使用Google Apps Script调用Amazon API时请求签名不匹配求助
Hey there, let's tackle this signature mismatch error you're facing when calling Amazon's UK Marketplace API from Google Apps Script. This is one of the most common (and frustrating) issues with AWS-style APIs, so let's break down the key areas to check:
1. Fix Timestamp & Time Sync Issues
Amazon requires your request's Timestamp to be within 15 minutes of its server time (UTC), and formatted exactly as YYYY-MM-DD'T'HH:mm:ss'Z' (no milliseconds!). Google Apps Script's default date methods might add milliseconds or use local time, which breaks this.
Use this snippet to generate a compliant timestamp:
const now = new Date(); const timestamp = Utilities.formatDate(now, "UTC", "yyyy-MM-dd'T'HH:mm:ss'Z'");
Avoid new Date().toISOString() here—it includes milliseconds, which Amazon rejects.
2. Verify Your "String to Sign"
The signature starts with a base string that must be perfectly formatted. Any tiny deviation (wrong order, bad encoding, missing characters) will cause a mismatch. Double-check these components:
- HTTP Method: Must be uppercase (
GET, notget) - Hostname: UK Marketplace uses
mws.amazonservices.co.uk(no extra slashes or typos) - Request Path: For Orders API v2013-09-01, this is
/Orders/2013-09-01 - Sorted & Encoded Parameters: All parameters must be sorted by ASCII value, with both key and value encoded per RFC 3986. Use this helper function to encode correctly (Google's default
encodeURIComponentmisses some required escapes):
Sort your parameter keys alphabetically, then build the string likefunction encodeRFC3986(str) { return encodeURIComponent(str) .replace(/!/g, '%21') .replace(/'/g, '%27') .replace(/\(/g, '%28') .replace(/\)/g, '%29') .replace(/\*/g, '%2A'); }key1=encodedValue1&key2=encodedValue2.
3. Check Secret Access Key & Signature Calculation
- Ensure your AWS Secret Access Key has no extra spaces, newlines, or formatting errors (copy-paste mistakes are super common here!). If you're storing it in GAS Script Properties, confirm the value is exactly as provided by Amazon.
- When generating the signature, use HMAC-SHA256 and correctly convert the result to Base64. Here's the proper GAS code:
Don't forget to URL-encode the final signature before adding it to your request parameters.const stringToSign = `${HTTP_METHOD}\n${HOST}\n${PATH}\n${ENCODED_PARAMS}`; const signatureBytes = Utilities.computeHmacSha256Signature(stringToSign, SECRET_KEY); const signature = Utilities.base64Encode(signatureBytes);
4. Confirm All Required Parameters Are Present & Correct
Make sure you're including every mandatory parameter, with exact casing:
AWSAccessKeyId: Your Amazon access keyAction: Should beGetOrderfor fetching a single orderVersion:2013-09-01(match the Orders API version you're using)Timestamp: The compliant UTC timestamp we generated earlierSignatureVersion:2SignatureMethod:HmacSHA256MarketplaceId.Id.1:A1F83G8C2ARO7P(UK marketplace ID)AmazonOrderId.Id.1: Your target order ID (XXX-XXXXXX-XXXXXX)
Amazon's API is case-sensitive—even a lowercase marketplaceId instead of MarketplaceId will break things.
5. Validate the API Endpoint
Double-check you're sending the request to the correct UK endpoint:https://mws.amazonservices.co.uk/Orders/2013-09-01
Using the wrong region's endpoint (like US's mws.amazonservices.com) will definitely cause signature failures.
Pro Tip for Debugging
Print out your full stringToSign and compare it against Amazon's documentation examples line by line. Even a single extra space or wrong character will be the culprit.
内容的提问来源于stack exchange,提问作者edward

