Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To get Bitcoin data from Coinbase in PHP, choose the Coinbase API product first. Exchange REST requests use API-key headers and an HMAC-SHA256 signature; Advanced Trade requests use a CDP JWT bearer token. The example below makes a read-only Exchange REST request for the BTC-USD ticker, using PHP cURL and credentials stored outside your code.

Choose the Coinbase API before writing PHP

Coinbase has more than one API, and their authentication schemes are not interchangeable. The Coinbase Exchange REST API and Advanced Trade API have different endpoint routes and credentials. Coinbase describes Advanced Trade as a REST API and WebSocket protocol for programmatic trading, order management, and real-time market data. Decide which product your account and task require before copying an example.

What to compare Coinbase Exchange REST Coinbase Advanced Trade
Authentication API key, passphrase, timestamp, and HMAC-SHA256 signature in CB-ACCESS-* headers. CDP JWT sent as a bearer token.
Endpoint The ticker route used below is /products/BTC-USD/ticker. Use the Exchange REST host specified in Coinbase’s Exchange documentation. Use the Advanced Trade host and route specified in its documentation; do not send an Exchange route with an Advanced Trade token.
Scope API key permissions include View, Transfer, Trade, and Manage. A read-only price lookup should use only the access it needs. Supports programmatic trading and order management. Coinbase Developer Documentation states a maximum of 100 Advanced Trade portfolios (2026 page crawl).
PHP SDK status Coinbase’s coinbase/coinbase-php repository labels the wrapper deprecated; its examples are historical, not evidence of a maintained SDK. Coinbase lists an official Python SDK and sample TypeScript, Go, and Java SDKs. PHP developers should use direct REST calls or independently verify a third-party library.

The code here is for Exchange REST only. If you need Advanced Trade, follow its current authentication and endpoint documentation rather than adapting the Exchange signature.

Prepare PHP and credentials

Enable cURL and JSON

The example requires PHP’s cURL extension and JSON support. Coinbase Exchange REST uses JSON for requests and responses, and its documentation says responses use typical HTTP status codes for success and failure. This request has no body, but it still sends Content-Type: application/json.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Store the key outside your source code

Create an Exchange API key with the least privilege needed. For a price-reading example, do not grant Trade, Transfer, or Manage access. Store the API key, API secret, and passphrase in environment variables named COINBASE_API_KEY, COINBASE_API_SECRET, and COINBASE_API_PASSPHRASE. Also set COINBASE_EXCHANGE_BASE_URL to the Exchange REST base host shown in Coinbase’s current Exchange documentation.

Coinbase says API secrets and passphrases are displayed only once; save them securely when creating the key. Do not print credentials, commit a .env file, or paste real keys into code examples. Coinbase’s security guidance recommends keeping credentials out of source control.

Call the BTC-USD ticker from PHP

This example signs a read-only Exchange REST GET request to /products/BTC-USD/ticker. The configured base URL must be the Exchange REST host for your use case, not an Advanced Trade host. The request path used to sign must match the path sent in the HTTP request.

<?php

function requiredEnv(string $name): string
{
    $value = getenv($name);
    if ($value === false || $value === '') {
        throw new RuntimeException("Missing environment variable: {$name}");
    }
    return $value;
}

$baseUrl = rtrim(requiredEnv('COINBASE_EXCHANGE_BASE_URL'), '/');
$apiKey = requiredEnv('COINBASE_API_KEY');
$encodedSecret = requiredEnv('COINBASE_API_SECRET');
$passphrase = requiredEnv('COINBASE_API_PASSPHRASE');

$method = 'GET';
$requestPath = '/products/BTC-USD/ticker';
$body = '';
$timestamp = (string) time();

$secret = base64_decode($encodedSecret, true);
if ($secret === false) {
    throw new RuntimeException('The API secret is not valid base64.');
}

$prehash = $timestamp . strtoupper($method) . $requestPath . $body;
$signature = base64_encode(hash_hmac('sha256', $prehash, $secret, true));

