You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Node.js中验证PayPal Webhook遇invalid_token错误,求解决方法

问题:PayPal Webhook验证返回invalid_token错误

按照PayPal官方Webhook验证步骤配置后,持续收到错误:

{ error: 'invalid_token', error_description: 'Token signature verification failed' }

以下是我的验证函数代码:

export const verifyPayPalWebhook = async (req: NextApiRequest) => {
  const url =
    "https://api-m.sandbox.paypal.com/v1/notifications/verify-webhook-signature";
  const res = await fetch(url, {
    method: "POST",
    headers: {
      "Content-Type": "application/json",
      Authorization: `Bearer ${process.env.PAYPAL_CLIENT_SECRET}`,
    },
    body: JSON.stringify({
      transmission_id: req.headers["paypal-transmission-id"],
      transmission_time: req.headers["paypal-transmission-time"],
      cert_url: req.headers["paypal-cert-url"],
      auth_algo: req.headers["paypal-auth-algo"],
      transmission_sig: req.headers["paypal-transmission-sig"],
      webhook_id: process.env.PAYPAL_WEBHOOK_ID,
      webhook_event: req.body,
    }),
  });

  const data = await res.json();

  if (!res.ok) {
    throw new Error(data.error_description);
  }
  return data.verification_status === "SUCCESS";
};

已确认信息:

  • PAYPAL_CLIENT_SECRET和PAYPAL_WEBHOOK_ID环境变量均已定义,其中PAYPAL_CLIENT_SECRET是应用密钥,PAYPAL_WEBHOOK_ID为对应Webhook的ID
  • 当前通过开发服务器创建并捕获订单测试Webhook端点

内容的提问来源于stack exchange,提问作者ohShoes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 16:47:27