You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP调用LBank API出现签名无效(错误码10007)问题求助

LBank API签名无效(error_code:10007)问题排查

我尝试用PHP对接LBank API,参照官方文档编写了代码,但调用接口时返回:

{"result":"false","msg":"Invalid signature","error_code":10007,"ts":1732090561500}

以下是我的代码:

$num = '0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';
$random_string = generateRandomString($num, 35);
$secret_Key = "A58E2F2E2DE40100274A635859913169";


try {
    $ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://www.lbkex.net/v2/timestamp.do");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_POST, 0);
$response = curl_exec($ch);

curl_close($ch);
$ch1 = curl_init();
$response_ts = json_decode($response, true); // 转换为关联数组
$timestamp = $response_ts['data'];

$parameters = "api_key=33ecc239-c375-4f9a-ac0c-3f0eb0a35101" . "&echostr=3d47056c3d47056c0bf0429c81afc8c3de7b0f90bf04&signature_method=HmacSHA256&timestamp=$timestamp";
$md5_hash = strtoupper(md5($parameters));
$signature = hash_hmac('sha256', $md5_hash, $secret_Key);
$base64_signature = base64_encode($signature);
echo $signature;
echo "<br>";
echo $base64_signature;
echo "<br>";

curl_setopt($ch1, CURLOPT_URL, "https://www.lbkex.net/v2/supplement/user_info.do");
curl_setopt($ch1, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch1, CURLOPT_POST, 1);
$headers = array(
    "echostr: $random_string",
    "timestamp: $timestamp",
    'signature_method: HmacSHA256',
    "contentType:'application/x-www-form-urlencoded'",
);
curl_setopt($ch1,CURLOPT_HTTPHEADER,$headers);

$post_data = array(
    'api_key' => '33ecc239-c375-4f9a-ac0c-3f0eb0a35101',
    'echostr' => $random_string,
    'sign' => "$base64_signature",
    'signature_method'=> 'HmacSHA256',
    'timestamp'=> $timestamp,
    'contentType'=> 'application/x-www-form-urlencoded',   
);
curl_setopt($ch1, CURLOPT_POSTFIELDS, $post_data);
$response = curl_exec($ch1);
curl_close($ch1);
echo $response;

} catch (Exception $e) {
    echo '发生错误: ' . $e->getMessage();
}

问题排查与修正方案

1. 签名参数不一致

代码中手动拼接的parameters里,echostr用了固定值,但实际请求用的是随机生成的$random_string,导致签名计算的参数和实际请求参数不匹配,这是核心错误。

2. 签名计算流程错误

多了一步MD5哈希转大写的操作,不符合LBank官方签名规则,官方要求直接对参数串做HMAC-SHA256加密后转Base64。

3. 请求格式与Header错误

  • Content-Type Header格式错误:正确写法是Content-Type: application/x-www-form-urlencoded,而非带单引号的小写格式
  • 部分参数同时放在Header和POST参数中,属于冗余且可能导致解析冲突
  • 用数组传递POST参数时,curl会自动转为multipart/form-data格式,和指定的application/x-www-form-urlencoded不匹配,导致服务器解析参数错误

4. 参数未排序

LBank API要求签名参数按ASCII升序排序后再拼接,代码中未做排序操作。


修正后的代码

function generateRandomString($chars, $length) {
    $randomString = '';
    for ($i = 0; $i < $length; $i++) {
        $randomString .= $chars[rand(0, strlen($chars) - 1)];
    }
    return $randomString;
}

$num = '0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';
$random_string = generateRandomString($num, 35);
$api_key = "33ecc239-c375-4f9a-ac0c-3f0eb0a35101";
$secret_Key = "A58E2F2E2DE40100274A635859913169";

try {
    // 获取服务器时间戳
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_URL, "https://www.lbkex.net/v2/timestamp.do");
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
    curl_setopt($ch, CURLOPT_POST, 0);
    $response = curl_exec($ch);
    curl_close($ch);

    $response_ts = json_decode($response, true);
    $timestamp = $response_ts['data'];

    // 准备签名参数:按ASCII升序排序
    $params = [
        'api_key' => $api_key,
        'echostr' => $random_string,
        'signature_method' => 'HmacSHA256',
        'timestamp' => $timestamp
    ];
    ksort($params); // 按键名升序排序
    $param_str = http_build_query($params); // 拼接成URL编码字符串

    // 生成签名:HMAC-SHA256加密后转Base64
    $signature = hash_hmac('sha256', $param_str, $secret_Key, true); // 第三个参数true返回原始二进制数据
    $base64_signature = base64_encode($signature);

    // 发起请求
    $ch1 = curl_init();
    curl_setopt($ch1, CURLOPT_URL, "https://www.lbkex.net/v2/supplement/user_info.do");
    curl_setopt($ch1, CURLOPT_RETURNTRANSFER, true);
    curl_setopt($ch1, CURLOPT_POST, 1);

    // 设置正确的Header
    $headers = [
        "Content-Type: application/x-www-form-urlencoded"
    ];
    curl_setopt($ch1, CURLOPT_HTTPHEADER, $headers);

    // 准备POST参数,包含签名
    $post_data = $params;
    $post_data['sign'] = $base64_signature;
    $post_str = http_build_query($post_data); // 转成URL编码字符串

    curl_setopt($ch1, CURLOPT_POSTFIELDS, $post_str);
    $response = curl_exec($ch1);
    curl_close($ch1);

    echo $response;
} catch (Exception $e) {
    echo '发生错误: ' . $e->getMessage();
}

内容的提问来源于stack exchange,提问作者Eng.Ali karimifard

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 01:34:56