSignOK = signer.verifySign(resEle.get("data"), resEle.get("sign").getAsString(), pubKey);
if (!retSignOK) {
throw new RuntimeException("verify response sign fail");
}
} catch (Exception e) {
e.printStackTrace();
}
System.out.println("OK");
}
Example of return result:
{
"status":200,
"data":{
"time":1620617260,
"trade_id":"202105101123221335892766889804"
},
"sign":"YbRyMoUmsCxLbWopD2JD5EZqkT+pIRARsdTSFo+WyhebOMP/TZ96zV/vy4CYn+9gk6nJ55acFnqSO78N4/uemiOyBgE+a8SaIjutc+kFCWGaCorboy9alFBFUbYPvHvFFKHNFJx19Z2cyv9uceGdOdz09g0OBgp8bTyfkCUNrhbUmut2M2S2ixSH3wSefqUq2SUpohb5hlD6tOsyO3JfZr7M/16aiRGcEye2XglsOMFTO5XRkj4hwHKB+nHacttvuZKnGH67ELyoajCc+ef1DkmzmO3P7vFLIuVtVXQ2FPlXVkzCR/+VesyDOpYogHwqyR1BzCCSzxpbZ/aFc/uANg=="
}
- 2nd risk control review for merchant withdrawal order API
- Note: The platform assigns a separate risk control public key to the merchant (different from the deposit/withdrawal public key)
- In this API, mechant and platform each need generate their own pair of rsa key
- When sending the request, Platform will use its own privater key to generate a sign, and the mechant will use the platform's public key to verify the sign.
- When mechant respond back to the request from the platform, mechant will use its private key to sign and platform will use merchant's public key to verify the sign
- Please refer back to the Signature Regulations section for the step
HTTP Request
POST The specific callback URL is provided by the merchant to the platform side
request parameters
| parameter name | required | type | description |
|---|---|---|---|
| data | no | string | as follows |
| data.trade_id | yes | string | Merchant-side transaction unique ID |
| data.user_id | yes | string | the user the order belongs to |
| data.source_coin | Yes | string | The source coin must be in lowercase, the coin provided by the platform shall prevail |
| data.target_coin | yes | string | target coin namemust be in lowercase, the coin provided by the platform shall prevail |
| data.amount | yes | decimal(20,8) | exchange amount |
| data.time | yes | int | current timestamp in second |
| sign | yes | string | sign the data in data |
Response parameter description
| parameter name | type | description |
|---|---|---|
| status | int | 200 passed, 2001 pending review, 5400 failed signature verification, 5401 time less than 30s, 5402 order number does not exist, 5001 platform order_id is different, 5002 amount is wrong, 5003 user uid is wrong, 5004 address is wrong, 5005 currency The symbol is wrong, 5006 order rejection, 5007 other, the description information can be expanded by yourself |
| msg | string | state description |
| data | jsonObject | |
| data.time | int | current time |
| data.trade_id | String | Order Id |
| sign | string | signature - the signature of the content of the data field in the response parameter |
- status=200; the order passed directly
- status in (2001,5400); the order will put into the retry queue. Please return status code of 2001 if the exception happen otherwise the respond wll be categories as rejected order.
