SikaaHub API Health Check

Developer Documentation

Security

Security

Stage 5 hardening adds:

Phone Verification

Customers and merchants register as pending_verification. Phone OTP verification activates customers and moves merchants to KYC.

OTP rules:

Device Security

Every login captures:

New devices trigger a device-trust OTP and risk alert. Financial actions require X-Device-ID.

Device endpoints:

Transaction PIN

Transaction PINs are hashed separately from passwords.

PIN is required for:

Failed PIN attempts are counted and can temporarily lock financial actions.

Fraud Signals

Risk alerts may be created for: