调用Lazada商品拉取API返回IncompleteSignature签名错误求助
Lazada商品接口签名错误修复
问题场景
自有系统对接Lazada平台拉取商品数据,调用/products/get接口时返回签名不符合规范错误。
原实现代码
$region = "https://api.lazada.com.ph/rest"; $getproductitem = "/products/get"; $app_key = 110150; $date = new DateTime(); $timestamp = 1656029861000; $access_token = "token***"; $app_secret = "secret***"; $sign_method="sha256"; $base_str = $getproductitem.'access_token'.$access_token.'app_key'.$app_key.'sign_method'.$sign_method.'timestamp'.$timestamp; $sign = hash_hmac('sha256', $base_str, $app_secret, false); //$sign = hex(sha256($getproductitem.'access_token'.$access_token.'app_key'.$app_key.'sign_method'.$sign_method.'timestamp'.$timestamp)); //return $uri = "https://api.lazada.com.ph/rest/products/get?app_key=$app_key&access_token=$access_token&sign_method=$sign_method×tamp=$timestamp&sign=$sign"; $response = Http::get($region.$getproductitem, [ "app_key" => $app_key, "access_token" => $access_token, "sign_method" => $sign_method, "timestamp" => $timestamp, "sign" => $sign, ]); return $response->json();
错误响应
{ "type": "ISV", "code": "IncompleteSignature", "message": "The request signature does not conform to platform standards", "request_id": "212a721616560299294283218" }
错误原因排查
- 待签名基串缺失请求方法前缀:Lazada签名规则要求待签名字符串最开头必须拼接请求的HTTP方法,GET接口需要在API路径前加
GET,当前基串直接从接口路径/products/get开始拼接,是触发错误的核心原因。 - 参数未按ASCII规则排序:代码中写死了参数拼接顺序,正确逻辑是所有参与签名的参数(含公共参数、业务参数,排除sign本身)必须按参数名的ASCII字典序升序排列后再拼接,避免后续新增参数时再次触发签名错误。
- 签名结果大小写不符合要求:
hash_hmac函数第四个参数传false时默认返回小写十六进制串,Lazada要求签名结果为全大写十六进制字符串,需要对生成的签名做大写转换。 - 时间戳逻辑错误:代码中写死了固定时间戳,Lazada要求请求时间戳与平台服务器时间差不能超过15分钟,固定时间戳会直接触发签名校验失败,必须取请求发起时的实时13位毫秒级时间戳。
- 参数编码逻辑风险:参与签名的参数值必须使用原始值拼接,不要提前做URL编码,签名完成后发起HTTP请求时再做编码即可,使用Laravel Http客户端时会自动处理参数编码,无需手动操作。
修正后代码
$region = "https://api.lazada.com.ph/rest"; $apiPath = "/products/get"; $app_key = 110150; $access_token = "token***"; $app_secret = "secret***"; $sign_method = "sha256"; // 生成实时13位毫秒时间戳 $timestamp = intval(microtime(true) * 1000); // 组装所有请求参数(sign字段除外,所有公共参数、业务参数都要加入) $params = [ "app_key" => $app_key, "access_token" => $access_token, "sign_method" => $sign_method, "timestamp" => $timestamp, ]; // 按参数名ASCII字典序升序排序 ksort($params); // 拼接待签名基串:请求方法 + 接口路径 + 排序后的参数键值对 $baseStr = "GET" . $apiPath; foreach ($params as $key => $value) { $baseStr .= $key . $value; } // 生成签名并转大写 $sign = strtoupper(hash_hmac('sha256', $baseStr, $app_secret)); $params['sign'] = $sign; $response = Http::get($region . $apiPath, $params); return $response->json();
内容的提问来源于stack exchange,提问作者Skiemo Santelices
相关产品推荐
相关产品推荐