- status=other; the order is directly rejected
Mpc order review API
$url = "http://*****/mpc/order/check";
$header = [
'Content-Type:application/json',
];
$params = [
"data" => [
"amount" => 2.00000000,
"coin_symbol" => "USDT_TRC20",
"address" => "TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi",
"user_id" => "1",
"order_id" => "1394934189494173697",
"timestamp" => 1621493658
],
"sign" => "dLtK+uiPcnxt2ACKMbBqQ6wI5ttAvesOHzK5ybVID1R6hqYPDTkagl7Tsjr5iLJafehcSLTZyJLtCRI8O2CtIWQUUroGXBneHZC486NUi/4FMOQs0FaAgm17pWlbhX5/96cWXXXMVeoe3IZFKaFNYSWaA14v3RcdDU6QDE/9ixGiSJ0DIxm9NKA0+RkbIFbyYeuFn8d63OcjmUhv7tsOE6rKCc3Q2yi7Qe9i6BNAQFYMFATztb18MsxsBHKUxNqklqyVnl0ofETAHmQhfOHLmungOJQnOqAAuwfmRtg50Qci5F+R2mXeqjmIXko/u3E+DLYW1ygDBp3afKZmU4PwmA=="
];
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_POSTFIELDS, $params);
curl_setopt($ch, CURLOPT_HTTPHEADER, $header);
$return = curl_exec($ch);
print_r($return);
var url = "http://*****/mpc/order/check"
data := map[string]interface{}{
"data": map[string]string{
"amount":"2.00000000",
"coin_symbol":"USDT_TRC20",
"address":"TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi",
"user_id":"1",
"order_id":"1394934189494173697",
"timestamp":"1621493658",
},
"sign": "OTA8utI8y8G93p7RPCyb4qIilFQ0B4Aq4iUjhaXWK9m2kgektqlHOASDKXT2VE7NPNysrGycYlVfjDR2WGZn1G66phHo3qa9CcCNpG9klOBEuBEMjiVbb/d8AXcxEzvQr9OCwNsikyxonyzLiY/lsNHeGm9cC5eRvlNLdUSVBipH+ajPd0lDHCayZPs1eCMfbm/xnf8e2lfy6z0UPOpHGfyX/0+hz99Ir5Xnx+0sBBzyZZJxKm4ROid5aDv/9m9guILpURae+Yw/IrkYF4uAKGX+/44cBvtTRQSdX76CAOBSiywZa6BAgDYBLRtkAPM+i+vwNzFBovqHUvI+4Ponaw==",
}
dataType, _ := json.Marshal(data)
resp, err := http.Post(url, "application/json", strings.NewReader(string(dataType)))
if err != nil {
fmt.Println(err)
}
defer resp.Body.Close()
body, err := ioutil.ReadAll(resp.Body)
if err != nil {
fmt.Println(err)
}
fmt.Println(string(body))
let HTTP = require('http')
let postData = {
"data": {
"amount":"2.00000000",
"coin_symbol":"USDT_TRC20",
"address":"TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi",
"user_id":"1",
"order_id":"1394934189494173697",
"timestamp":"1621493658",
},
"sign": "OTA8utI8y8G93p7RPCyb4qIilFQ0B4Aq4iUjhaXWK9m2kgektqlHOASDKXT2VE7NPNysrGycYlVfjDR2WGZn1G66phHo3qa9CcCNpG9klOBEuBEMjiVbb/d8AXcxEzvQr9OCwNsikyxonyzLiY/lsNHeGm9cC5eRvlNLdUSVBipH+ajPd0lDHCayZPs1eCMfbm/xnf8e2lfy6z0UPOpHGfyX/0+hz99Ir5Xnx+0sBBzyZZJxKm4ROid5aDv/9m9guILpURae+Yw/IrkYF4uAKGX+/44cBvtTRQSdX76CAOBSiywZa6BAgDYBLRtkAPM+i+vwNzFBovqHUvI+4Ponaw==",
};
let POST_OPTIONS = {
port: 80,
host: "api.xxxx.com",
path: "/mpc/order/check",
