You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用aws4模块调用Appsync时签名验证失败,签名不匹配

问题描述

使用Node服务器上的aws4模块向Appsync发起请求,IAM密钥和策略配置正确,但收到签名不匹配错误:

{"errors":[{"errorType":"BadRequestException","message":"The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details.

The Canonical String for this request should have been
'POST
/graphql

content-type:application/json
host:*****.appsync-api.eu-central-1.amazonaws.com
x-amz-date:20230303T180202Z

content-type;host;x-amz-date
7f0fb133cf00e6ce0efa197c0e1737c04608f5bc1ee1316a56e0ab5929311496'

The String-to-Sign should have been
'AWS4-HMAC-SHA256
20230303T180202Z
20230303/eu-central-1/appsync/aws4_request
201966c7d6de1f6a0d30748e5e4db678a6dd8eae8011cc4d8a3c91a793f0bbb9'
"}]}

调用代码如下:

const options = {
  hostname: hostname,
  path: path,
  service: service,
  method: 'POST',
  region: process.env.AWS_REGION,
  timeout: 5000,
  headers: { ...headers, 'Content-Type' : 'application/json' }
};

return new Promise((resolve, reject) => {
  const req = https.request(aws4.sign(options), (res) => {.....}
.....
解决方案
  • 修正service参数值:错误信息里的String-to-Sign使用了appsync作为服务名,但Appsync API对应的服务名应该是appsync-api。检查你的service变量是否传入正确值,改为'appsync-api'后重新尝试。
  • 确保请求体参与签名计算:Canonical String中的哈希值基于请求体生成,若请求包含GraphQL查询体,必须将body字段添加到options对象中,示例:
    const options = {
      // 其他参数
      body: JSON.stringify({ query: 'your-graphql-query' })
    };
    
    aws4会自动计算body的哈希并加入签名流程,缺失body会导致哈希不匹配。
  • 清理冗余headers:确保headers对象中没有多余字段,错误信息里的Canonical Headers仅包含content-type、host、x-amz-date,若自定义headers有其他字段,不需要则直接移除,需要则确保aws4将其加入签名headers列表。
  • 验证region参数:确认process.env.AWS_REGION的值为eu-central-1,与错误信息中的region一致,region不匹配会直接导致签名计算错误。

内容的提问来源于stack exchange,提问作者Dionisis G

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 23:20:15