API Authorization

In order to use the API, service provider's application must send the request by TLS and authenticate as per the HTTP basic authentication scheme (RFC 2617) using the API key.

API key is issued by LVRTC when registering service provider as customer of the e-Identity platform.

Service provider's application must include the API key in the Authorization header of the API requests as follows.

Authorization: Basic {API-key}

Where {API-key} is the result of encoding the client identifier of the application (client_id) and its secret (client_secret) as follows:

base64(url_encode(utf8(client_id)) ':' url_encode(utf8(client_secret)))

The meaning of the above pseudocode is:

  • Encode client_id first in UTF-8 and then according to the URL character escape rules.
  • Encode client_secret first in UTF-8 and then according to the URL character escape rules.
  • Concatenate both using colons (“:”) as the separator.
  • Encode the resulting string in base64 without line breaks.

Did this page help you?