You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

生成设备Token时遇‘Signature mismatch’错误,请求细节排查

Fixing "Signature mismatch" Error for HERE Tracking Device Token Requests

Hey, let's walk through the issues here since you've already ruled out timestamp problems. The most obvious red flag I see is a parameter mismatch that's definitely causing the signature failure:

1. Nonce & Timestamp Don't Match Between Headers and Signature Base String

Look closely at your values:

  • In your request Authorization header, you're using oauth_nonce="LIIBLApk88" and oauth_timestamp="1558262091"
  • But the base string you used to generate the signature has oauth_nonce="LIIBLApk5" and oauth_timestamp="1558260025"

OAuth relies on these values to prevent replay attacks, so they must be identical in both places. Even a single character difference in the nonce or a timestamp mismatch will make the signature invalid immediately.

2. Double-Check Your Signature Base String Build

Make sure you're following OAuth 1.0a rules to the letter when constructing the base string:

  • Use uppercase for the HTTP method (POST — you have this right)
  • The encoded URL must exactly match the endpoint you're hitting (your https%3A%2F%2Ftracking.api.here.com%2Fv2%2Ftoken looks correct, but no typos allowed!)
  • Sort all OAuth parameters (excluding oauth_signature) lexicographically by key, URL-encode each key-value pair, then join them with &
    • Your parameter order looks good, but confirm there are no accidental spaces or incorrect encoding (e.g., missing % characters)

3. Verify Your Signature Key

You said your signature key is {Device secret}& — make sure:

  • You've replaced {Device secret} with your actual device secret (not leaving the placeholder in there!)
  • The trailing & is included (this is required in OAuth 1.0 when there's no token secret, which is the case for token requests)
  • You're using the key as-is for HMAC-SHA256 (don't URL-encode the key itself unless the API explicitly says to)

4. Regenerate the Signature with Correct Parameters

Let's fix the base string first to match your headers. Your corrected base string should be:

POST&https%3A%2F%2Ftracking.api.here.com%2Fv2%2Ftoken&oauth_consumer_key%3Dac85020f-c352-4ac9-853e-4b64f3645463%26oauth_nonce%3DLIIBLApk88%26oauth_signature_method%3DHMAC-SHA256%26oauth_timestamp%3D1558262091%26oauth_version%3D1.0

Then generate the HMAC-SHA256 signature using your real device secret plus the trailing &, and plug that new signature into your oauth_signature header.

That should resolve the signature mismatch since the core issue here is the nonce/timestamp inconsistency between your base string and request headers.

内容的提问来源于stack exchange,提问作者Elic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 07:42:29