You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OKEx API调用出现Invalid Authority(50114)错误,寻求解决方法

解决OKEx V5 API调用返回50114(Invalid Authority)问题

OKEx API返回50114错误码(提示Invalid Authority),通常是签名验证失败、权限配置错误或时间同步问题导致,以下是具体排查和修复方案:

1. 修复签名生成逻辑

你的代码在处理GET请求时存在几个关键问题:GET请求参数需放在URL query部分而非body、签名时GET请求body必须为空、签名结果需转为字符串格式。修改后的完整代码如下:

import base64
import datetime as dt
import hmac
import requests
from urllib.parse import urlencode
import json

APIKEY = "xxxxx"
APISECRET = "xxxx"
PASS = "xxxx"
BASE_URL = 'https://aws.okex.com'

def send_signed_request(http_method, url_path, payload={}):
    def get_time():
        return dt.datetime.utcnow().isoformat()[:-3]+'Z'
    
    def signature(timestamp, method, request_path, body, secret_key):
        # GET请求body固定为空字符串,POST请求用无空格的JSON序列化字符串
        if method.upper() == 'GET':
            body_str = ''
        else:
            body_str = json.dumps(body, separators=(',', ':')) if body else ''
        message = str(timestamp) + method.upper() + request_path + body_str
        mac = hmac.new(bytes(secret_key, encoding='utf8'), bytes(message, encoding='utf-8'), digestmod='sha256')
        # 将bytes类型签名转为字符串
        return base64.b64encode(mac.digest()).decode('utf-8')
    
    def get_header(request_method, request_path, body_data):
        cur_time = get_time()
        sign = signature(cur_time, request_method, request_path, body_data, APISECRET)
        return {
            'CONTENT-TYPE': 'application/json',
            'OK-ACCESS-KEY': APIKEY,
            'OK-ACCESS-SIGN': sign,
            'OK-ACCESS-TIMESTAMP': cur_time,
            'OK-ACCESS-PASSPHRASE': PASS
        }

    # 处理GET请求的query参数,拼接完整请求URL和签名用路径
    url = BASE_URL + url_path
    signed_path = url_path
    if http_method.upper() == 'GET' and payload:
        query_str = urlencode(payload)
        url += '?' + query_str
        signed_path += '?' + query_str

    header = get_header(http_method, signed_path, payload if http_method.upper() != 'GET' else {})
    
    print(url)
    print(header)
    if http_method.upper() == 'GET':
        response = requests.get(url, headers=header)
    else:
        response = requests.request(http_method, url, headers=header, json=payload)
    
    print(response.json())
    return response.json()

send_signed_request("GET", "/api/v5/account/balance", payload={})

2. 检查API密钥配置

  • 权限验证:登录OKEx后台,确认创建的API密钥已勾选账户查询权限(如“查看账户余额”);
  • 环境匹配:若使用测试网密钥,需将BASE_URL改为https://testnet.okex.com;生产网密钥对应https://aws.okex.com;
  • 密码正确性:代码中的PASS必须与创建API时设置的Passphrase完全一致,注意大小写、特殊字符的匹配。

3. 同步系统时间

OKEx要求签名时间戳与UTC标准时间误差不超过30秒,偏差过大会直接导致签名验证失败:

  • 打印代码中生成的cur_time,与UTC标准时间对比,确认误差范围;
  • 若偏差过大,同步本地系统时间;或调用OKEx公共接口获取服务器时间用于签名,示例:
def get_okex_time():
    url = BASE_URL + '/api/v5/public/time'
    resp = requests.get(url).json()
    # 将毫秒级时间戳转为ISO格式字符串
    return dt.datetime.utcfromtimestamp(int(resp['data'][0]['ts'])/1000).isoformat()[:-3]+'Z'

# 替换原有get_time函数为上述函数

4. 验证请求头格式

确保请求头中的OK-ACCESS-SIGN是字符串类型,而非bytes对象;CONTENT-TYPE值为application/json(POST请求必须,GET请求可保留)。

内容的提问来源于stack exchange,提问作者Stack Overflow

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 00:37:19