Docs / Getting started
HTTPS
Gurdx is served over HTTPS so that your API keys and the data you send are encrypted in transit.
Always use HTTPS#
Use the secure base URL for every call:
https://gurdx.cretip.com/api
Requests sent over plain HTTP are not a supported way to use the API. Your key travels in the URL or in a header, and sending it in clear text exposes it to anyone on the network path.
Verify certificates#
Keep certificate verification turned on in your HTTP client. Do not disable it to work around a local problem.
$response = Http::withOptions(['verify' => true])
->get('https://gurdx.cretip.com/api/geoip', ['key' => env('GURDX_KEY')]);
import requests
r = requests.get("https://gurdx.cretip.com/api/geoip", params={"key": "YOUR_API_KEY"}, timeout=5, verify=True)
const res = await fetch("https://gurdx.cretip.com/api/geoip?key=" + process.env.GURDX_KEY);
Protect the key in transit and at rest#
- Prefer the
Authorization: Bearerheader over?key=so the key stays out of access logs and referrer headers. - Do not log full request URLs on your side without masking the
keyparameter. - Keep the key in an environment variable or secret manager, never in source control.
Sensitive payloads#
For Payment Fraud Detection, Gurdx does not store card numbers. Only the BIN (up to 8 digits), the last four digits and a keyed hash are kept. You should still send data only over HTTPS and send the minimum needed.
Timeouts and retries#
Set a client timeout (a few seconds is usually enough) and decide in advance what your application does when Gurdx is unreachable: fail open for low-risk actions or fail closed for high-risk ones. Retry only on network failures, and back off if you receive error 106. See Error codes.
Found a mistake? Tell us on the contact page. Contact