基于MPGS接入Google Pay支付时的签名验证与解密问题
Google Pay接入MPGS时签名验证与token解密失败问题
我们正在推进一个项目,拟通过MasterCard Payment Gateway Services(MPGS)作为处理方接入Google Pay支付功能。已获取Google与MPGS的商户ID,可正常唤起Google Pay窗口,窗口内显示提示:"App is currently running within a test environment"。遵循MPGS官方文档集成,但发起支付时收到MPGS返回的两类错误:
- 无法验证Google Pay payment token的签名
- Google Pay paymentToken数据无法解密
以下是唤起Google Pay窗口的部分代码:
const baseRequest = { apiVersion: 2, apiVersionMinor: 0 }; function initializeGooglePay() { const tokenizationSpecification = { type: 'PAYMENT_GATEWAY', parameters: { 'gateway': 'mpgs', 'gatewayMerchantId': 'mpgs-id' } }; const allowedCardNetworks = ["AMEX", "DISCOVER", "INTERAC", "JCB", "MASTERCARD", "MIR", "VISA"]; const allowedCardAuthMethods = ["PAN_ONLY", "CRYPTOGRAM_3DS"]; const baseCardPaymentMethod = { type: 'CARD', parameters: { allowedAuthMethods: allowedCardAuthMethods, allowedCardNetworks: allowedCardNetworks } }; cardPaymentMethod = Object.assign( { tokenizationSpecification: tokenizationSpecification }, baseCardPaymentMethod ); paymentsClient = new google.payments.api.PaymentsClient({ environment: document.getElementById('gpEnvironment').value }); isReadyToPayRequest = Object.assign({}, baseRequest); isReadyToPayRequest.allowedPaymentMethods = [baseCardPaymentMethod]; }
排查与解决方向
1. 环境与商户ID一致性校验
- 确认Google Pay的
environment参数(代码中取自gpEnvironment元素值)与MPGS接入环境完全匹配:测试环境用MPGS沙箱商户ID,生产环境用正式商户ID,混用会直接导致签名验证失败。 - 核实Google Pay控制台配置的商户ID已与MPGS后台完成绑定关联,二者未关联会使MPGS无法校验token签名。
2. Tokenization参数修正
- 将
tokenizationSpecification中的gatewayMerchantId替换为实际MPGS商户ID,代码中占位符mpgs-id需替换为真实值。 - 确认
gateway字段严格为'mpgs',拼写错误会导致MPGS无法识别token格式,引发解密失败。
3. MPGS后台密钥与证书配置
- 在MPGS后台确认已正确上传Google Pay对应的公钥证书,缺失或错误的证书会导致MPGS无法验证token签名。
- 检查MPGS后台配置的加密密钥是否与Google Pay生成token时使用的密钥一致,密钥不匹配会造成paymentToken解密失败。
4. 请求数据完整性检查
- 确保发起支付时,Google Pay返回的完整
paymentData已传递给MPGS,字段缺失或篡改会触发签名/解密错误。 - 确认
apiVersion和apiVersionMinor参数(当前为2和0)与MPGS支持的版本兼容,若MPGS后台限制版本需调整对应参数。
内容的提问来源于stack exchange,提问作者mr-nobody
相关产品推荐
相关产品推荐

