$method, CURLOPT_RETURNTRANSFER => true, // TLS verification ON by default (production-safe). Only disable // for local development against a self-signed cert by setting // WHOST_TLS_VERIFY=0 in the env. CURLOPT_SSL_VERIFYPEER => (getenv('WHOST_TLS_VERIFY') === '0') ? false : true, CURLOPT_SSL_VERIFYHOST => (getenv('WHOST_TLS_VERIFY') === '0') ? 0 : 2, CURLOPT_HTTPHEADER => [ "X-WHost-Key: {$apiKey}", "X-WHost-Timestamp: {$timestamp}", "X-WHost-Nonce: {$nonce}", "X-WHost-Signature: {$signature}", ], ]); // POST/PUT/PATCH/DELETE with a body: pass the JSON in CURLOPT_POSTFIELDS and // use the same string as $body above when computing the signature. if ($body !== '' && in_array($method, ['POST', 'PUT', 'PATCH', 'DELETE'], true)) { curl_setopt($ch, CURLOPT_POSTFIELDS, $body); } $response = curl_exec($ch); $status = curl_getinfo($ch, CURLINFO_RESPONSE_CODE); curl_close($ch); echo "HTTP {$status}\n{$response}\n";