连接亚马逊SP-API时遇InvalidSignature错误求助
亚马逊SP-API InvalidSignature错误排查求助
尝试连接亚马逊SP-API已达一周,始终受困于InvalidSignature错误,多次查阅官方文档仍未定位问题根源。使用亚马逊提供的Python签名示例代码测试:取消注释EC2相关配置后,调用DescribeRegions接口可正常运行;但使用SP-API的ListOrders接口配置时,就会触发签名不匹配错误。原应用基于Java开发,同样出现该错误。
测试代码
# Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. # SPDX-License-Identifier: Apache-2.0 """ Important The AWS SDKs sign API requests for you using the access key that you specify when you configure the SDK. When you use an SDK, you don’t need to learn how to sign API requests. We recommend that you use the AWS SDKs to send API requests, instead of writing your own code. The following example is a reference to help you get started if you have a need to write your own code to send and sign requests. The example is for reference only and is not maintained as functional code. """ # AWS Version 4 signing example # EC2 API (DescribeRegions) # See: http://docs.aws.amazon.com/general/latest/gr/sigv4_signing.html # This version makes a GET request and passes the signature # in the Authorization header. import sys, os, base64, datetime, hashlib, hmac import requests # pip install requests # ************* REQUEST VALUES ************* method = 'GET' service = 'execute-api' host = 'sellingpartnerapi-na.amazon.com' region = 'us-east-1' endpoint = 'https://sellingpartnerapi-na.amazon.com' request_parameters = 'Action=ListOrders&MarketplaceId=ATVPDKIKX0DER&Version=0' #service = 'ec2' #host = 'ec2.amazonaws.com' #region = 'us-east-1' #endpoint = 'https://ec2.amazonaws.com' #request_parameters = 'Action=DescribeRegions&Version=2013-10-15' # Key derivation functions. See: # http://docs.aws.amazon.com/general/latest/gr/sigv4-examples.html#signature-v4-examples-python def sign(key, msg): return hmac.new(key, msg.encode('utf-8'), hashlib.sha256).digest() def getSignatureKey(key, dateStamp, regionName, serviceName): kDate = sign(('AWS4' + key).encode('utf-8'), dateStamp) kRegion = sign(kDate, regionName) kService = sign(kRegion, serviceName) kSigning = sign(kService, 'aws4_request') return kSigning # Read AWS access key from env. variables or configuration file. Best practice is NOT # to embed credentials in code. access_key = 'AKIEXAMPLE' secret_key = 'SECRETEXAMPLE' if access_key is None or secret_key is None: print('No access key is available.') sys.exit() # Create a date for headers and the credential string t = datetime.datetime.utcnow() amzdate = t.strftime('%Y%m%dT%H%M%SZ') datestamp = t.strftime('%Y%m%d') # Date w/o time, used in credential scope # ************* TASK 1: CREATE A CANONICAL REQUEST ************* # http://docs.aws.amazon.com/general/latest/gr/sigv4-create-canonical-request.html # Step 1 is to define the verb (GET, POST, etc.)--already done. # Step 2: Create canonical URI--the part of the URI from domain to query # string (use '/' if no path) canonical_uri = '/orders/v0/orders' # Step 3: Create the canonical query string. In this example (a GET request), # request parameters are in the query string. Query string values must # be URL-encoded (space=%20). The parameters must be sorted by name. # For this example, the query string is pre-formatted in the request_parameters variable. canonical_querystring = request_parameters # Step 4: Create the canonical headers and signed headers. Header names # must be trimmed and lowercase, and sorted in code point order from # low to high. Note that there is a trailing \n. canonical_headers = 'host:' + host + '\n' + 'x-amz-date:' + amzdate + '\n' # Step 5: Create the list of signed headers. This lists the headers # in the canonical_headers list, delimited with ";" and in alpha order. # Note: The request can include any headers; canonical_headers and # signed_headers lists those that you want to be included in the # hash of the request. "Host" and "x-amz-date" are always required. signed_headers = 'host;x-amz-date' # Step 6: Create payload hash (hash of the request body content). For GET # requests, the payload is an empty string (""). payload_hash = hashlib.sha256(('').encode('utf-8')).hexdigest() # Step 7: Combine elements to create canonical request canonical_request = method + '\n' + canonical_uri + '\n' + canonical_querystring + '\n' + canonical_headers + '\n' + signed_headers + '\n' + payload_hash # ************* TASK 2: CREATE THE STRING TO SIGN************* # Match the algorithm to the hashing algorithm you use, either SHA-1 or # SHA-256 (recommended) algorithm = 'AWS4-HMAC-SHA256' credential_scope = datestamp + '/' + region + '/' + service + '/' + 'aws4_request' string_to_sign = algorithm + '\n' + amzdate + '\n' + credential_scope + '\n' + hashlib.sha256(canonical_request.encode('utf-8')).hexdigest() # ************* TASK 3: CALCULATE THE SIGNATURE ************* # Create the signing key using the function defined above. signing_key = getSignatureKey(secret_key, datestamp, region, service) # Sign the string_to_sign using the signing_key signature = hmac.new(signing_key, (string_to_sign).encode('utf-8'), hashlib.sha256).hexdigest() # ************* TASK 4: ADD SIGNING INFORMATION TO THE REQUEST ************* # The signing information can be either in a query string value or in # a header named Authorization. This code shows how to use a header. # Create authorization header and add to request headers authorization_header = algorithm + ' ' + 'Credential=' + access_key + '/' + credential_scope + ', ' + 'SignedHeaders=' + signed_headers + ', ' + 'Signature=' + signature # The request can include any headers, but MUST include "host", "x-amz-date", # and (for this scenario) "Authorization". "host" and "x-amz-date" must # be included in the canonical_headers and signed_headers, as noted # earlier. Order here is not significant. # Python note: The 'host' header is added automatically by the Python 'requests' library. headers = {'x-amz-date':amzdate, 'Authorization':authorization_header} # ************* SEND THE REQUEST ************* request_url = endpoint + '?' + canonical_querystring print('\nBEGIN REQUEST++++++++++++++++++++++++++++++++++++') print('Request URL = ' + request_url) r = requests.get(request_url, headers=headers) print('\nRESPONSE++++++++++++++++++++++++++++++++++++') print('Response code: %d\n' % r.status_code) print(r.text)
完整错误信息
{ "errors": [ { "message": "The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details.", "code": "InvalidSignature" } ] }
排查关键点
- 请求URL路径不匹配:代码中
canonical_uri设置为/orders/v0/orders,但实际请求URL是endpoint + '?' + canonical_querystring,没有带上该路径。签名计算的URI和实际请求的URI不一致,这是导致签名错误的核心原因。正确的请求URL应为:endpoint + canonical_uri + '?' + canonical_querystring。 - 接口参数格式错误:SP-API的ListOrders接口要求的
Version参数格式应为YYYY-MM-DD(如2021-08-01),而非Version=0,错误的参数会导致查询字符串哈希计算不符。 - 服务名称验证:确认SP-API对应区域的签名服务名是否为
execute-api,部分场景可能需要核对官方签名要求。 - 时间同步问题:确保本地时间与UTC时间同步,
x-amz-date的时间与服务器时间差超过5分钟会触发签名验证失败。 - 签名计算细节:检查
canonical_headers的换行符、小写格式是否正确;确认credential_scope中的日期、区域、服务名与实际请求完全一致;验证payload_hash的计算逻辑(GET请求为空字符串的SHA256哈希)。
内容的提问来源于stack exchange,提问作者ChalsBP
相关产品推荐
相关产品推荐

