# Data: { message: ‘invalid signature’, code: -1 }

**URL:** <https://community.fireblocks.com/t/data-message-invalid-signature-code-1/743>\
**Category:** Developer Discussion\
**Tags:** docs\
**Created:** [February 27, 2024, 6:07am UTC](https://community.fireblocks.com/t/data-message-invalid-signature-code-1/743 "2024-02-27T06:07:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akash](https://avatars.discourse-cdn.com/v4/letter/a/a5b964/32.png) [@Akash](https://community.fireblocks.com/u/Akash)\
**Post date:** [February 27, 2024, 6:07am UTC](https://community.fireblocks.com/t/data-message-invalid-signature-code-1/743/1 "2024-02-27T06:07:39Z")

</div>

"I am currently in the process of setting up the ncw-backend-demo repository to test the APIs. On the frontend side, I have a Flutter setup. When the login event is triggered from the frontend, three consecutive routes are called:

1. Login API
2. Assigns a newly generated deviceId (POST /api/devices/:deviceId/assign)
3. API for sending NCW SDK-generated messages to the backend, which then forwards these to the Fireblocks API (GET /api/devices/:deviceId/rpc).

The first two APIs are functioning perfectly fine; however, the second API encounters an error with the message: ‘Invalid signature’ and the error code: -1.

On the backend, I am using the ncw-backend-demo repository. For the Flutter setup, I have configured it to interact with the backend APIs.

Your assistance in resolving this issue would be greatly appreciated."

---

<div class="post-metadata">

**Author:** ![mnamakwala](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@mnamakwala](https://community.fireblocks.com/u/mnamakwala)\
**Post date:** [February 27, 2024, 8:09pm UTC](https://community.fireblocks.com/t/data-message-invalid-signature-code-1/743/2 "2024-02-27T20:09:42Z")

</div>

Hi Akash,  
Can you please make sure if the keys were generated correctly on the front end?  
Before the key generation step, the SDK needs to be initialized  
Please make sure the SDK is initialized correctly before key generation.  
The RPC calls wont work if the SDK is not initialized

> **[Initializing the SDK](https://ncw-developers.fireblocks.com/docs/initializing-the-sdk)**
>
> Overall flow Generate a device ID by calling the generateDeviceId() static method of the SDK.Assign the deviceId to a wallet on your backend server. (POST /v1/wallets/ can be executed at this point.)Initialize a new SDK instance. Initialize the...

Also can you please try using our front-end demo and check if you have same issues in the workflow?

> **[Setup](https://ncw-developers.fireblocks.com/docs/setup)**
>
> OverviewThe React Demo Application uses the Fireblocks Non-Custodial Wallet (NCW) Web SDK and was built as a reference for Fireblocks customers (or any developer looking for reference code for NCW implementation). It communicates with the Backend...

Thanks.

---

<div class="post-metadata">

**Author:** ![Akash](https://avatars.discourse-cdn.com/v4/letter/a/a5b964/32.png) [@Akash](https://community.fireblocks.com/u/Akash)\
**Post date:** [February 28, 2024, 8:08am UTC](https://community.fireblocks.com/t/data-message-invalid-signature-code-1/743/3 "2024-02-28T08:08:37Z")

</div>

Hi mnamakwala,

Thankyou for you response,

We are using same depositories which are present on the fireblocks demo repositories and we did not changed anything still we are facing same issue, I am adding repositories link over here.  
For frontend  
[GitHub - fireblocks/ncw-ios-demo](https://github.com/fireblocks/ncw-ios-demo)  
For backend  
[GitHub - fireblocks/ncw-backend-demo: Fireblocks Non custodial wallet demo backend](https://github.com/fireblocks/ncw-backend-demo)

Also I am confused with some of the env variables for backend configuration could you help me with it like how will i get those variables may be this can be the cause of error

1.FIREBLOCKS\_API\_SECRET  
2.FIREBLOCKS\_API\_KEY\_NCW\_SIGNER  
3.FIREBLOCKS\_API\_KEY\_NCW\_ADMIN

It will be helpful if I get help on this as soon as possible

Thank you.

---

<div class="post-metadata">

**Author:** ![mnamakwala](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@mnamakwala](https://community.fireblocks.com/u/mnamakwala)\
**Post date:** [February 28, 2024, 5:07pm UTC](https://community.fireblocks.com/t/data-message-invalid-signature-code-1/743/4 "2024-02-28T17:07:56Z")

</div>

Hi Akash,  
The FIREBLOCKS\_API\_SECRET is the secret key generated during creation of the CSR file used to create API user.  
Please use the same CSR file to create NCW ADMIN and NCW SIGNER users.

[https://support.fireblocks.io/hc/en-us/articles/4407823826194-Adding-new-API-users](https://support.fireblocks.io/hc/en-us/articles/4407823826194-Adding-new-API-users)

> **[Quickstart](https://ncw-developers.fireblocks.com/docs/setup-1)**
>
> The open-source backend demo application, which encompasses all the necessary backend operations for the Fireblocks Non-Custodial Wallet (NCW), can be accessed on our official GitHub account.This application provides all the essential endpoints for...

Please check out the articles above.

FIREBLOCKS\_API\_KEY\_NCW\_SIGNER, FIREBLOCKS\_API\_KEY\_NCW\_ADMIN are the API keys of the two created users

You can find the API keys in the console on the user page.

[https://support.fireblocks.io/hc/en-us/articles/4407823826194-Adding-new-API-users#:~:text=ID%3A%20a…a-,Retrieving%20an%20API%20user’s%20key,-When%20you%20want](https://support.fireblocks.io/hc/en-us/articles/4407823826194-Adding-new-API-users#:~:text=ID%3A%20a%E2%80%A6a-,Retrieving%20an%20API%20user%E2%80%99s%20key,-When%20you%20want)
