Last Modified October 1, 2026
- Home
- Guides
- Activation API V1 Reference
- Signatures
Oveview
All HTTPS Requests and Responses are signed to ensure secure communication with the DNA Servers.
The <SIGNATURE> is a HMAC256 Hash (Base64 encoded) of several parameters included in the HTTPS Request or Response using
the Activation API Key (WEB_KEY) assigned to the DNA Product. The <SIGNATURE> is created by the sender,
and re-created by the receiver to validate the signature of the communication.
The <SIGNATURE> is also used by the App to validate the stored DNA License JSON String in the App.
You can retrieve and change the Activation API Key (the WEB_KEY) for your DNA Product from the DNA Control Panel Product Configuration screen. The Key must be kept secret and is not communicated in the communication
with the DNA Servers, but used at either end to sign and validate the signature of each communication.
Activation API Request Signature
For each Activation API request:
build a base string (i.e. baseStringForHash) by concatenating
the following parameters in the following order:
- API (ex: WEB_ACTIVATE)
- WEB_KEY (the Activation API Key for the DNA Product)
- DNA_Key1
- DNA_Key2
- PRODUCT_ID
- DATE
These parameters (except WEB_KEY) must be included in the Request.
The DATE parameter is a string representation of the current date in any format
create the HMAC256 Hash using the HMAC256 algorithm with the base string
and the WEB_KEY as the key.
convert to Base64 encoding to create the SIGNATURE.
add the SIGNATURE in the Request JSON String.
// NOTE: exact syntax will depend on your implementation
baseStringForHash = API + WEB_KEY + DNA_KEY1 + DNA_KEY2 + PRODUCT_ID + DATE;
computedHash = HMAC256(baseStringForHash,WEB_KEY);
requestSignature = Convert.ToBase64String(computedHash, Base64FormattingOptions.None);
Activation API Response Signature
For each Activation API response received, you can validate the SIGNATURE of the response:
build a base string (i.e. baseStringForHash) by concatenating
the WEB_KEY (the Activation API Key for the DNA Product) with the following parameters included in the Response in the following order:
- WEB_KEY
- DNA_Key1
- DNA_Key2
- EXPIRY_DATE
- VALIDATION_LIMIT
- LICENSE_DATA
- ERROR
- RESPDATE
If a parameter does not exist, use a <blank> or do not include.
create the RESPONSE SIGNATURE using the HMAC256 algorithm with the base string and the
WEB_KEY as the key, and convert to Base64 encoding
compare the RESPONSE SIGNATURE with the SIGNATURE parameter included
in the POST Response JSON string.
// NOTE: exact syntax will depend on your implementation
baseStringForHash = WEB_KEY + DNA_KEY1 + DNA_KEY2 + EXPIRY_DATE + VALIDATION_LIMIT + LICENSE_DATA + ERROR + RESPDATE;
computerHash = HMAC256(baseStringForHash,WEB_KEY);
responseSignature = Convert.ToBase64String(computedHash, Base64FormattingOptions.None);