Amazon Pay v2沙箱弹窗提示无法继续问题求助
问题:Amazon Pay V2沙箱环境登录后弹窗提示无法继续
点击Amazon Pay按钮登录沙箱测试账号后,弹窗显示:
You can’t continue in this page
To continue, close this page
前端按钮实现代码
async initializeAmazonPayV2Button() { try { // Get checkout session details from the backend const { payloadJSON, signature } = await this.createCheckoutSession(); console.log('this.apMerchantId', this.apMerchantId) console.log('this.apPublicKey', this.apPublicKey) console.log('payloadJSON', payloadJSON); console.log('signature', signature); // Initialize the Amazon Pay V2 button new amazon.Pay.renderButton('#AmazonPayV2Button', { // Set the environment merchantId: this.apMerchantId, publicKeyId: this.apPublicKey, ledgerCurrency: 'USD', // Customize the buyer experience checkoutLanguage: 'en_US', productType: 'PayAndShip', placement: 'Checkout', // estimatedOrderAmount: { 'amount': this.estTotal.toFixed(2), currencyCode: 'USD' }, createCheckoutSessionConfig: { payloadJSON: payloadJSON, signature: signature, algorithm: 'AMZN-PAY-RSASSA-PSS-V2', }, onError: (error) => { console.error('Amazon Pay V2 Error:', error); }, }); } catch (error) { console.error('Failed to initialize Amazon Pay V2 Button:', error); } },
后端生成的Payload
payload = { "storeId": settings.AMAZON_PAY_V2_STORE_ID, # Replace with your Amazon Store ID "webCheckoutDetails": { "checkoutReviewReturnUrl": checkout_review_url, }, "chargePermissionType": "OneTime", "scopes": ["name", "email", "phoneNumber", "billingAddress"] } payload_json = json.dumps(payload)
已排查点
- 排除签名不匹配问题(此前签名错误会直接报错,当前可正常完成登录流程)
- 已验证
renderButton的配置变量值正确 - 使用Amazon Pay ScratchPad测试功能正常,但签名生成方式不同(自定义Python代码vs官方SDK)
排查建议
- 检查返回URL的有效性:确保
checkout_review_url是可公开访问的HTTPS地址,无登录拦截、跳转逻辑,且域名已添加到Amazon Pay控制台的「Allowed JavaScript origins」和「Allowed return URLs」列表中。沙箱环境同样要求HTTPS,不能使用HTTP或localhost(可使用ngrok等工具做本地代理)。 - 核对Payload序列化格式:将后端生成的
payloadJSON与ScratchPad生成的有效Payload做对比,确认无额外转义、格式错误(比如引号、逗号的使用,是否有多余空格)。确保json.dumps未修改原始结构(比如默认的ensure_ascii=False是否启用,避免字符转义异常)。 - 验证签名实现细节:虽然签名未报错,但自定义Python代码实现
AMZN-PAY-RSASSA-PSS-V2时可能存在参数偏差:- 必须对原始Payload JSON字符串签名,而非Python字典对象
- 签名算法需严格遵循RSASSA-PSS规范,哈希函数为SHA256,盐长度等于哈希长度(32字节),可参考官方SDK的签名逻辑做对齐
- 检查控制台配置:确认沙箱环境的
storeId、merchantId、publicKeyId完全匹配,且已启用PayAndShip产品类型的权限。 - 查看隐藏日志:在浏览器控制台过滤
amazon相关日志,Amazon Pay脚本可能输出未捕获的详细错误信息,帮助定位问题。 - 替换测试URL:临时将
checkout_review_url替换为ScratchPad中可用的返回URL,测试是否能正常跳转,排除URL本身的问题。
内容的提问来源于stack exchange,提问作者Chad
相关产品推荐
相关产品推荐

