配置Alexa智能家居技能账号关联时,能否使用HTTP协议的认证API?
Short answer: No—Alexa Smart Home Skills require HTTPS for all API endpoints involved in account linking and skill interactions, and HTTP endpoints are not supported.
Why You're Seeing That Error
The "Error: A URL must be between 9 and 2000 characters." message you're getting when trying to save an HTTP URL is a side effect of Alexa's underlying validation rules. The system first rejects any HTTP endpoint outright (due to security requirements), and this rejection triggers an invalid state that leads to the misleading length-related error. Even if your HTTP URL meets the character count, it will still fail validation because HTTP isn't allowed.
Official Requirements Breakdown
Alexa enforces HTTPS for all skill endpoints, including the Authorization URL and Access Token URI used in account linking, for critical security reasons:
- It ensures user authentication data (like tokens and credentials) is encrypted during transmission, preventing interception or tampering.
- The HTTPS certificate must be issued by a trusted certificate authority (CA)—self-signed certificates won't work for production skills.
Workarounds If You Only Have HTTP Endpoints
If your cloud service currently only exposes HTTP endpoints, here are practical options to comply with Alexa's requirements:
- Add HTTPS to your cloud service: Install a valid SSL certificate (from providers like Let's Encrypt, AWS Certificate Manager, etc.) and configure your server to handle HTTPS requests.
- Use a proxy service: Tools like AWS API Gateway can act as an HTTPS front-end for your HTTP endpoint. The gateway handles SSL termination with a trusted certificate, then forwards requests to your HTTP backend.
- Local testing exceptions: For development/testing, you might use tools like ngrok to create a temporary HTTPS tunnel to your local HTTP server. Note this is only for testing—production skills still require a permanent, trusted HTTPS endpoint.
内容的提问来源于stack exchange,提问作者Nidhish

