To get Bitcoin data from Coinbase in PHP, choose the Coinbase API product first. Exchange REST requests use API-key headers and an HMAC-SHA256 signature; Advanced Trade requests use a CDP JWT bearer token. The example below makes a read-only Exchange REST request for the BTC-USD ticker, using PHP cURL and credentials stored outside your code.
Choose the Coinbase API before writing PHP
Coinbase has more than one API, and their authentication schemes are not interchangeable. The Coinbase Exchange REST API and Advanced Trade API have different endpoint routes and credentials. Coinbase describes Advanced Trade as a REST API and WebSocket protocol for programmatic trading, order management, and real-time market data. Decide which product your account and task require before copying an example.
| What to compare | Coinbase Exchange REST | Coinbase Advanced Trade |
|---|---|---|
| Authentication | API key, passphrase, timestamp, and HMAC-SHA256 signature in CB-ACCESS-* headers. |
CDP JWT sent as a bearer token. |
| Endpoint | The ticker route used below is /products/BTC-USD/ticker. Use the Exchange REST host specified in Coinbase’s Exchange documentation. |
Use the Advanced Trade host and route specified in its documentation; do not send an Exchange route with an Advanced Trade token. |
| Scope | API key permissions include View, Transfer, Trade, and Manage. A read-only price lookup should use only the access it needs. | Supports programmatic trading and order management. Coinbase Developer Documentation states a maximum of 100 Advanced Trade portfolios (2026 page crawl). |
| PHP SDK status | Coinbase’s coinbase/coinbase-php repository labels the wrapper deprecated; its examples are historical, not evidence of a maintained SDK. |
Coinbase lists an official Python SDK and sample TypeScript, Go, and Java SDKs. PHP developers should use direct REST calls or independently verify a third-party library. |
The code here is for Exchange REST only. If you need Advanced Trade, follow its current authentication and endpoint documentation rather than adapting the Exchange signature.
Prepare PHP and credentials
Enable cURL and JSON
The example requires PHP’s cURL extension and JSON support. Coinbase Exchange REST uses JSON for requests and responses, and its documentation says responses use typical HTTP status codes for success and failure. This request has no body, but it still sends Content-Type: application/json.
Recommended Free Tools
#1 Best Overall
Store the key outside your source code
Create an Exchange API key with the least privilege needed. For a price-reading example, do not grant Trade, Transfer, or Manage access. Store the API key, API secret, and passphrase in environment variables named COINBASE_API_KEY, COINBASE_API_SECRET, and COINBASE_API_PASSPHRASE. Also set COINBASE_EXCHANGE_BASE_URL to the Exchange REST base host shown in Coinbase’s current Exchange documentation.
Coinbase says API secrets and passphrases are displayed only once; save them securely when creating the key. Do not print credentials, commit a .env file, or paste real keys into code examples. Coinbase’s security guidance recommends keeping credentials out of source control.
Call the BTC-USD ticker from PHP
This example signs a read-only Exchange REST GET request to /products/BTC-USD/ticker. The configured base URL must be the Exchange REST host for your use case, not an Advanced Trade host. The request path used to sign must match the path sent in the HTTP request.
<?php
function requiredEnv(string $name): string
{
$value = getenv($name);
if ($value === false || $value === '') {
throw new RuntimeException("Missing environment variable: {$name}");
}
return $value;
}
$baseUrl = rtrim(requiredEnv('COINBASE_EXCHANGE_BASE_URL'), '/');
$apiKey = requiredEnv('COINBASE_API_KEY');
$encodedSecret = requiredEnv('COINBASE_API_SECRET');
$passphrase = requiredEnv('COINBASE_API_PASSPHRASE');
$method = 'GET';
$requestPath = '/products/BTC-USD/ticker';
$body = '';
$timestamp = (string) time();
$secret = base64_decode($encodedSecret, true);
if ($secret === false) {
throw new RuntimeException('The API secret is not valid base64.');
}
$prehash = $timestamp . strtoupper($method) . $requestPath . $body;
$signature = base64_encode(hash_hmac('sha256', $prehash, $secret, true));
$headers = [
'CB-ACCESS-KEY: ' . $apiKey,
'CB-ACCESS-SIGN: ' . $signature,
'CB-ACCESS-TIMESTAMP: ' . $timestamp,
'CB-ACCESS-PASSPHRASE: ' . $passphrase,
'Content-Type: application/json',
];
$ch = curl_init($baseUrl . $requestPath);
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => $headers,
CURLOPT_CUSTOMREQUEST => $method,
CURLOPT_TIMEOUT => 15,
]);
$responseBody = curl_exec($ch);
if ($responseBody === false) {
$error = curl_error($ch);
curl_close($ch);
throw new RuntimeException('HTTP request failed: ' . $error);
}
$status = curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);
$data = json_decode($responseBody, true);
if (!is_array($data)) {
throw new RuntimeException('Coinbase returned invalid JSON.');
}
if ($status < 200 || $status >= 300) {
$message = $data['message'] ?? 'No error message was returned.';
throw new RuntimeException("Coinbase HTTP {$status}: {$message}");
}
if (!isset($data['price'])) {
throw new RuntimeException('The ticker response did not include a price field.');
}
echo 'BTC-USD ticker price: ' . $data['price'] . PHP_EOL;
The signature is formed from the timestamp, uppercase HTTP method, request path, and request body, concatenated in that order. The API secret is base64-decoded before use in HMAC-SHA256; the binary digest is then base64-encoded for CB-ACCESS-SIGN. For this bodyless GET, the body component is an empty string. For other requests, sign the exact body you send.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
The ticker price is market data, not a promise of the price you would receive for a buy or sell. If your request succeeds but its JSON shape differs, consult the current Exchange REST response documentation for that route before changing the parsing logic.
Read errors and fix common failures
Coinbase documents HTTP status codes for success and failure; inspect the code and parse the JSON message field rather than treating every response as a successful price. The example reports the status and message when Coinbase returns an error.
Rank #4
- Mine Bitcoins and Stay Motivated With This tShirt - Funny Nerdy Shirt
- Bitcoin In Binary Code Miner Shirts - Perfect Gift For your Computer Science Programing Dad Mom Sibling - They Will Love This TEE
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
- 400: Check the route, request parameters, and body format.
- 401: Check that the key, passphrase, timestamp, signature, and decoded secret correspond to the same Exchange API key.
- 403: Check the key’s permissions and whether access is allowed for the requested operation.
- 404: Check that the host and route belong to the API product you selected.
- 500: The server returned an error; retain the status and message when investigating the failure.
If PHP reports a cURL error rather than an HTTP status, check that the cURL extension is enabled and that the configured host is reachable. Never include API credentials in diagnostic output.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What about Coinbase’s PHP SDK?
Coinbase’s coinbase/coinbase-php repository is explicitly marked “DEPRECATED — PHP wrapper for the Coinbase API.” Its examples, including getSpotPrice('BTC-USD'), getBuyPrice('BTC-USD'), and getSellPrice('BTC-USD'), can help explain the older wrapper’s interface, but they do not establish that it is maintained or suitable for a new integration.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- Used Book in Good Condition
For Advanced Trade, Coinbase’s documentation lists an official Python SDK and sample SDKs in TypeScript, Go, and Java—not PHP. A PHP integration therefore needs direct REST calls or a third-party library whose maintenance, authentication support, and compatibility you verify independently.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

