User Penalties

Receive user penalty notifications, including mute and account bans.

POSTcallbackUrl

Configure the receiving URL in Console → Service Configuration → User Penalties → Callback URL.

Request Parameters

Request Headers

All headers below are required.

Header Value Description
Content-Type application/json; charset=UTF-8 Request body format
Accept application/json; charset=UTF-8 Response format
X-AppId — Project ID from Console → Service Configuration
X-TimeStamp — UTC time when the callback is sent, in W3C format.
Format example: 2026-09-30T02:30:00Z. This example illustrates the format only.
Authorization — See Callback Signature below

Request Body

Parameter Type Required Description
appId String Required Project Number
userId String Required User ID
type String Required Method of punishment(mute:Mute, ban_account:Ban Account)
hours String Required Length of punishment(permanent:Permanent,{n}:{n} hours)
category String Required Reason for punishment(sensitive:Sensitive Words, advertising:Advertising Words)

Request Example

{
  "appId": "80700001",
  "userId": "usertest",
  "type": "mute",
  "hours": "24",
  "category": "advertising"
}

Callback Signature

Verify the Authorization header with the callback signature below. It signs the full CallbackUrl, rather than separate host and path values.

Signing Parameter Value
HTTPMethod POST
CallbackUrl Configured callback URL
  1. Hash the UTF-8 request body with SHA256 and convert the digest to hexadecimal.
  2. Build StringToSign as shown below.
  3. Compute HMAC-SHA256 using secretKey, encode the result with Base64, and compare it with Authorization.
CanonicalizedQueryString = hex(sha256(jsonBody))
StringToSign = HTTPMethod + "\n" +
               CallbackUrl + "\n" +
               CanonicalizedQueryString + "\n" +
               "X-AppId:" + SAME_APPID_IN_HEADER + "\n" +
               "X-TimeStamp:" + SAME_TIMESTAMP_IN_HEADER