method: 'POST',
headers: {
"Content-Type": "application/json; charset=utf-8"
}
};
const REQUEST = HTTP.request(POST_OPTIONS,function (res) {
let data = []
res.on('data', chunk => {
data.push(...chunk)
})
res.on('end', () => {
let _date = JSON.parse( new TextDecoder().decode(new Uint8Array(data)))
console.log(_date)
})
});
REQUEST.setTimeout(6000)
REQUEST.write(JSON.stringify(postData), 'utf8')
REQUEST.end()
public static void main() {
String priKey = "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCtdgvcfozY7fe/x6UlXR/Fff8+wX++CiG05YVRafDe90O8y5KJAMZ156TgajEUXSRyKZqASz7iVoMAcu5FqfK1KuOOdjTAg0LFe/twIZvKmAqHcCSS2pjUXk0fTpZEgQ5lmDCK12Mg07YXvr+BeHjF+kBpwRJMPMG/+DGBDYNFNeRSJqWyopt6yyF528soAykHIUQ7TTultJV5IPCrvjRQQrGdJ/QtCdE0vZg+tA09nFN7AqgraU99kIvzyS0sqysj+pP1SJRmTRSGtlVAO3mILfkXOekZl1KD60G7CF+7BIaaW83FPD55tZhAGhnbLMYyiq7OiIyU61LTRcNSaJ0tAgMBAAECggEBAIGgGKcSzxCBbMYdXLV6TPbZ/HeaRGrwyVWUu7cmc0E8CJu6iWvmb2jGzbiCwuCT5luF6ZZ8JKchvU4FlTfsE5r9TQY2IZ/Ht4s65qBaDUEts5iY3kv8HX9+ZSXDJZpV0ztqqsPmx4ZNj+NYwWXwcFiKdb5R8OmV8bgSsnPddD6wFhwewglUOBPRAjropHE4sqk1Vam6q1MlFq5kiekMn/CItyFYFFzST/ruqAtVTp7YIvazAMrfCKH+pvXWk6pYNHZmL/JZey0GglRyJ1nItiqL33X8Lji056FcbAclidq022h/KPLEJpZk6irWqYdqYZeF6YMLHtdZFDkTZ/hXY+UCgYEA5i794UTQ1Kd6K+iui/S8K5H8nGdiXb3+uZ5j5VKYfbRmzXhAdVYisYe8czeTECxhH+MeHgM4tLR4ifx9q60ylvZxl9Fav1p6EaE36YcvGVmpm7Gm3q6QDDBa4gB+X9u7CxCS4LpotV917YS1QvOIF9lnRonSj1zNzFtbXkywrN8CgYEAwOpx/mR40ZvgZxNCq9DsIdrSZYAFFKpw0xy0OtF1PpuwMaREoRabnlVw6Bb3Hofg50XA3JxemzAX6fB92ee+NfXfeL4UtC4vG1K9JyiXHtHq8p9Uw2W03ehIEeNa3xdoRRnLmD4VUpyfL19ViE2+7TM1Gd3TogjDT+AMOCSuq3MCgYBsurPH7gaq/LVT+mRAzgj4l8v4YUlwuGeTbIMJdvt7HXUWB4CDLH3U2CYnUpAQKrZyJok6ahEmIr1xiKggKP7lmmHL8eNo0icpHrtXfzi7Q8Q/PCpzs4dtioXTjaIkS5nNvzVyG/uL+RyuZmpsxrZ5dYM4KbAhchfwORMutxEZhwKBgQC5zpVw4jCEItBmNuTWO+nTScGvxTgfiXIVw+XLaQa2AJoZlhAL34yPWdffko79tv3lgweY9HsimZXO2rU8dbp8mo5c6ydhy8HPXUeWOcAkDSdv/ApWENW9jgYsRIC3swHY3Fl+Dv3Wjce8huQI3mjwaYvRmBhIToxfmHnscVhTBQKBgB9uciEHfz8hMI7ePrPo2PkyK/RbJDm3HnuWE2lFBp7MOUMlh53MXwv4dIRaYMbRrFuN1UIKEFxuKhWwTHSzZJufk/UENrha/81fpj2BoFsAKkEunKeETvaIh6fZSjec16h2+zxbzwkdS6b+yIYkSlaoAxmDYrMtae0C8G4e0YS9";
String pubKey = "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArXYL3H6M2O33v8elJV0fxX3/PsF/vgohtOWFUWnw3vdDvMuSiQDGdeek4GoxFF0kcimagEs+4laDAHLuRanytSrjjnY0wINCxXv7cCGbypgKh3AkktqY1F5NH06WRIEOZZgwitdjINO2F76/gXh4xfpAacESTDzBv/gxgQ2DRTXkUialsqKbesshedvLKAMpByFEO007pbSVeSDwq740UEKxnSf0LQnRNL2YPrQNPZxTewKoK2lPfZCL88ktLKsrI/qT9UiUZk0UhrZVQDt5iC35FznpGZdSg+tBuwhfuwSGmlvNxTw+ebWYQBoZ2yzGMoquzoiMlOtS00XDUmidLQIDAQAB";
rsaSigner signer = new rsaSigner();
