You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP Laravel对接Coinex API获取余额遇签名错误求助

Coinex API查询余额签名错误排查及解决方案

问题描述

我尝试使用PHP对接Coinex API查询账户余额,已遵循官方文档实现,但始终收到签名错误提示。虽多次调整代码仍未解决问题,希望有人帮忙分析错误原因,指导正确的API对接方式,提供相关思路或示例。

相关官方文档:

  • Coinex API授权文档
  • Coinex API查询余额文档

我的代码片段

API类代码

<?php

namespace App\Classes\Api;

use GuzzleHttp\Client;

class CoinexFuturesApi{
    public string $apiKey = "";
    public string $secretKey = "";

    public function get_balance(){
        $client = new Client();

        $timestamp = (int)(microtime(true)*1000);
        $prepString = "GET"."/assets/spot/balance".$timestamp;

        $key = $this->secretKey;
        $message = $prepString;

        $signed_str = hash_hmac('sha256', $message, $key);
        $signed_str = strtolower($signed_str);

        $response = $client->get("https://api.coinex.com/v2/assets/spot/balance",[
            'headers' => [
                "X-COINEX-KEY" =>$this->apiKey,
                "X-COINEX-SIGN" => $signed_str,
                "X-COINEX-TIMESTAMP" =>$timestamp
            ],
        ]);

        $response = json_decode($response->getBody()->getContents(),false,512,JSON_THROW_ON_ERROR);
        return $response;
    }
}

控制器类代码

<?php

namespace App\Http\Controllers\Dashboard;

use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
use App\Classes\Api\CoinexFuturesApi;

class TestController extends Controller{
    public function __construct(){
        $this->middleware('auth');
    }

    public function index(){
        $cx = new CoinexFuturesApi();
        $response = $cx->get_balance();

        echo '<pre>';
        print_r($response);
        echo '</pre>';
    }
}

遇到的错误

错误截图

错误原因分析及解决方案

核心错误:签名字符串的路径不匹配

你拼接签名字符串时使用的路径是/assets/spot/balance,但实际请求的API路径包含v2前缀(/v2/assets/spot/balance),两者不一致导致签名验证失败,这是最关键的问题。

修正后的代码

<?php

namespace App\Classes\Api;

use GuzzleHttp\Client;

class CoinexFuturesApi{
    public string $apiKey = ""; // 替换为你的API密钥
    public string $secretKey = ""; // 替换为你的Secret密钥

    public function get_balance(){
        $client = new Client();
        $timestamp = (int)(microtime(true)*1000);
        // 修正路径:与实际请求路径完全一致
        $requestPath = "/v2/assets/spot/balance";
        // 按官方要求拼接签名字符串:METHOD + 请求路径 + 时间戳 + 查询参数字符串(无参数则为空)
        $prepString = "GET" . $requestPath . $timestamp . "";
        
        // 生成签名并转小写
        $signed_str = hash_hmac('sha256', $prepString, $this->secretKey);
        $signed_str = strtolower($signed_str);

        $response = $client->get("https://api.coinex.com" . $requestPath, [
            'headers' => [
                "X-COINEX-KEY" => $this->apiKey,
                "X-COINEX-SIGN" => $signed_str,
                "X-COINEX-TIMESTAMP" => $timestamp
            ],
        ]);

        $response = json_decode($response->getBody()->getContents(), false, 512, JSON_THROW_ON_ERROR);
        return $response;
    }
}

额外排查思路

  1. 核对签名字符串组成:
    • HTTP方法必须为大写(如GET/POST),与请求方法完全一致
    • 请求路径要和实际请求的URL路径完全匹配(包括版本前缀、参数路径等)
    • 时间戳必须是毫秒级整数,且请求头中的X-COINEX-TIMESTAMP要和签名字符串中的时间戳完全相同
    • 如果是带查询参数的GET请求,需要将参数按字典序排序后拼接成key1=value1&key2=value2的格式,追加到签名字符串末尾
  2. 验证签名生成逻辑:用官方文档提供的示例参数手动计算签名,对比代码生成的结果,确认哈希算法和字符串拼接是否正确
  3. 检查密钥正确性:确保apiKey和secretKey没有复制错误,无多余空格或换行符
  4. 时间同步:Coinex API要求客户端时间与服务器时间差不超过30秒,可调用Coinex的时间接口获取服务器时间,校准本地时间

内容的提问来源于stack exchange,提问作者MohsenCreative

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 01:05:57