The security should be done with HTTP Headers - X-API-KEY, X-API-TIMESTAMP, X-API-SIGNATURE. Using SHA256 for encrypting the signature.