Map<String, Object> data = new HashMap<>();
data.put("amount", "2.00000000");
data.put("coin_symbol", "USDT_TRC20");
data.put("address", "TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi");
data.put("user_id", "1");
data.put("order_id", "1394934189494173697");
data.put("timestamp", "1621493658");
try {
Map<String, Object> params = new HashMap<>();
params.put("data", data);
params.put("sign", signer.genSign(data, priKey));
Gson gson = new GsonBuilder().create();
System.out.println("params = " + gson.toJson(params));
String res;
// platform request shop callback API
// res = doPost("http://api.shophost.com/mpc/order/check", gson.toJson(params));
// if (null == res) {
// throw new RuntimeException("http error");
// }
// mock response from shop callback API
{
res = """
{
"status":200,
"data":{
"time":1620617260,
"trade_id":"202105101123221335892766889804"
},
"sign":"YbRyMoUmsCxLbWopD2JD5EZqkT+pIRARsdTSFo+WyhebOMP/TZ96zV/vy4CYn+9gk6nJ55acFnqSO78N4/uemiOyBgE+a8SaIjutc+kFCWGaCorboy9alFBFUbYPvHvFFKHNFJx19Z2cyv9uceGdOdz09g0OBgp8bTyfkCUNrhbUmut2M2S2ixSH3wSefqUq2SUpohb5hlD6tOsyO3JfZr7M/16aiRGcEye2XglsOMFTO5XRkj4hwHKB+nHacttvuZKnGH67ELyoajCc+ef1DkmzmO3P7vFLIuVtVXQ2FPlXVkzCR/+VesyDOpYogHwqyR1BzCCSzxpbZ/aFc/uANg=="
}
""";
}
System.out.println("response = " + res);
JsonParser jp = new JsonParser();
JsonObject resEle = jp.parse(res).getAsJsonObject();
boolean retSignOK = signer.verifySign(resEle.get("data"), resEle.get("sign").getAsString(), pubKey);
if (!retSignOK) {
throw new RuntimeException("verify response sign fail");
}
} catch (Exception e) {
e.printStackTrace();
}
System.out.println("OK");
}
Example of return result:
{
"status":200,
"data":{
"is_valid": 1,
"timestamp":1620617260,
"order_id":"1394934189494173697"
},
"sign":"YbRyMoUmsCxLbWopD2JD5EZqkT+pIRARsdTSFo+WyhebOMP/TZ96zV/vy4CYn+9gk6nJ55acFnqSO78N4/uemiOyBgE+a8SaIjutc+kFCWGaCorboy9alFBFUbYPvHvFFKHNFJx19Z2cyv9uceGdOdz09g0OBgp8bTyfkCUNrhbUmut2M2S2ixSH3wSefqUq2SUpohb5hlD6tOsyO3JfZr7M/16aiRGcEye2XglsOMFTO5XRkj4hwHKB+nHacttvuZKnGH67ELyoajCc+ef1DkmzmO3P7vFLIuVtVXQ2FPlXVkzCR/+VesyDOpYogHwqyR1BzCCSzxpbZ/aFc/uANg=="
}
- This is use for merchant to review the MPC withdrawal
- Note: The platform assigns a separate mpc public key to the merchant (different from the deposit/withdrawal/risk control public key)
- In this API, mechant and platform each need generate their own pair of rsa key
- When sending the request, Platform will use its own privater key to generate a sign, and the mechant will use the platform's public key to verify the sign.
- When mechant respond back to the request from the platform, mechant will use its private key to sign and platform will use merchant's public key to verify the sign
- Please refer back to the Signature Regulations section for the step
HTTP Request
POST The specific callback URL is provided by the merchant to the platform side
request parameters
| parameter name | required | type | description |
|---|---|---|---|
| data | no | string | as follows |
| data.order_id | Yes | string | The unique ID of the merchant transaction (trade_id when withdrawing) |
| data.user_id | yes | string | user the order belongs to |
| data.coin_symbol | yes | string | lowercase coin name, subject to the coin provided by the platform |
| data.address | yes | string | withdrawal address |
| data.amount | yes | decimal(20,8) | withdrawal amount |
| data.timestamp | yes | int | current timestamp in second |
| sign | yes | string | sign the data in data |
Response parameter description
| parameter name | type | description |
|---|---|---|
| status | int | 200 passed, 2001 pending review, 5400 failed signature verification, 5401 time less than 30s, 5402 order number does not exist, 5001 platform order_id is different, 5002 amount is wrong, 5003 user uid is wrong, 5004 address is wrong, 5005 currency The symbol is wrong, 5006 order rejection, 5007 other, the description information can be expanded by yourself |
| msg | string | state description |
| data | jsonObject | |
| data.is_valid | int | 1 pass; 2 fail |
| data.order_id | string | order number |
| data.timestamp | int | current time |
| sign | string | signature - the signature of the content of the data field in the response parameter |
CoSigner-Mpc order review API
$url = "http://*****/cs_mpc/order/check";
$header = [
'Content-Type:application/json',
];
$params = [
"data" => [
"amount" => 2.00000000,
"coin" => "USDT_TRC20",
"address" => "TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi",
"user_id" => "1",
"trade_id" => "1394934189494173697",
"timestamp" => 1621493658
],
"sign" => "dLtK+uiPcnxt2ACKMbBqQ6wI5ttAvesOHzK5ybVID1R6hqYPDTkagl7Tsjr5iLJafehcSLTZyJLtCRI8O2CtIWQUUroGXBneHZC486NUi/4FMOQs0FaAgm17pWlbhX5/96cWXXXMVeoe3IZFKaFNYSWaA14v3RcdDU6QDE/9ixGiSJ0DIxm9NKA0+RkbIFbyYeuFn8d63OcjmUhv7tsOE6rKCc3Q2yi7Qe9i6BNAQFYMFATztb18MsxsBHKUxNqklqyVnl0ofETAHmQhfOHLmungOJQnOqAAuwfmRtg50Qci5F+R2mXeqjmIXko/u3E+DLYW1ygDBp3afKZmU4PwmA=="
];
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_POSTFIELDS, $params);
curl_setopt($ch, CURLOPT_HTTPHEADER, $header);
$return = curl_exec($ch);
print_r($return);
var url = "http://*****/cs_mpc/order/check"
data := map[string]interface{}{
"data": map[string]string{
"amount":"2.00000000",
"coin":"USDT_TRC20",