$headers = [
    'CB-ACCESS-KEY: ' . $apiKey,
    'CB-ACCESS-SIGN: ' . $signature,
    'CB-ACCESS-TIMESTAMP: ' . $timestamp,
    'CB-ACCESS-PASSPHRASE: ' . $passphrase,
    'Content-Type: application/json',
];

$ch = curl_init($baseUrl . $requestPath);
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => $headers,
    CURLOPT_CUSTOMREQUEST => $method,
    CURLOPT_TIMEOUT => 15,
]);

$responseBody = curl_exec($ch);
if ($responseBody === false) {
    $error = curl_error($ch);
    curl_close($ch);
    throw new RuntimeException('HTTP request failed: ' . $error);
}

$status = curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);

$data = json_decode($responseBody, true);
if (!is_array($data)) {
    throw new RuntimeException('Coinbase returned invalid JSON.');
}

if ($status < 200 || $status >= 300) {
    $message = $data['message'] ?? 'No error message was returned.';
    throw new RuntimeException("Coinbase HTTP {$status}: {$message}");
}

if (!isset($data['price'])) {
    throw new RuntimeException('The ticker response did not include a price field.');
}

echo 'BTC-USD ticker price: ' . $data['price'] . PHP_EOL;

The signature is formed from the timestamp, uppercase HTTP method, request path, and request body, concatenated in that order. The API secret is base64-decoded before use in HMAC-SHA256; the binary digest is then base64-encoded for CB-ACCESS-SIGN. For this bodyless GET, the body component is an empty string. For other requests, sign the exact body you send.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The ticker price is market data, not a promise of the price you would receive for a buy or sell. If your request succeeds but its JSON shape differs, consult the current Exchange REST response documentation for that route before changing the parsing logic.

Read errors and fix common failures

Coinbase documents HTTP status codes for success and failure; inspect the code and parse the JSON message field rather than treating every response as a successful price. The example reports the status and message when Coinbase returns an error.

Rank #4
BITCOIN In Binary Code | Computer Programming Shirt
  • Mine Bitcoins and Stay Motivated With This tShirt - Funny Nerdy Shirt
  • Bitcoin In Binary Code Miner Shirts - Perfect Gift For your Computer Science Programing Dad Mom Sibling - They Will Love This TEE
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
  • 400: Check the route, request parameters, and body format.
  • 401: Check that the key, passphrase, timestamp, signature, and decoded secret correspond to the same Exchange API key.
  • 403: Check the key’s permissions and whether access is allowed for the requested operation.
  • 404: Check that the host and route belong to the API product you selected.
  • 500: The server returned an error; retain the status and message when investigating the failure.

If PHP reports a cURL error rather than an HTTP status, check that the cURL extension is enabled and that the configured host is reachable. Never include API credentials in diagnostic output.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What about Coinbase’s PHP SDK?

Coinbase’s coinbase/coinbase-php repository is explicitly marked “DEPRECATED — PHP wrapper for the Coinbase API.” Its examples, including getSpotPrice('BTC-USD'), getBuyPrice('BTC-USD'), and getSellPrice('BTC-USD'), can help explain the older wrapper’s interface, but they do not establish that it is maintained or suitable for a new integration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
The SQL Programming Language: .
  • Used Book in Good Condition

For Advanced Trade, Coinbase’s documentation lists an official Python SDK and sample SDKs in TypeScript, Go, and Java—not PHP. A PHP integration therefore needs direct REST calls or a third-party library whose maintenance, authentication support, and compatibility you verify independently.

Quick Recap

Bestseller No. 1
Bestseller No. 4
BITCOIN In Binary Code | Computer Programming Shirt
BITCOIN In Binary Code | Computer Programming Shirt
Mine Bitcoins and Stay Motivated With This tShirt - Funny Nerdy Shirt; Lightweight, Classic fit, Double-needle sleeve and bottom hem
$15.95
Bestseller No. 5
The SQL Programming Language: .
The SQL Programming Language: .
Used Book in Good Condition
$4.23

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.