Timestamps in responses
Every timestamp returned by the API is formatted:Z (denoting UTC) is always present. The API never emits offsets like -03:00.
Parsing
All mainstream languages parse this format natively:Display
Format with the user’s locale on the client side:Timestamps in requests
Most request bodies do not carry timestamps — those are server-assigned. The single exception is the signedX-Access-Timestamp header carrying the request time.
X-Access-Timestamp: milliseconds, not seconds
The signing protocol uses Unix epoch milliseconds, not seconds. A 2026-era timestamp is 13 digits, not 10:
Clock-skew tolerance: ±10 seconds
The Access Protocol rejects any request whoseX-Access-Timestamp is more than ±10 seconds from server time. This is tighter than typical cloud SDKs (which allow minutes), and it is non-negotiable.
Why so strict?
Tight clock-skew tolerance reduces the window in which a captured request can be replayed. Combined with the 1-hour deduplication ofX-Access-Request-Id, the protocol is robust against replay attacks without requiring nonce challenges or session tokens.
Common failure modes
Programmatic clock-skew check: GET /time
If you cannot run NTP (e.g., shared CI runners), the preferred programmatic check is the unauthenticated GET /time endpoint, which returns the server’s current time. Because it requires no signature, you can call it even when every signed request is failing with TIMESTAMP_SKEW_EXCEEDED:
- Record your local clock immediately before and after calling
GET /time. - Compute the offset:
offsetMs = serverTime - localMidpoint(the midpoint of the two local readings compensates for network latency). - Apply the offset when signing: generate
X-Access-TimestampasDate.now() + offsetMs. - Re-measure periodically — local clocks drift.
GET /time is not convenient, the server time is also conveyed in the Date response header on every response — including error responses — at whole-second precision:
Time zones
The API contract has no notion of time zones. Every absolute moment is UTC. Convert at the edges:- Server → User: UTC timestamp → user’s local time on the client.
- User → Server: parse user input in their local timezone → UTC ISO 8601 → send.
filter expression:
Next
Sign a request
Where
X-Access-Timestamp fits in the canonical request.Filtering
How to filter list endpoints by date ranges.