"address":"TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi",
"user_id":"1",
"trade_id":"1394934189494173697",
"timestamp":"1621493658",
},
"sign": "OTA8utI8y8G93p7RPCyb4qIilFQ0B4Aq4iUjhaXWK9m2kgektqlHOASDKXT2VE7NPNysrGycYlVfjDR2WGZn1G66phHo3qa9CcCNpG9klOBEuBEMjiVbb/d8AXcxEzvQr9OCwNsikyxonyzLiY/lsNHeGm9cC5eRvlNLdUSVBipH+ajPd0lDHCayZPs1eCMfbm/xnf8e2lfy6z0UPOpHGfyX/0+hz99Ir5Xnx+0sBBzyZZJxKm4ROid5aDv/9m9guILpURae+Yw/IrkYF4uAKGX+/44cBvtTRQSdX76CAOBSiywZa6BAgDYBLRtkAPM+i+vwNzFBovqHUvI+4Ponaw==",
}
dataType, _ := json.Marshal(data)
resp, err := http.Post(url, "application/json", strings.NewReader(string(dataType)))
if err != nil {
fmt.Println(err)
}
defer resp.Body.Close()
body, err := ioutil.ReadAll(resp.Body)
if err != nil {
fmt.Println(err)
}
fmt.Println(string(body))
let HTTP = require('http')
let postData = {
"data": {
"amount":"2.00000000",
"coin":"USDT_TRC20",
"address":"TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi",
"user_id":"1",
"trade_id":"1394934189494173697",
"timestamp":"1621493658",
},
"sign": "OTA8utI8y8G93p7RPCyb4qIilFQ0B4Aq4iUjhaXWK9m2kgektqlHOASDKXT2VE7NPNysrGycYlVfjDR2WGZn1G66phHo3qa9CcCNpG9klOBEuBEMjiVbb/d8AXcxEzvQr9OCwNsikyxonyzLiY/lsNHeGm9cC5eRvlNLdUSVBipH+ajPd0lDHCayZPs1eCMfbm/xnf8e2lfy6z0UPOpHGfyX/0+hz99Ir5Xnx+0sBBzyZZJxKm4ROid5aDv/9m9guILpURae+Yw/IrkYF4uAKGX+/44cBvtTRQSdX76CAOBSiywZa6BAgDYBLRtkAPM+i+vwNzFBovqHUvI+4Ponaw==",
};
let POST_OPTIONS = {
port: 80,
host: "api.xxxx.com",
path: "/cs_mpc/order/check",
method: 'POST',
headers: {
"Content-Type": "application/json; charset=utf-8"
}
};
const REQUEST = HTTP.request(POST_OPTIONS,function (res) {
let data = []
res.on('data', chunk => {
data.push(...chunk)
})
res.on('end', () => {
let _date = JSON.parse( new TextDecoder().decode(new Uint8Array(data)))
console.log(_date)
})
});
REQUEST.setTimeout(6000)
REQUEST.write(JSON.stringify(postData), 'utf8')
REQUEST.end()
public static void main() {
String priKey = "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCtdgvcfozY7fe/x6UlXR/Fff8+wX++CiG05YVRafDe90O8y5KJAMZ156TgajEUXSRyKZqASz7iVoMAcu5FqfK1KuOOdjTAg0LFe/twIZvKmAqHcCSS2pjUXk0fTpZEgQ5lmDCK12Mg07YXvr+BeHjF+kBpwRJMPMG/+DGBDYNFNeRSJqWyopt6yyF528soAykHIUQ7TTultJV5IPCrvjRQQrGdJ/QtCdE0vZg+tA09nFN7AqgraU99kIvzyS0sqysj+pP1SJRmTRSGtlVAO3mILfkXOekZl1KD60G7CF+7BIaaW83FPD55tZhAGhnbLMYyiq7OiIyU61LTRcNSaJ0tAgMBAAECggEBAIGgGKcSzxCBbMYdXLV6TPbZ/HeaRGrwyVWUu7cmc0E8CJu6iWvmb2jGzbiCwuCT5luF6ZZ8JKchvU4FlTfsE5r9TQY2IZ/Ht4s65qBaDUEts5iY3kv8HX9+ZSXDJZpV0ztqqsPmx4ZNj+NYwWXwcFiKdb5R8OmV8bgSsnPddD6wFhwewglUOBPRAjropHE4sqk1Vam6q1MlFq5kiekMn/CItyFYFFzST/ruqAtVTp7YIvazAMrfCKH+pvXWk6pYNHZmL/JZey0GglRyJ1nItiqL33X8Lji056FcbAclidq022h/KPLEJpZk6irWqYdqYZeF6YMLHtdZFDkTZ/hXY+UCgYEA5i794UTQ1Kd6K+iui/S8K5H8nGdiXb3+uZ5j5VKYfbRmzXhAdVYisYe8czeTECxhH+MeHgM4tLR