PHP Laravel对接Coinex API获取余额遇签名错误求助
Coinex API查询余额签名错误排查及解决方案
问题描述
我尝试使用PHP对接Coinex API查询账户余额,已遵循官方文档实现,但始终收到签名错误提示。虽多次调整代码仍未解决问题,希望有人帮忙分析错误原因,指导正确的API对接方式,提供相关思路或示例。
相关官方文档:
- Coinex API授权文档
- Coinex API查询余额文档
我的代码片段
API类代码
<?php namespace App\Classes\Api; use GuzzleHttp\Client; class CoinexFuturesApi{ public string $apiKey = ""; public string $secretKey = ""; public function get_balance(){ $client = new Client(); $timestamp = (int)(microtime(true)*1000); $prepString = "GET"."/assets/spot/balance".$timestamp; $key = $this->secretKey; $message = $prepString; $signed_str = hash_hmac('sha256', $message, $key); $signed_str = strtolower($signed_str); $response = $client->get("https://api.coinex.com/v2/assets/spot/balance",[ 'headers' => [ "X-COINEX-KEY" =>$this->apiKey, "X-COINEX-SIGN" => $signed_str, "X-COINEX-TIMESTAMP" =>$timestamp ], ]); $response = json_decode($response->getBody()->getContents(),false,512,JSON_THROW_ON_ERROR); return $response; } }
控制器类代码
<?php namespace App\Http\Controllers\Dashboard; use App\Http\Controllers\Controller; use Illuminate\Http\Request; use App\Classes\Api\CoinexFuturesApi; class TestController extends Controller{ public function __construct(){ $this->middleware('auth'); } public function index(){ $cx = new CoinexFuturesApi(); $response = $cx->get_balance(); echo '<pre>'; print_r($response); echo '</pre>'; } }
遇到的错误

错误原因分析及解决方案
核心错误:签名字符串的路径不匹配
你拼接签名字符串时使用的路径是/assets/spot/balance,但实际请求的API路径包含v2前缀(/v2/assets/spot/balance),两者不一致导致签名验证失败,这是最关键的问题。
修正后的代码
<?php namespace App\Classes\Api; use GuzzleHttp\Client; class CoinexFuturesApi{ public string $apiKey = ""; // 替换为你的API密钥 public string $secretKey = ""; // 替换为你的Secret密钥 public function get_balance(){ $client = new Client(); $timestamp = (int)(microtime(true)*1000); // 修正路径:与实际请求路径完全一致 $requestPath = "/v2/assets/spot/balance"; // 按官方要求拼接签名字符串:METHOD + 请求路径 + 时间戳 + 查询参数字符串(无参数则为空) $prepString = "GET" . $requestPath . $timestamp . ""; // 生成签名并转小写 $signed_str = hash_hmac('sha256', $prepString, $this->secretKey); $signed_str = strtolower($signed_str); $response = $client->get("https://api.coinex.com" . $requestPath, [ 'headers' => [ "X-COINEX-KEY" => $this->apiKey, "X-COINEX-SIGN" => $signed_str, "X-COINEX-TIMESTAMP" => $timestamp ], ]); $response = json_decode($response->getBody()->getContents(), false, 512, JSON_THROW_ON_ERROR); return $response; } }
额外排查思路
- 核对签名字符串组成:
- HTTP方法必须为大写(如
GET/POST),与请求方法完全一致 - 请求路径要和实际请求的URL路径完全匹配(包括版本前缀、参数路径等)
- 时间戳必须是毫秒级整数,且请求头中的
X-COINEX-TIMESTAMP要和签名字符串中的时间戳完全相同 - 如果是带查询参数的GET请求,需要将参数按字典序排序后拼接成
key1=value1&key2=value2的格式,追加到签名字符串末尾
- HTTP方法必须为大写(如
- 验证签名生成逻辑:用官方文档提供的示例参数手动计算签名,对比代码生成的结果,确认哈希算法和字符串拼接是否正确
- 检查密钥正确性:确保
apiKey和secretKey没有复制错误,无多余空格或换行符 - 时间同步:Coinex API要求客户端时间与服务器时间差不超过30秒,可调用Coinex的时间接口获取服务器时间,校准本地时间
内容的提问来源于stack exchange,提问作者MohsenCreative
相关产品推荐
相关产品推荐

