配置Amazon API Gateway接收Adyen Webhooks遇授权错误求助
问题:API Gateway集成S3接收Adyen Webhooks遇授权错误
场景描述
尝试配置AWS API Gateway接收Adyen平台的Webhooks,采用API Gateway与S3存储桶集成的方式创建API,已将认证方式设为“none”,但仍收到授权相关错误。Webhook使用HTTP POST方法。
Webhook示例请求体
{ "live": "false", "notificationItems": [ { "NotificationRequestItem": { "amount": { "currency": "EUR", "value": 0 }, "eventCode": "REPORT_AVAILABLE", "eventDate": "2022-11-22T15:19:37+01:00", "merchantAccountCode": "COM", "merchantReference": "testMerchantRef1", "pspReference": "1OW4XY4YXEFDLM0F", "reason": "将包含报告的URL", "success": "true" } } ] }
收到的错误响应
{"message":"Authorization header requires 'Credential' parameter. Authorization header requires 'Signature' parameter. Authorization header requires 'SignedHeaders' parameter. Authorization header requires existence of either a 'X-Amz-Date' or a 'Date' header. Authorization=Basic amFnYTYxOTBAZ21haWwuY29tOndJTERGSVJFQDEyMw=="}
API Gateway配置详情

解决方案
这个错误的核心原因是:API Gateway直接集成S3时,默认会要求请求携带AWS签名认证信息,但Adyen的Webhook不会生成这类签名。要解决这个问题,需要调整集成方式,让API Gateway绕过S3的签名验证,直接转发Webhook请求:
- 切换集成类型:将API Gateway的集成从「S3服务集成」改为「HTTP集成」,集成端点填写S3存储桶的REST地址(格式:
https://<你的桶名>.s3.<区域>.amazonaws.com)。 - 配置权限:给API Gateway的执行角色添加S3写入权限(比如
s3:PutObject),确保它能将Webhook内容存入S3。 - 设置请求映射:在集成请求的「Body Mapping Templates」中,添加
application/json模板,内容填写$input.json('$'),保证请求体完整转发。 - 处理头信息:在集成请求的「Headers」设置里,映射
Content-Type等必要头,避免S3因头信息缺失拒绝请求。
如果一定要用S3服务集成,也可以通过自定义集成请求参数来禁用签名,但这种方式稳定性较差,更推荐使用HTTP集成的方案。
内容的提问来源于stack exchange,提问作者Jaga Priyan
相关产品推荐
相关产品推荐

