You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NodeJs实现支付网关交易签名验证 参考Python代码签名不匹配问题

签名验证失败解决办法

你的代码核心错误是签名输出的编码格式和官方要求不匹配:

  • 官方Python实现中,HMAC-SHA256计算完成后是对原始二进制结果做Base64编码生成最终签名
  • 你当前Node.js代码调用hmac.digest('hex')是把结果转为十六进制字符串,和要求的Base64格式完全不符,所以验证失败

修正后的Node.js实现代码

const crypto = require('crypto');

// 替换为你的真实应用密钥
const appSecret = "你的实际appSecret";
// 严格按照官方要求的顺序拼接参数
const signatureData = request.body.orderId + request.body.orderAmount + request.body.referenceId + request.body.txStatus + request.body.paymentMode + request.body.txMsg + request.body.txTime;
// 生成Base64格式的签名
const generatedSignature = crypto.createHmac('sha256', appSecret)
    .update(signatureData, 'utf8')
    .digest('base64');
// 校验签名
const isSignatureValid = generatedSignature === request.body.cashfreeSignature;
console.log(isSignatureValid);

其他校验注意事项

  • 确认参数拼接顺序和官方要求完全一致,不要调换任意参数位置
  • 确认你使用的appSecret和商户后台配置的密钥完全一致,无多余空格、大小写错误
  • 确认request.body中的参数值为回调原始值,没有被服务端框架自动转义

内容的提问来源于stack exchange,提问作者Nanda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.07 10:57:02