Quickpay API回调报错:HTTP_QUICKPAY_CHECKSUM_SHA256未定义如何赋值?
Hey there, let's clear up this confusion around the HTTP_QUICKPAY_CHECKSUM_SHA256 variable and fix that "Undefined index" error.
What is HTTP_QUICKPAY_CHECKSUM_SHA256?
This variable is not something you set manually — it's an HTTP request header automatically added by the Quickpay servers when they send a callback to your configured URL.
Quickpay generates this header by signing the raw request body with your account's private key using HMAC-SHA256, just like your sign() function does. The purpose is to let you verify that the callback actually came from Quickpay (not a malicious actor).
Why are you seeing the "Undefined index" error?
There are a few common reasons for this:
- No actual callback was sent: If you're testing locally without triggering a real Quickpay event (like a test payment completion), Quickpay hasn't sent any request to your endpoint. The header only exists when Quickpay's servers hit your URL.
- PHP server configuration filters headers: Some server setups restrict which HTTP headers are exposed in the
$_SERVERsuperglobal. Check yourphp.inifor thevariables_ordersetting — it needs to include the letterE(for environment variables, which includes HTTP headers). For example:variables_order = "GPCS E" - Case/naming mismatch: Quickpay sends the header as
Quickpay-Checksum-Sha256, and PHP automatically converts it toHTTP_QUICKPAY_CHECKSUM_SHA256(replacing hyphens with underscores, uppercasing, and prefixing withHTTP_). Double-check you didn't misspell this in your code (you seem to have it right, but it's worth confirming).
How to fix it
Ensure Quickpay is configured correctly:
- Log into your Quickpay account, go to your payment setup, and verify that your callback URL is correctly entered.
- Trigger a test event (like a successful test payment) to make sure Quickpay sends the callback to your endpoint.
Alternative ways to fetch the header:
If$_SERVERdoesn't expose the header, use PHP'sgetallheaders()function (works on most servers) to retrieve it directly:function sign($base, $private_key) { return hash_hmac("sha256", $base, $private_key); } $request_body = file_get_contents("php://input"); $headers = getallheaders(); // Use null coalescing to avoid undefined index errors $quickpayChecksum = $headers['Quickpay-Checksum-Sha256'] ?? ''; $checksum = sign($request_body, "your_account_private_key"); if ($checksum === $quickpayChecksum) { // Request is authenticated } else { // Request is NOT authenticated }Local testing tip:
Use a tool like Postman or curl to simulate Quickpay's callback request. Manually add theQuickpay-Checksum-Sha256header with a signature you generate yourself (using your private key and the test request body) to validate your code works.
Important Note
Always make sure you're using your actual Quickpay account private key (not a placeholder) and that you don't modify the raw request body before generating your checksum — even minor changes (like extra whitespace) will make the signatures mismatch.
内容的提问来源于stack exchange,提问作者Lars M

