Security
Encryption
The Tola Wallet API is secured using TLS based encryption via the HTTPS protocol, this will ensure the privacy and integrity of the data exchanged between your application and the Tola Wallet platform.
Credentials
You will be securely supplied with a username and password to authenticate to your Tola Wallet API URL using HTTP Basic Authentication. We recommend that you do not share these credentials in chat clients or in the clear.
Every Tola Wallet API URL can optionally have its payload signed by a Message Authentication Code for additional security. See HMAC Signing for more details.
IP Whitelisting
During integration you will be asked for a list of IP addresses from which your application will invoke the Tola Wallet API.
Any request from an IP address not on this list will be rejected to ensure that all requests originate from your approved set of IPs.
We will supply our IP address and we strongly suggest that you reject callbacks originating from other IP addresses.
Any additional IPs to be added to the whitelist or changes to any existing IPs must be formally communicated to Tola, this is to ensure that there is no service interruption.