Skip to main content
URL: https://buy-sandbox.moonpay.com/?apiKey=pk_test_123

Sign your URLs

New on-ramp integrations sign every widget URL. IP matching is mandatory for going live, and the allowedIpAddress parameter it uses only works on signed URLs, so signing is part of every URL you generate. Signing is also required whenever you pass walletAddress, walletAddresses, or other sensitive parameters; the widget fails to load without it. See URL signing for the algorithm, code samples, and a test vector to verify your implementation.

Here’s an example. Give it a try