ICOBench API请求头HMAC签名带参数时失效问题咨询
I’ve run into similar signed API headaches before—let’s walk through your two problems: invalid signatures when adding parameters, and the API acting like it never got your params (returning page 0). Here’s what to check:
1. You’re Probably Signing the Wrong Parameter String
ICOBench’s HMAC SHA384 signature relies on hashing the exact JSON payload you send plus your private key. The most common mistakes here are:
- Whitespace mismatches: If you’re pretty-printing your JSON for debugging but sending minified JSON to the API, you’re signing a different string than what the API sees. Always use the exact, unmodified JSON string that’s included in your request. For example, use
json.dumps(params, separators=(",", ":"))in Python to avoid extra spaces. - Unsorted keys: Even though JSON is technically unordered, some APIs require you to sort parameter keys alphabetically before stringifying. Check ICOBench’s docs—if they mention this, sort your params first (e.g.,
sorted(params.items())in Python) before turning them into a string. - Typos or extra characters: A trailing comma, capitalization error in a field name, or missing quote will make your signature completely invalid. Print out the string you’re signing and compare it line-by-line to what you’re sending.
Here’s a solid example workflow for generating the signature correctly:
import hmac import hashlib import json private_key = "your_actual_private_key" params = {"page": 1, "per_page": 20} # 1. Create the exact JSON string that will be sent payload_str = json.dumps(params, separators=(",", ":")) # No indent, no extra spaces # 2. Combine with private key (as per ICOBench's requirement) signing_data = payload_str + private_key # 3. Generate HMAC SHA384 signature signature = hmac.new( private_key.encode("utf-8"), signing_data.encode("utf-8"), hashlib.sha384 ).hexdigest()
2. You Might Be Sending Params in the Wrong Place
You said you’re adding parameters to the URL, but most signed APIs (like ICOBench) expect parameters to be sent in the request body (as JSON) instead of the query string. If you’re appending ?page=1 to the URL, the API might not be reading those params at all—hence returning the default page 0.
Double-check the API docs: almost all HMAC-signed APIs use POST requests with the payload in the body, because query strings are easier to tamper with and harder to sign consistently.
3. Confirm You’re Sending the Signature in the Right Header
Make sure you’re passing the generated signature in the HTTP header that ICOBench specifies. Common headers are X-Signature or Authorization, but it’s specific to their API. If you’re putting the signature in the wrong header, the API won’t validate it at all.
4. Test with a Super Simple Payload
Start with a minimal parameter set (like {"page": 1}) to eliminate complexity. Print out the payload string and signing data, then use an online HMAC SHA384 tool to verify your code generates the same signature. This will tell you if your signature logic is broken, or if the issue is with how you’re sending the request.
内容的提问来源于stack exchange,提问作者filip.s

