You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Lazada商品拉取API返回IncompleteSignature签名错误求助

Lazada商品接口签名错误修复

问题场景

自有系统对接Lazada平台拉取商品数据,调用/products/get接口时返回签名不符合规范错误。

原实现代码

$region = "https://api.lazada.com.ph/rest";
$getproductitem = "/products/get";
$app_key = 110150;
$date = new DateTime();
$timestamp = 1656029861000;
$access_token = "token***";
$app_secret = "secret***";
$sign_method="sha256";
$base_str = $getproductitem.'access_token'.$access_token.'app_key'.$app_key.'sign_method'.$sign_method.'timestamp'.$timestamp; 
$sign = hash_hmac('sha256', $base_str, $app_secret, false);
//$sign = hex(sha256($getproductitem.'access_token'.$access_token.'app_key'.$app_key.'sign_method'.$sign_method.'timestamp'.$timestamp));

//return $uri = "https://api.lazada.com.ph/rest/products/get?app_key=$app_key&access_token=$access_token&sign_method=$sign_method&timestamp=$timestamp&sign=$sign";

$response = Http::get($region.$getproductitem,  [
    "app_key" => $app_key,
    "access_token" => $access_token,
    "sign_method" => $sign_method,
    "timestamp" =>  $timestamp,
    "sign" => $sign,
]); 

return $response->json();

错误响应

{
"type": "ISV",
"code": "IncompleteSignature",
"message": "The request signature does not conform to platform standards",
"request_id": "212a721616560299294283218"
}

错误原因排查

  • 待签名基串缺失请求方法前缀:Lazada签名规则要求待签名字符串最开头必须拼接请求的HTTP方法,GET接口需要在API路径前加GET,当前基串直接从接口路径/products/get开始拼接,是触发错误的核心原因。
  • 参数未按ASCII规则排序:代码中写死了参数拼接顺序,正确逻辑是所有参与签名的参数(含公共参数、业务参数,排除sign本身)必须按参数名的ASCII字典序升序排列后再拼接,避免后续新增参数时再次触发签名错误。
  • 签名结果大小写不符合要求:hash_hmac函数第四个参数传false时默认返回小写十六进制串,Lazada要求签名结果为全大写十六进制字符串,需要对生成的签名做大写转换。
  • 时间戳逻辑错误:代码中写死了固定时间戳,Lazada要求请求时间戳与平台服务器时间差不能超过15分钟,固定时间戳会直接触发签名校验失败,必须取请求发起时的实时13位毫秒级时间戳。
  • 参数编码逻辑风险:参与签名的参数值必须使用原始值拼接,不要提前做URL编码,签名完成后发起HTTP请求时再做编码即可,使用Laravel Http客户端时会自动处理参数编码,无需手动操作。

修正后代码

$region = "https://api.lazada.com.ph/rest";
$apiPath = "/products/get";
$app_key = 110150;
$access_token = "token***";
$app_secret = "secret***";
$sign_method = "sha256";
// 生成实时13位毫秒时间戳
$timestamp = intval(microtime(true) * 1000);

// 组装所有请求参数(sign字段除外,所有公共参数、业务参数都要加入)
$params = [
    "app_key" => $app_key,
    "access_token" => $access_token,
    "sign_method" => $sign_method,
    "timestamp" => $timestamp,
];
// 按参数名ASCII字典序升序排序
ksort($params);

// 拼接待签名基串:请求方法 + 接口路径 + 排序后的参数键值对
$baseStr = "GET" . $apiPath;
foreach ($params as $key => $value) {
    $baseStr .= $key . $value;
}

// 生成签名并转大写
$sign = strtoupper(hash_hmac('sha256', $baseStr, $app_secret));
$params['sign'] = $sign;

$response = Http::get($region . $apiPath, $params);
return $response->json();

内容的提问来源于stack exchange,提问作者Skiemo Santelices

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.29 02:15:39