We use the same approach as existing SOAP implementation, in which we require the consumer (RSP) to pass in the rspSign (optional for certain methods), UID, and PWD for authentication.

However, in REST implementation, we leverage on Authorization header, which is used by Amazon with HMAC implementation. But instead of using HMAC implementation, we require the API consumer to pass in the Authorization header in this format:

GLOREMIT <UID>:<PWD>:<rspSign>

Authorization is the header key and the value after that is the header’s value. Example:

GLOREMIT rsp_api:p@assword123:7caa844e9b40d140b125cf51ac088868