Skip to content
All library documents

Signing Exchange API Requests in MQL5 with HMAC-SHA256

Article MQL5 articles

Summary

This article introduces request authentication for exchange APIs from MQL5, focusing on signatures, message authentication codes, HMAC, and SHA-256. It explains how a client combines request data with a secret key to generate a signature that a server can recompute. Matching signatures provide evidence that the request came from someone holding the shared key and that its contents were not changed in transit. A timestamp is included in the signed request so repeated requests differ and older requests can be rejected.

The discussion describes the concepts and signature-generation process, including converting the resulting value into a hexadecimal string for use with an API request. It emphasizes that the secret key stays on the client and that the signature, rather than the key, is sent. The article is a primer rather than a complete live integration: it says sensitive queries and actual exchange requests will be covered in a later installment. It gives no trading strategy or performance results, and its security explanation does not cover operational safeguards such as key storage or broader request-handling risks.

Key ideas

  • HMAC-SHA256 combines request data with a shared secret to produce an API signature.
  • A server can verify the signature to check request authenticity and integrity.
  • A timestamp makes signed requests distinct and can help prevent replay of older requests.
  • The client sends the derived signature while keeping the secret key private.
  • The article explains the signing concepts but leaves live sensitive API calls for a later installment.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.