You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在APIM策略中通过校验订阅密钥添加查询参数?

在APIM中通过订阅密钥校验并添加对应查询参数的实现方法

最便捷的方式是利用APIM的入站策略,通过条件判断匹配订阅密钥(或订阅名称),然后动态添加查询参数。以下是具体实现方案:

方案一:直接匹配订阅密钥(适合少量固定消费者)

在目标API的入站策略中添加以下代码,通过硬编码密钥值匹配并添加参数:

<policies>
    <inbound>
        <base />
        <!-- 匹配订阅密钥并添加对应user参数 -->
        <choose>
            <when condition="@(context.Subscription.Key == "43434-4545435-dfdfgfdg")">
                <set-query-parameter name="user" exists-action="override">
                    <value>consumerA</value>
                </set-query-parameter>
            </when>
            <!-- 可添加更多消费者规则 -->
            <when condition="@(context.Subscription.Key == "xxxxxx-xxxxxx-xxxxxx")">
                <set-query-parameter name="user" exists-action="override">
                    <value>consumerB</value>
                </set-query-parameter>
            </when>
            <!-- 可选:拦截无效密钥请求 -->
            <otherwise>
                <return-response>
                    <set-status code="403" reason="Invalid Subscription Key" />
                    <set-body>{"error": "无效或未识别的订阅密钥"}</set-body>
                </return-response>
            </otherwise>
        </choose>
    </inbound>
    <backend>
        <base />
    </backend>
    <outbound>
        <base />
    </outbound>
    <on-error>
        <base />
    </on-error>
</policies>

关键说明:

  • context.Subscription.Key:直接获取当前请求携带的订阅密钥
  • <set-query-parameter>:负责添加/覆盖查询参数,exists-action="override"表示如果参数已存在就替换,若需追加可改为append
  • <otherwise>:可选逻辑,用来处理密钥不匹配的场景,直接返回403错误拦截非法请求

方案二:基于订阅名称匹配(推荐最佳实践)

如果需要频繁轮换密钥或管理更多消费者,建议通过订阅名称来匹配,无需硬编码密钥值,更易维护:

<policies>
    <inbound>
        <base />
        <!-- 基于订阅名称添加user参数 -->
        <choose>
            <when condition="@(context.Subscription.Name == "ConsumerA")">
                <set-query-parameter name="user" exists-action="override">
                    <value>consumerA</value>
                </set-query-parameter>
            </when>
            <when condition="@(context.Subscription.Name == "ConsumerB")">
                <set-query-parameter name="user" exists-action="override">
                    <value>consumerB</value>
                </set-query-parameter>
            </when>
        </choose>
    </inbound>
    <backend>
        <base />
    </backend>
    <outbound>
        <base />
    </outbound>
    <on-error>
        <base />
    </on-error>
</policies>

优势:

  • 订阅名称是APIM中可管理的元数据,密钥可以随时轮换而无需修改策略
  • APIM默认会自动校验订阅密钥的有效性,无需额外编写校验逻辑,只需在通过校验后根据订阅名称添加参数即可

进阶优化:使用命名值存储映射关系

如果消费者数量较多,可以将密钥/订阅名称与用户标识的映射存储到APIM的**命名值(Named Values)**中,避免策略中大量硬编码:

  1. 在APIM门户中创建命名值,比如:

    • 名称:ConsumerA_Key,值:43434-4545435-dfdfgfdg
    • 名称:ConsumerA_User,值:consumerA
  2. 策略中通过命名值获取数据:

<when condition="@(context.Subscription.Key == context.NamedValues.GetValueOrDefault("ConsumerA_Key"))">
    <set-query-parameter name="user" exists-action="override">
        <value>@(context.NamedValues.GetValueOrDefault("ConsumerA_User"))</value>
    </set-query-parameter>
</when>

这种方式既保证了密钥的安全性(命名值可以加密存储),又便于统一管理映射关系。

内容的提问来源于stack exchange,提问作者R.A 1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 19:03:13