4ifx9q60ylvZxl9Fav1p6EaE36YcvGVmpm7Gm3q6QDDBa4gB+X9u7CxCS4LpotV917YS1QvOIF9lnRonSj1zNzFtbXkywrN8CgYEAwOpx/mR40ZvgZxNCq9DsIdrSZYAFFKpw0xy0OtF1PpuwMaREoRabnlVw6Bb3Hofg50XA3JxemzAX6fB92ee+NfXfeL4UtC4vG1K9JyiXHtHq8p9Uw2W03ehIEeNa3xdoRRnLmD4VUpyfL19ViE2+7TM1Gd3TogjDT+AMOCSuq3MCgYBsurPH7gaq/LVT+mRAzgj4l8v4YUlwuGeTbIMJdvt7HXUWB4CDLH3U2CYnUpAQKrZyJok6ahEmIr1xiKggKP7lmmHL8eNo0icpHrtXfzi7Q8Q/PCpzs4dtioXTjaIkS5nNvzVyG/uL+RyuZmpsxrZ5dYM4KbAhchfwORMutxEZhwKBgQC5zpVw4jCEItBmNuTWO+nTScGvxTgfiXIVw+XLaQa2AJoZlhAL34yPWdffko79tv3lgweY9HsimZXO2rU8dbp8mo5c6ydhy8HPXUeWOcAkDSdv/ApWENW9jgYsRIC3swHY3Fl+Dv3Wjce8huQI3mjwaYvRmBhIToxfmHnscVhTBQKBgB9uciEHfz8hMI7ePrPo2PkyK/RbJDm3HnuWE2lFBp7MOUMlh53MXwv4dIRaYMbRrFuN1UIKEFxuKhWwTHSzZJufk/UENrha/81fpj2BoFsAKkEunKeETvaIh6fZSjec16h2+zxbzwkdS6b+yIYkSlaoAxmDYrMtae0C8G4e0YS9";
String pubKey = "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArXYL3H6M2O33v8elJV0fxX3/PsF/vgohtOWFUWnw3vdDvMuSiQDGdeek4GoxFF0kcimagEs+4laDAHLuRanytSrjjnY0wINCxXv7cCGbypgKh3AkktqY1F5NH06WRIEOZZgwitdjINO2F76/gXh4xfpAacESTDzBv/gxgQ2DRTXkUialsqKbesshedvLKAMpByFEO007pbSVeSDwq740UEKxnSf0LQnRNL2YPrQNPZxTewKoK2lPfZCL88ktLKsrI/qT9UiUZk0UhrZVQDt5iC35FznpGZdSg+tBuwhfuwSGmlvNxTw+ebWYQBoZ2yzGMoquzoiMlOtS00XDUmidLQIDAQAB";
rsaSigner signer = new rsaSigner();
Map<String, Object> data = new HashMap<>();
data.put("amount", "2.00000000");
data.put("coin", "USDT_TRC20");
data.put("address", "TLhdZuFU1fDPnzxPoXfJ6WZZMpKzY15DUi");
data.put("user_id", "1");
data.put("trade_id", "1394934189494173697");
data.put("timestamp", "1621493658");
try {
Map<String, Object> params = new HashMap<>();
params.put("data", data);
params.put("sign", signer.genSign(data, priKey));
Gson gson = new GsonBuilder().create();
System.out.println("params = " + gson.toJson(params));
String res;
// platform request shop callback API
// res = doPost("http://api.shophost.com/cs_mpc/order/check", gson.toJson(params));
// if (null == res) {
// throw new RuntimeException("http error");
// }
// mock response from shop callback API
{
res = """
{
"status":200,
"data":{
"time":1620617260,
"trade_id":"202105101123221335892766889804"
},
"sign":"YbRyMoUmsCxLbWopD2JD5EZqkT+pIRARsdTSFo+WyhebOMP/TZ96zV/vy4CYn+9gk6nJ55acFnqSO78N4/uemiOyBgE+a8SaIjutc+kFCWGaCorboy9alFBFUbYPvHvFFKHNFJx19Z2cyv9uceGdOdz09g0OBgp8bTyfkCUNrhbUmut2M2S2ixSH3wSefqUq2SUpohb5hlD6tOsyO3JfZr7M/16aiRGcEye2XglsOMFTO5XRkj4hwHKB+nHacttvuZKnGH67ELyoajCc+ef1DkmzmO3P7vFLIuVtVXQ2FPlXVkzCR/+VesyDOpYogHwqyR1BzCCSzxpbZ/aFc/uANg=="
}
""";
}
System.out.println("response = " + res);
JsonParser jp = new JsonParser();
JsonObject resEle = jp.parse(res).getAsJsonObject();
boolean retSignOK = signer.verifySign(resEle.get("data"), resEle.get("sign").getAsString(), pubKey);
if (!retSignOK) {
