Last Modified October 1, 2026

Activation API V1 Reference - Signatures

Activation API Signatures

  1. Overview
  2. Activation API HTTPS Request Signature
  3. Activation API HTTPS Response Signature

Oveview

All HTTPS Requests and Responses are signed to ensure secure communication with the DNA Servers.

The <SIGNATURE> is a HMAC256 Hash (Base64 encoded) of several parameters included in the HTTPS Request or Response using the Activation API Key (WEB_KEY) assigned to the DNA Product. The <SIGNATURE> is created by the sender, and re-created by the receiver to validate the signature of the communication.

The <SIGNATURE> is also used by the App to validate the stored DNA License JSON String in the App.

You can retrieve and change the Activation API Key (the WEB_KEY) for your DNA Product from the DNA Control Panel Product Configuration screen. The Key must be kept secret and is not communicated in the communication with the DNA Servers, but used at either end to sign and validate the signature of each communication.

 

Activation API Request Signature

For each Activation API request:

  1. build a base string (i.e. baseStringForHash) by concatenating the following parameters in the following order:

    • API    (ex: WEB_ACTIVATE)
    • WEB_KEY    (the Activation API Key for the DNA Product)
    • DNA_Key1
    • DNA_Key2
    • PRODUCT_ID
    • DATE

    These parameters (except WEB_KEY) must be included in the Request.

    The DATE parameter is a string representation of the current date in any format

  2. create the HMAC256 Hash using the HMAC256 algorithm with the base string and the WEB_KEY as the key.

  3. convert to Base64 encoding to create the SIGNATURE.

  4. add the SIGNATURE in the Request JSON String.

            	
               	// NOTE: exact syntax will depend on your implementation 
                
                baseStringForHash = API + WEB_KEY + DNA_KEY1 + DNA_KEY2 + PRODUCT_ID + DATE;
                
                computedHash = HMAC256(baseStringForHash,WEB_KEY);

                requestSignature = Convert.ToBase64String(computedHash, Base64FormattingOptions.None);
                
                
                

 

Activation API Response Signature

For each Activation API response received, you can validate the SIGNATURE of the response:

  1. build a base string (i.e. baseStringForHash) by concatenating the WEB_KEY (the Activation API Key for the DNA Product) with the following parameters included in the Response in the following order:

    • WEB_KEY
    • DNA_Key1
    • DNA_Key2
    • EXPIRY_DATE
    • VALIDATION_LIMIT
    • LICENSE_DATA
    • ERROR
    • RESPDATE

    If a parameter does not exist, use a <blank> or do not include.

  2. create the RESPONSE SIGNATURE using the HMAC256 algorithm with the base string and the WEB_KEY as the key, and convert to Base64 encoding

  3. compare the RESPONSE SIGNATURE with the SIGNATURE parameter included in the POST Response JSON string.

            	
               	// NOTE: exact syntax will depend on your implementation 
                
                baseStringForHash = WEB_KEY + DNA_KEY1 + DNA_KEY2 + EXPIRY_DATE + VALIDATION_LIMIT + LICENSE_DATA + ERROR + RESPDATE;
                
                computerHash = HMAC256(baseStringForHash,WEB_KEY);

                responseSignature = Convert.ToBase64String(computedHash, Base64FormattingOptions.None);