Complete the steps in order: Sign Up → Activate → Signature → Debug → Go Live.
Leave everything else to XiaoYingAPI — a unified response {code, msg, data}.
Create an Account
Sign up with a username / email / phone number — any one works (email and phone sign-up can be enabled).
Create a Project
Contact the site admin to activate an Integration Project and get your dedicated APPID and APPSECRET.
Read the Docs + Live Debug
Enter your keys in the API Docs; the page signs the request for you and forwards it for real — verify first, then write code.
Integrate in Production
Implement HMAC-SHA256 signing on your server, keep the secret in environment variables and never expose it to the frontend.
app_xxx, it identifies which project is making the call and takes part in the signature.sk_xxx, used only on the server to compute the signature, must never be sent to the frontend.Endpoints that are Signature Required (auth) must include the common parameters on every request:
app_id / timestamp / nonce / sign.
key=value&key=value…;timestamp is a Unix timestamp in seconds with a ±5 minute validity window; nonce must be unique per request (the server deduplicates to prevent replay).
import hashlib
import hmac
import time
import secrets
APP_ID = 'app_yourAppId'
APP_SECRET = 'sk_yourAppSecret'
def build_sign(params: dict, secret: str) -> str:
"""Sort by parameter name in ascending ASCII order, join as key=value, and output lowercase hex via HMAC-SHA256"""
items = sorted(
(k, str(v)) for k, v in params.items()
if k != 'sign' and v not in (None, '')
)
raw = '&'.join(f'{k}={v}' for k, v in items)
return hmac.new(secret.encode(), raw.encode(), hashlib.sha256).hexdigest()
def signed_params(biz: dict):
params = dict(biz)
params.update({
'app_id': APP_ID,
'timestamp': str(int(time.time())),
'nonce': secrets.token_hex(8),
})
params['sign'] = build_sign(params, APP_SECRET)
return params
Tip: the Live Debug page signs requests automatically with the keys you enter, so beginners don't need to compute signatures by hand; before going to production, make sure your implementation matches the server exactly.
What to Try First?
User Center · File Upload · CAPTCHA Recognition · AI Chat and 15 services in total support live debugging.
Note: SMS, CAPTCHA and AI calls hit external services for real and may incur costs or send SMS; confirm before debugging.