You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用curl调用Coinbase Sandbox API /accounts接口遇无效签名问题

Coinbase Sandbox API 签名无效问题解决

问题描述

调用Coinbase Sandbox API的/accounts接口获取账户列表时,始终返回{"message":"invalid signature"}错误,尝试多种签名计算方式均无效,原始脚本如下:

#!/usr/bin/env bash

TS=$(date +%s)
API_KEY=fbb28bed4617217f482d878770b8c9b7
PASSPHRASE="passphrase87867"
SECRET="apcep9z66jyW3koh5uHhnq0hKQ5q59EBgTtpZ/GsvN9aigrFbxMpuz+YP7xXo/ev+OBZpqmv4OpCk7OKx6qGbw=="
URL="https://api-public.sandbox.exchange.coinbase.com/accounts"
#https://api.exchange.coinbase.com/accounts \
#https://api-public.sandbox.pro.coinbase.com/accounts \

SIG=$(echo "${TS}GET/accounts" | hmac256 --binary $API_KEY | base64)
#SIG=$(echo "${TS}GET/accounts" | hmac256 --binary $SECRET | base64)
#also tried with PASSPHRASE & SECRET and without base64:
#SIG=$(echo "${TS}GET/accounts" | hmac256 $PASSPHRASE)
#SIG=$(echo "${TS}GET/accounts" | hmac256 $SECRET)

curl --request GET \
     --url $URL \
     --header 'Accept: application/json' \
     --header "cb-access-key: $API_KEY" \
     --header "cb-access-passphrase: $PASSPHRASE" \
     --header "cb-access-sign: $SIG" \
     --header "cb-access-timestamp: $TS"

核心问题与解决步骤

1. 签名计算的三个关键错误

  • 必须使用API Secret(而非API Key或Passphrase)作为HMAC加密密钥
  • echo命令默认会追加换行符,破坏签名字符串完整性,必须加-n参数
  • 部分环境的hmac256工具行为不明确,建议用通用的openssl工具计算

2. 正确的签名计算命令

SIG=$(echo -n "${TS}GET/accounts" | openssl dgst -sha256 -hmac "${SECRET}" -binary | base64)
  • -n:禁止echo添加换行符,保证签名字符串完全匹配要求
  • -hmac "${SECRET}":指定API Secret为加密密钥
  • -binary:输出二进制HMAC结果,再通过base64编码(Coinbase要求签名为base64格式)

3. 其他注意事项

  • 时间戳需用UTC时区:TS=$(date -u +%s),避免本地时区与服务器时间差超过30秒导致验证失败
  • 确认API密钥、Passphrase、Secret均为Sandbox环境生成,勿混用生产环境密钥
  • 接口URL保持为https://api-public.sandbox.exchange.coinbase.com/accounts

修正后的完整脚本

#!/usr/bin/env bash

# 使用UTC时间戳,避免时区偏差
TS=$(date -u +%s)
API_KEY=fbb28bed4617217f482d878770b8c9b7
PASSPHRASE="passphrase87867"
SECRET="apcep9z66jyW3koh5uHhnq0hKQ5q59EBgTtpZ/GsvN9aigrFbxMpuz+YP7xXo/ev+OBZpqmv4OpCk7OKx6qGbw=="
URL="https://api-public.sandbox.exchange.coinbase.com/accounts"

# 正确计算签名
SIG=$(echo -n "${TS}GET/accounts" | openssl dgst -sha256 -hmac "${SECRET}" -binary | base64)

curl --request GET \
     --url "$URL" \
     --header 'Accept: application/json' \
     --header "cb-access-key: $API_KEY" \
     --header "cb-access-passphrase: $PASSPHRASE" \
     --header "cb-access-sign: $SIG" \
     --header "cb-access-timestamp: $TS"

内容的提问来源于stack exchange,提问作者Henry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 01:25:23