Crypto.com Exchange C# API调用账户摘要接口失败求助
Crypto.com Exchange C# API调用问题及修复方案
Crypto.com Exchange的C#相关API文档极少,调用获取账户摘要接口时多次失败,以下是简化后的代码:
using Newtonsoft.Json; using RestSharp; using System.Security.Cryptography; using System.Text; namespace Crypto.Account { internal class AccountSummary { private readonly string apiKey = "xxxxxx"; private readonly string apiSecret = "xxxxx"; private readonly string apiUrl = "https://api.crypto.com/v2/private/get-account-summary"; public AccountResponse GetAccountSummary() { var client = new RestClient(); var request = new RestRequest(apiUrl, Method.Post); long timestamp = DateTimeOffset.UtcNow.ToUnixTimeMilliseconds(); string sign = GetSignature(timestamp); var requestBody = new { id = 1, method = "private/get-account-summary", @params = new { }, nonce = timestamp, api_key = apiKey, sig = sign }; request.AddJsonBody(requestBody); var response = client.Execute(request); if (response.IsSuccessful) { //return JsonConvert.DeserializeObject<AccountResponse>(response.Content); return "hooray"; } else { throw new Exception($"Error: {response.StatusCode}, {response.Content}"); } } private string GetSignature(long timestamp) { string sigPayload = $"{apiKey}{timestamp}private/get-account-summary"; using (var hmacsha256 = new HMACSHA256(Encoding.UTF8.GetBytes(apiSecret))) { var hash = hmacsha256.ComputeHash(Encoding.UTF8.GetBytes(sigPayload)); return BitConverter.ToString(hash).Replace("-", "").ToLower(); } } } }
调用时遇到两种错误:
- 错误码10002,401 UNAUTHORIZED:未认证,或密钥/签名错误
- 错误码10003,401 IP_ILLEGAL:IP地址未加入白名单
修复方案
针对错误码10003(IP_ILLEGAL)
- 登录Crypto.com Exchange后台,进入API密钥管理界面,将当前运行代码的设备/服务器IP添加至API密钥的白名单中;
- 若使用动态IP,可临时关闭IP白名单(不推荐,存在安全风险),或切换为静态IP后再添加白名单。
针对错误码10002(签名/认证错误)
Crypto.com的v2 API签名规则与当前代码实现不符,需做以下修正:
修正签名生成逻辑
官方要求签名载荷为api_key + nonce + params的无空格JSON字符串,而非当前的apiKey + timestamp + method。修改签名方法如下:private string GetSignature(long nonce, object paramObj) { // 将params序列化为无空格的JSON字符串 string paramsJson = JsonConvert.SerializeObject(paramObj, Formatting.None); string sigPayload = $"{apiKey}{nonce}{paramsJson}"; using (var hmacsha256 = new HMACSHA256(Encoding.UTF8.GetBytes(apiSecret))) { var hash = hmacsha256.ComputeHash(Encoding.UTF8.GetBytes(sigPayload)); return BitConverter.ToString(hash).Replace("-", "").ToLower(); } }调整请求头与Body结构
v2 API要求API-Key、Nonce、Signature通过请求头传递,而非将api_key和sig放在请求Body中。修正请求构建逻辑:public AccountResponse GetAccountSummary() { var client = new RestClient(apiUrl); var request = new RestRequest(Method.Post); // 显式指定Content-Type为application/json request.AddHeader("Content-Type", "application/json"); long nonce = DateTimeOffset.UtcNow.ToUnixTimeMilliseconds(); var paramObj = new { }; // 若有接口参数,在此传入对应对象 string sign = GetSignature(nonce, paramObj); // 通过请求头传递认证信息 request.AddHeader("API-Key", apiKey); request.AddHeader("Nonce", nonce.ToString()); request.AddHeader("Signature", sign); var requestBody = new { id = 1, method = "private/get-account-summary", @params = paramObj, nonce = nonce }; request.AddJsonBody(requestBody); var response = client.Execute(request); if (response.IsSuccessful) { return JsonConvert.DeserializeObject<AccountResponse>(response.Content); } else { throw new Exception($"Error: {response.StatusCode}, {response.Content}"); } }额外注意事项
- 确保
nonce为毫秒级时间戳,且每次请求的nonce必须唯一,不能重复使用; - 确认API密钥的权限已开启“账户信息”相关权限,否则会导致认证失败;
- 检查
apiSecret是否正确,避免复制时出现空格或字符缺失。
- 确保
内容的提问来源于stack exchange,提问作者Franck E
相关产品推荐
相关产品推荐

