You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:请求提供GDAX API签名实现示例(含中间值与多请求类型)

GDAX (Coinbase Pro) API Signature Example with Intermediate Values

我明白你在实现GDAX API签名时遇到了麻烦——没有像Binance那样的假密钥预期签名来验证实现确实是个痛点。下面我给你一个Python的可运行示例,包含所有关键的中间值(预哈希字符串、原始HMAC字节等),用完全假的密钥,覆盖GET和POST两种请求类型,把每个编码细节和body的要求都讲清楚,你可以对照着调试你的Phix代码。

Background

GDAX的签名规则核心是:

签名 = Base64(HMAC-SHA256( Base64解码后的API Secret, 预哈希字符串 ))
预哈希字符串 = timestamp + HTTP_METHOD + request_path + request_body

所有字符串都使用UTF-8编码,timestamp是Unix时间戳(秒级,整数),request_body对于GET请求是空字符串,POST请求是JSON格式的请求体(要和发送的完全一致,不能有多余空格或换行)。

Fake Credentials (For Testing)

我们用以下假密钥来演示,你可以直接复用这些值来验证:

  • API_KEY: fake-api-key-123
  • API_SECRET: ZmFrZS1zZWNyZXQtYWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU2Nzg5(这是fake-secret-abcdefghijklmnopqrstuvwxyz0123456789的Base64编码)
  • PASSPHRASE: fake-passphrase-xyz

Python Example Code

这个代码会输出所有中间步骤,你可以直接运行,然后对比你的Phix实现的每一步结果:

import hmac
import hashlib
import base64

# Fake credentials
API_SECRET = "ZmFrZS1zZWNyZXQtYWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU2Nzg5"
DECODED_SECRET = base64.b64decode(API_SECRET)

def generate_gdax_signature(timestamp, method, request_path, body=""):
    # Step 1: Build prehash string
    prehash = f"{timestamp}{method}{request_path}{body}"
    print(f"Prehash String: {repr(prehash)}")
    
    # Step 2: Compute HMAC-SHA256
    hmac_digest = hmac.new(DECODED_SECRET, prehash.encode('utf-8'), hashlib.sha256).digest()
    print(f"Raw HMAC Digest (hex): {hmac_digest.hex()}")
    
    # Step 3: Encode digest to Base64
    signature = base64.b64encode(hmac_digest).decode('utf-8')
    return signature

# ------------------------------
# Test GET Request Example
# ------------------------------
print("\n=== GET Request Example (/accounts) ===")
timestamp = 1620000000  # Fixed Unix timestamp for reproducibility
method = "GET"
request_path = "/accounts"
body = ""  # GET requests have empty body

get_signature = generate_gdax_signature(timestamp, method, request_path, body)
print(f"Final Signature (Base64): {get_signature}")

# ------------------------------
# Test POST Request Example (/orders)
# ------------------------------
print("\n=== POST Request Example (/orders) ===")
timestamp = 1620000001
method = "POST"
request_path = "/orders"
# POST body must be the exact JSON string sent (no extra whitespace!)
body = '{"type":"limit","side":"buy","product_id":"BTC-USD","price":"50000","size":"0.001"}'

post_signature = generate_gdax_signature(timestamp, method, request_path, body)
print(f"Final Signature (Base64): {post_signature}")

Key Details to Verify in Your Phix Implementation

  • Encoding: 确保所有字符串(预哈希、body)都用UTF-8编码成字节后再参与HMAC计算
  • API Secret Handling: 必须先对Secret进行Base64解码,得到原始字节后再作为HMAC的密钥
  • Body for GET: GET请求的body必须是空字符串,不能省略或用null
  • Body for POST: 必须使用和发送到API完全一致的JSON字符串——不能有多余的空格、换行,键值对的顺序也要完全匹配(GDAX会严格校验这一点)
  • Timestamp: 必须是Unix时间戳(秒级,整数),而且要和请求头里的CB-ACCESS-TIMESTAMP完全一致

Debug Tips

如果你的签名和示例不一致,一步步对比:

  1. 检查预哈希字符串是否完全和示例中的一致(包括timestamp、method大小写、路径、body)
  2. 检查API Secret的Base64解码是否正确
  3. 检查HMAC计算时的输入字节是否正确(UTF-8编码的预哈希字符串)
  4. 检查最终的HMAC字节是否正确Base64编码成字符串

内容的提问来源于stack exchange,提问作者Pete Lomax

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:22:36