You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Gate.io API V4出现INVALID_SIGNATURE错误的排查求助

Gate.io API V4 创建订单时签名不匹配问题排查

调用Gate.io加密货币市场API V4创建订单时,收到错误:

{"label":"INVALID_SIGNATURE","message":"Signature mismatch"}

以下是我的C++代码实现,包含HMAC-SHA512签名生成逻辑及请求构造过程,尝试过多种payload格式均无效,求解决方法:

当前代码实现

std::string hmac_sha512(const std::string& key, const std::string& data) {
    unsigned char* digest = HMAC(EVP_sha512(), key.c_str(), key.length(),
        reinterpret_cast<const unsigned char*>(data.c_str()), data.length(), nullptr, nullptr);
    std::stringstream ss;
    for (int i = 0; i < SHA512_DIGEST_LENGTH; i++) {
        ss << std::hex << std::setw(2) << std::setfill('0') << (int)digest[i];
    }
    return ss.str();
}

void CreateOrder(){
std::string host = "api.gateio.ws";
std::string prefix = "/api/v4";
std::string path = "/spot/orders";
std::string method = "POST";

//https://api.gateio.ws/api/v4/spot/orders
std::string payload = "{\"text\":\"t-123456\",\"currency_pair\":\"ETH_BTC\",\"type\":\"limit\",\"account\":\"spot\",\"side\":\"buy\",\"iceberg\":\"0\",\"amount\":\"1\",\"price\":\"5.00032\",\"time_in_force\":\"gtc\",\"auto_borrow\":false,\"stp_act\":\"cn\"}";
std::string hashJsonPayload = hmac_sha512(secretKey, payload);
std::string timestamp_seconds= std::to_string(std::chrono::duration_cast<std::chrono::seconds>(std::chrono::system_clock::now().time_since_epoch()).count());
std::string queryParam = "";
std::string sign_string = method + "\n" + "/api/v4/spot/orders"  + "\n" + queryParam + "\n" + hashJsonPayload + "\n" + timestamp_seconds;

std::string signHash = hmac_sha512(secretKey, sign_string);

req_.method(boost::beast::http::verb::post);
req_.target(r.target);
req_.version(11);
req_.set(boost::beast::http::field::host, r.host);
req_.set(boost::beast::http::field::accept, "application/json");
req_.set(boost::beast::http::field::content_type, "application/json");
req_.set(boost::beast::http::field::user_agent, BOOST_BEAST_VERSION_STRING);
req_.set("KEY", api_key); // API密钥添加
req_.set("Timestamp", timestamp_seconds);
req_.set("SIGN", signHash);
// ... 后续请求发送逻辑
}

尝试过的无效Payload格式

// 格式1:未转义双引号,语法错误
std::string payload1 = "{"text":"t-123456","currency_pair":"ETH_BTC","type":"limit","account":"spot","side":"buy","iceberg":"0","amount":"1","price":"5.00032","time_in_force":"gtc","auto_borrow":false,"stp_act":"cn"}";

// 格式2:包含换行和空格,非紧凑JSON
std::string payload2 = R"(
{
    "text": "t-123456",
    "currency_pair": "ETH_BTC",
    "type": "limit",
    "account": "spot",
    "side": "buy",
    "iceberg": "0",
    "amount": "1",
    "price": "5.00032",
    "time_in_force": "gtc",
    "auto_borrow": false,
    "stp_act": "cn"
}
)";

// 格式3:字符串拼接语法错误,双引号嵌套错误
std::string payload3= "{"account":"spot","currency_pair":"" + currencyPair + "","type":"market","side":"" + side + "","amount":"" + amount + "}";

问题根源及修正方案

  1. 签名规则错误:
    Gate.io V4 API的POST请求签名不需要先对payload做HMAC,正确的签名串构造逻辑是:

    // 去掉多余的payload HMAC步骤,直接使用原始payload
    std::string sign_string = method + "\n" + path + "\n" + queryParam + "\n" + payload + "\n" + timestamp_seconds;
    std::string signHash = hmac_sha512(secretKey, sign_string);
    

    你之前多做了一步hashJsonPayload = hmac_sha512(secretKey, payload),这完全不符合Gate.io的签名规范。

  2. Payload格式问题:

    • payload1存在语法错误,字符串内的双引号未转义,无法通过编译;
    • payload2包含换行和空格,Gate.io要求签名用的payload必须是无多余空格、换行的紧凑JSON,否则签名会不匹配;
    • payload3的字符串拼接逻辑错误,双引号嵌套导致JSON格式无效,正确的拼接应该用转义或字符串流处理:
      // 示例:正确的动态拼接方式
      std::stringstream payload_ss;
      payload_ss << "{\"account\":\"spot\",\"currency_pair\":\"" << currencyPair << "\",\"type\":\"market\",\"side\":\"" << side << "\",\"amount\":\"" << amount << "\"}";
      std::string payload = payload_ss.str();
      
  3. 其他排查点:

    • 确保时间戳是当前UTC时间的秒数,服务器会校验时间戳与服务器时间的偏差(允许±30秒),本地时间偏差过大也会导致签名失败;
    • 确认HMAC输出是小写十六进制字符串,你的代码中std::hex默认是小写,无需修改,但要避免被设置为大写;
    • 检查API Key和Secret Key是否正确,无复制错误或大小写问题;
    • 确保请求的target与签名串中的path完全一致(即/api/v4/spot/orders),无多余字符。

内容的提问来源于stack exchange,提问作者akdrkr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 06:20:53