Skip to content
Gurdx

Docs / Getting started

HTTPS

Gurdx is served over HTTPS so that your API keys and the data you send are encrypted in transit.

Always use HTTPS#

Use the secure base URL for every call:

https://gurdx.cretip.com/api

Requests sent over plain HTTP are not a supported way to use the API. Your key travels in the URL or in a header, and sending it in clear text exposes it to anyone on the network path.

Verify certificates#

Keep certificate verification turned on in your HTTP client. Do not disable it to work around a local problem.

$response = Http::withOptions(['verify' => true])
    ->get('https://gurdx.cretip.com/api/geoip', ['key' => env('GURDX_KEY')]);
import requests

r = requests.get("https://gurdx.cretip.com/api/geoip", params={"key": "YOUR_API_KEY"}, timeout=5, verify=True)
const res = await fetch("https://gurdx.cretip.com/api/geoip?key=" + process.env.GURDX_KEY);

Protect the key in transit and at rest#

  • Prefer the Authorization: Bearer header over ?key= so the key stays out of access logs and referrer headers.
  • Do not log full request URLs on your side without masking the key parameter.
  • Keep the key in an environment variable or secret manager, never in source control.

Sensitive payloads#

For Payment Fraud Detection, Gurdx does not store card numbers. Only the BIN (up to 8 digits), the last four digits and a keyed hash are kept. You should still send data only over HTTPS and send the minimum needed.

Timeouts and retries#

Set a client timeout (a few seconds is usually enough) and decide in advance what your application does when Gurdx is unreachable: fail open for low-risk actions or fail closed for high-risk ones. Retry only on network failures, and back off if you receive error 106. See Error codes.

Found a mistake? Tell us on the contact page. Contact