生成设备Token时遇‘Signature mismatch’错误,请求细节排查
Hey, let's walk through the issues here since you've already ruled out timestamp problems. The most obvious red flag I see is a parameter mismatch that's definitely causing the signature failure:
1. Nonce & Timestamp Don't Match Between Headers and Signature Base String
Look closely at your values:
- In your request Authorization header, you're using
oauth_nonce="LIIBLApk88"andoauth_timestamp="1558262091" - But the base string you used to generate the signature has
oauth_nonce="LIIBLApk5"andoauth_timestamp="1558260025"
OAuth relies on these values to prevent replay attacks, so they must be identical in both places. Even a single character difference in the nonce or a timestamp mismatch will make the signature invalid immediately.
2. Double-Check Your Signature Base String Build
Make sure you're following OAuth 1.0a rules to the letter when constructing the base string:
- Use uppercase for the HTTP method (
POST— you have this right) - The encoded URL must exactly match the endpoint you're hitting (your
https%3A%2F%2Ftracking.api.here.com%2Fv2%2Ftokenlooks correct, but no typos allowed!) - Sort all OAuth parameters (excluding
oauth_signature) lexicographically by key, URL-encode each key-value pair, then join them with&- Your parameter order looks good, but confirm there are no accidental spaces or incorrect encoding (e.g., missing
%characters)
- Your parameter order looks good, but confirm there are no accidental spaces or incorrect encoding (e.g., missing
3. Verify Your Signature Key
You said your signature key is {Device secret}& — make sure:
- You've replaced
{Device secret}with your actual device secret (not leaving the placeholder in there!) - The trailing
&is included (this is required in OAuth 1.0 when there's no token secret, which is the case for token requests) - You're using the key as-is for HMAC-SHA256 (don't URL-encode the key itself unless the API explicitly says to)
4. Regenerate the Signature with Correct Parameters
Let's fix the base string first to match your headers. Your corrected base string should be:
POST&https%3A%2F%2Ftracking.api.here.com%2Fv2%2Ftoken&oauth_consumer_key%3Dac85020f-c352-4ac9-853e-4b64f3645463%26oauth_nonce%3DLIIBLApk88%26oauth_signature_method%3DHMAC-SHA256%26oauth_timestamp%3D1558262091%26oauth_version%3D1.0
Then generate the HMAC-SHA256 signature using your real device secret plus the trailing &, and plug that new signature into your oauth_signature header.
That should resolve the signature mismatch since the core issue here is the nonce/timestamp inconsistency between your base string and request headers.
内容的提问来源于stack exchange,提问作者Elic

