Unity C#调用Poloniex私有交易API报‘invalid command’错误求助
Hey there, let's break down why you're hitting that 'invalid command' error and fix it step by step. I've dealt with this exact issue before when working with Poloniex's API, so here's what to check:
1. You're Missing (or Misspelling) the command Parameter
Poloniex's private APIs require a command parameter in your POST data, and it has to match their exact command names (like returnBalances, buy, sell—they're case-sensitive!). If you forget this parameter or typo the command name, you'll get this error immediately.
Make sure you're adding it to your form data like this:
formData.Add("command", "returnBalances"); // Replace with your target command
2. Wrong Request Method or Content-Type
Poloniex's private endpoints only accept POST requests, and you must set the Content-Type header to application/x-www-form-urlencoded. Using GET or skipping the content type will make the server fail to parse your command, leading to the error.
In Unity's UnityWebRequest, set this up correctly:
UnityWebRequest www = UnityWebRequest.Post("https://poloniex.com/tradingApi", formData); www.SetRequestHeader("Content-Type", "application/x-www-form-urlencoded");
3. Broken HMAC-SHA512 Signature
Private API requests need a valid HMAC-SHA512 signature generated from your POST data and API Secret. If your signature logic is wrong, the server might reject your request with a misleading 'invalid command' message (instead of a signature error, which is annoying!).
Here's a reliable signature generation method for your code:
private string GenerateSignature(Dictionary<string, string> postData, string secret) { // Convert form data to a URL-encoded string string postString = string.Join("&", postData.Select(kv => $"{kv.Key}={kv.Value}")); byte[] secretBytes = System.Text.Encoding.UTF8.GetBytes(secret); byte[] postBytes = System.Text.Encoding.UTF8.GetBytes(postString); using (HMACSHA512 hmac = new HMACSHA512(secretBytes)) { byte[] hashBytes = hmac.ComputeHash(postBytes); // Convert to lowercase hex string (Poloniex expects this format) return BitConverter.ToString(hashBytes).Replace("-", "").ToLower(); } }
4. Missing or Invalid nonce Parameter
Poloniex requires a nonce (a strictly increasing integer, usually using UTC timestamp in milliseconds) to prevent replay attacks. Skip this, or use a non-increasing value, and your request will fail.
Add it to your form data like this:
formData.Add("nonce", ((long)(DateTime.UtcNow - new DateTime(1970, 1, 1)).TotalMilliseconds).ToString());
5. Incorrect API Key Headers
Don't forget to attach your API Key and generated signature to the request headers. Without these, the server can't authenticate you, and you'll get errors (including 'invalid command').
Add these headers to your UnityWebRequest:
www.SetRequestHeader("Key", _apiKey); www.SetRequestHeader("Sign", generatedSignature);
Full Working Request Snippet
Here's how to put all this together in your existing script (filling in the gaps you left):
IEnumerator SendPoloniexPrivateRequest() { Dictionary<string, string> formData = new Dictionary<string, string>(); // Replace with the command you want to call formData.Add("command", "returnBalances"); // Add required nonce formData.Add("nonce", ((long)(DateTime.UtcNow - new DateTime(1970, 1, 1)).TotalMilliseconds).ToString()); // Generate valid signature string signature = GenerateSignature(formData, _apiSecret); // Setup POST request UnityWebRequest www = UnityWebRequest.Post("https://poloniex.com/tradingApi", formData); www.SetRequestHeader("Content-Type", "application/x-www-form-urlencoded"); www.SetRequestHeader("Key", _apiKey); www.SetRequestHeader("Sign", signature); yield return www.SendWebRequest(); // Handle response if (www.result != UnityWebRequest.Result.Success) { OutputText.text = $"Error: {www.error} | Response: {www.downloadHandler.text}"; } else { OutputText.text = $"Success! Response: {www.downloadHandler.text}"; } }
One last check: Make sure your API Key has the correct permissions enabled in the Poloniex dashboard (like trading, balance query, etc.). If permissions are missing, even a perfect request will get rejected.
内容的提问来源于stack exchange,提问作者DroneLord