throw new RuntimeException("verify response sign fail");
}
} catch (Exception e) {
e.printStackTrace();
}
System.out.println("OK");
}
Example of return result:
{
"status":200,
"data":{
"is_valid": 1,
"timestamp":1620617260,
"trade_id":"1394934189494173697"
},
"sign":"YbRyMoUmsCxLbWopD2JD5EZqkT+pIRARsdTSFo+WyhebOMP/TZ96zV/vy4CYn+9gk6nJ55acFnqSO78N4/uemiOyBgE+a8SaIjutc+kFCWGaCorboy9alFBFUbYPvHvFFKHNFJx19Z2cyv9uceGdOdz09g0OBgp8bTyfkCUNrhbUmut2M2S2ixSH3wSefqUq2SUpohb5hlD6tOsyO3JfZr7M/16aiRGcEye2XglsOMFTO5XRkj4hwHKB+nHacttvuZKnGH67ELyoajCc+ef1DkmzmO3P7vFLIuVtVXQ2FPlXVkzCR/+VesyDOpYogHwqyR1BzCCSzxpbZ/aFc/uANg=="
}
- This is use for merchant to review the CoSigner-Mpc withdrawal
- Note: The platform assigns a separate CoSigner-Mpc public key to the merchant (different from the deposit/withdrawal/risk control public key)
- In this API, merchant and platform each need generate their own pair of rsa key
- When sending the request, Platform will use its own privater key to generate a sign, and the merchant will use the platform's public key to verify the sign.
- When merchant respond back to the request from the platform, merchant will use its private key to sign and platform will use merchant's public key to verify the sign
- Please refer back to the Signature Regulations section for the step
HTTP Request
POST The specific callback URL is provided by the merchant to the platform side
request parameters
| parameter name | required | type | description |
|---|---|---|---|
| data | no | string | as follows |
| data.trade_id | Yes | string | The unique ID of the merchant transaction (trade_id when withdrawing) |
| data.user_id | yes | string | user the order belongs to |
| data.coin | yes | string | lowercase coin name, subject to the coin provided by the platform |
| data.address | yes | string | withdrawal address |
| data.amount | yes | decimal(20,8) | withdrawal amount |
| data.timestamp | yes | int | current timestamp in second |
| sign | yes | string | sign the data in data |
Response parameter description
| parameter name | type | description |
|---|---|---|
| status | int | 200 passed, 2001 pending review, 5400 failed signature verification, 5401 time less than 30s, 5402 order number does not exist, 5001 platform order_id is different, 5002 amount is wrong, 5003 user uid is wrong, 5004 address is wrong, 5005 currency The symbol is wrong, 5006 order rejection, 5007 other, the description information can be expanded by yourself |
| msg | string | state description |
| data | jsonObject | |
| data.is_valid | int | 1 pass; 2 fail |
| data.trade_id | string | order number |
| data.timestamp | int | current time |
| sign | string | signature - the signature of the content of the data field in the response parameter |