TypeScript调用Steam市场API报400 Session mismatch,Python正常
调用Steam社区sellitem接口出现Session mismatch问题的解决方法
我用TypeScript调用Steam社区市场的sellitem接口售卖物品时,持续收到400响应,错误信息为“Session mismatch”,但用Python实现完全相同的请求逻辑却能正常返回200。以下是相关代码和请求详情,以及问题的解决方法:
可正常运行的Python代码
session = requests.Session() cookies = { "sessionid": "XXX", "steamLoginSecure": "X%7C%XX.X.X", } session.cookies.update(cookies) def sellSteamMarketItem(cookie): url = "https://steamcommunity.com/market/sellitem/" HEADERS = { "Referer": "https://steamcommunity.com/profiles/XXXXXX/inventory" } session_body = session.post("https://steamcommunity.com/market/sellitem/", data={ "sessionid": "XXXXX", "appid": "730", # App-ID(例如CS:GO) "contextid": "2", # 库存上下文ID "assetid": "XXXX", # 物品ID "amount": "1", # 数量 "price": "149999" }, headers=HEADERS) if session_body.status_code != 200: print("Error, Statuscode: ", session_body.status_code)
Python请求详情
<PreparedRequest [POST]> HTTP方法: POST URL: https://steamcommunity.com/market/sellitem/ Headers: { 'User-Agent': 'python-requests/2.32.3', 'Accept-Encoding': 'gzip, deflate, br', 'Accept': '*/*', 'Connection': 'keep-alive', 'Referer': 'https://steamcommunity.com/profiles/XXXXX/inventory', 'Cookie': 'sessionid=<REDACTED>; steamLoginSecure=<REDACTED>', 'Content-Length': '98', 'Content-Type': 'application/x-www-form-urlencoded' } Body: sessionid=<REDACTED>&appid=730&contextid=2&assetid=XXXXX&amount=1&price=149999
出现问题的TypeScript代码
create(assetId: number, price: number) { let url: string = "https://steamcommunity.com/market/sellitem/"; const data = { sessionid: sessionid, appid: "730", contextid: "2", assetid: assetId.toString(), amount: "1", price: price.toString(), }; const referer = "https://steamcommunity.com/profiles/" + steamID.getSteamID64() + "/inventory"; const respone = sendRequest(url, data, referer); console.log(respone); } async sendRequest(url, params, referer) { const headers = { "Cookie": cookies, "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36", "Accept": "application/json, text/plain, */*", "Accept-Encoding": "gzip, deflate, br", "Connection": "keep-alive", "Referer": referer }; response = await axios.post(url, params, { headers: headers }); }
Axios 400响应详情
{ "headers": { "Accept": "application/json, text/plain, */*", "Content-Type": "application/json", "Cookie": "sessionid=XX; steamLoginSecure=XX;", "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36", "Accept-Encoding": "gzip, deflate, br", "Connection": "keep-alive", "Referer": "https://steamcommunity.com/profiles/XX/inventory", "Content-Length": "123" }, "method": "post", "url": "https://steamcommunity.com/market/sellitem/", "data": { "sessionid": "XX", "appid": "730", "contextid": "2", "assetid": "XX", "amount": "1", "price": "14555" } } { "data": { "success": false, "message": "Session mismatch" }, "status": 400 }
问题原因及解决方法
核心问题
Axios默认会把请求体序列化为JSON格式(Content-Type: application/json),而Python的requests.post使用data参数时,会自动采用application/x-www-form-urlencoded表单编码格式。Steam的sellitem接口仅接受表单编码的请求体,因此JSON格式的请求会触发Session验证失败,返回"Session mismatch"。
解决步骤
将Axios的请求体转换为表单编码格式,以下两种方式任选其一:
方式一:使用URLSearchParams构造请求体
修改sendRequest函数:
async sendRequest(url, params, referer) { const headers = { "Cookie": cookies, "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36", "Accept": "*/*", // 建议和Python保持一致,减少请求头差异 "Accept-Encoding": "gzip, deflate, br", "Connection": "keep-alive", "Referer": referer, "Content-Type": "application/x-www-form-urlencoded" // 显式指定表单编码 }; // 将参数转换为表单格式 const formData = new URLSearchParams(); Object.entries(params).forEach(([key, value]) => { formData.append(key, value); }); const response = await axios.post(url, formData, { headers: headers }); return response; }
方式二:使用qs库序列化数据
先安装依赖:npm install qs,再修改sendRequest函数:
import qs from 'qs'; async sendRequest(url, params, referer) { const headers = { "Cookie": cookies, "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36", "Accept": "*/*", "Accept-Encoding": "gzip, deflate, br", "Connection": "keep-alive", "Referer": referer, "Content-Type": "application/x-www-form-urlencoded" }; // 序列化参数为表单格式 const serializedData = qs.stringify(params); const response = await axios.post(url, serializedData, { headers: headers }); return response; }
额外注意事项
- 确保
sessionid在Cookie和请求体中的值完全一致,无额外空格或字符; - 尽量对齐Python请求的
Accept头为*/*,减少不必要的请求差异。
内容的提问来源于stack exchange,提问作者UsAA12
相关产品推荐
相关产品推荐

