> ## Documentation Index
> Fetch the complete documentation index at: https://apidocs.returnhelper.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Signing Key を取得

<Warning>
  このページはAIによって自動翻訳されています。API技術仕様は英語が正式です。不明点がある場合は[英語版](/api-reference/apiaccount/get-signing-key)を参照してください。
</Warning>

呼び出しに使用した API キーに対応するアカウントの署名キーを返します。このキーは Base64 エンコードされており、受信する webhook 通知の `ReturnHelper-Signature` ヘッダーを検証するために使用します——API リクエストの認証には**使用しません**。

同じ値は Return Helper ユーザーポータルの **Settings → Signing Key and API Token** 画面にも表示されます。ポータルからコピーする代わりにプログラムでキーを読み取りたい場合は、本エンドポイントを使用してください。

<Warning>
  署名キーは機密情報です。安全に保管し、クライアントサイドのコードで公開せず、ログにも記録しないでください。
</Warning>

<h2 id="related">
  関連
</h2>

* [Webhooks → 署名の検証](/ja/webhooks#signature-verification) — キーの使用方法。
* [認証](/ja/introduction#authentication) — API キーとトークン。署名キーとは別の認証情報です。


## OpenAPI

````yaml get /api/ApiAccount/GetSigningKey
openapi: 3.1.0
info:
  title: Return Helper API
  description: API documentation for Return Helper — covering User and Public endpoints.
  version: 1.0.0
servers:
  - url: https://api.returnshelper.com/uat/user
    description: Sandbox — User API
  - url: https://api.returnshelper.com/uat/public
    description: Sandbox — Public API
  - url: https://api.returnhelpercentre.com/v1/user
    description: Production — User API
  - url: https://api.returnhelpercentre.com/v1/public
    description: Production — Public API
  - url: https://api.returnhelperchina.com/user
    description: Production — User API (China)
security:
  - ApiKey: []
    ApiToken: []
paths:
  /api/ApiAccount/GetSigningKey:
    get:
      tags:
        - ApiAccount
      summary: Get signing key
      operationId: ReturnUserApi_GetSigningKey
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/General_UserGetSigningKeyReply'
        '401':
          description: >-
            Authentication failed. Returned when the `x-rr-apikey` or
            `x-rr-apitoken` header is missing or invalid. The body uses the
            standard `ApiResponse` envelope with `meta.error.message` describing
            the auth failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse'
      security:
        - ApiKey: []
          ApiToken: []
      servers:
        - url: https://api.returnshelper.com/uat/user
          description: Sandbox — User API
components:
  schemas:
    General_UserGetSigningKeyReply:
      type: object
      properties:
        data:
          $ref: '#/components/schemas/UserGetSigningKeyReply'
    ApiResponse:
      type: object
      description: >-
        Universal response envelope. Successful responses include the business
        payload as additional top-level fields alongside `correlationId` and
        `meta`. Failed responses (auth errors, validation errors) only populate
        `correlationId` and `meta`, with `meta.errorCode` and `meta.error`
        describing the failure.
      properties:
        correlationId:
          type:
            - string
            - 'null'
          description: >-
            Unique correlation ID for tracing the request through Return Helper
            systems.
        meta:
          $ref: '#/components/schemas/ApiResponseMeta'
    UserGetSigningKeyReply:
      type: object
      properties:
        signingKey:
          type:
            - string
            - 'null'
          description: >-
            Base64-encoded signing key used to verify the ReturnHelper-Signature
            header on webhook notifications.
    ApiResponseMeta:
      type: object
      description: >-
        Application-level metadata for every API response. Inspect `status` and
        `errorCode` to detect soft-error responses (validation failures arrive
        as HTTP 200 with `meta.status: 400`).
      properties:
        status:
          type: integer
          description: >-
            Application-level status code. For successful operations this
            mirrors the HTTP status (e.g. 200). For validation failures it
            reports the logical status (e.g. 400) even though the wire HTTP
            status is 200.
        data:
          type: object
          additionalProperties:
            type: string
          description: Reserved free-form metadata key/value pairs. Usually empty.
        errorCode:
          type:
            - string
            - 'null'
          description: >-
            Machine-readable error code (e.g. `VALIDATION_FAILED`). Non-null
            only when the operation failed.
        error:
          type: object
          additionalProperties: true
          description: >-
            Field-level or message-level error detail keyed by request property
            name. Empty object on success.
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: x-rr-apikey
      description: Your API key
    ApiToken:
      type: apiKey
      in: header
      name: x-rr-apitoken
      description: Your API token — keep this private

````