You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Coinbase V2交易接口分页用CDP JWT认证返回401,首页正常

使用CDP密钥通过JWT Bearer认证(ES256)调用Coinbase App V2接口的分页问题

我目前使用CDP密钥通过JWT Bearer认证(ES256)调用Coinbase App V2接口,而非旧版CB-ACCESS-* HMAC头,遇到了分页相关的认证问题,详情如下:

正常请求

以下请求均返回200 OK:

  • GET /v2/user
  • GET /v2/accounts/BTC
  • GET /v2/accounts/ETH
  • GET /v2/accounts/USD
  • GET /v2/accounts/{account_id}/transactions(仅第一页)

示例:

  • GET /v2/accounts/BTC返回有效的BTC钱包账户对象
  • ETH和USD账户的同类请求同理

调用GET /v2/accounts/<btc_account_id>/transactions时,返回200 OK并附带分页信息:

{
  "ending_before": null,
  "limit": 25,
  "next_starting_after": "<cursor_id>",
  "next_uri": "/v2/accounts/<btc_account_id>/transactions?starting_after=<cursor_id>",
  "order": "desc",
  "previous_ending_before": null,
  "previous_uri": null,
  "starting_after": null
}

失败请求

以下两种请求均返回401 Unauthorized:

  • GET /v2/accounts/<btc_account_id>/transactions?starting_after=<cursor_id>
  • 直接调用返回的next_uri

BTC、ETH、USD账户均存在此问题。

Python示例代码

import json, time, secrets, jwt, requests
from urllib.parse import urlencode

with open("cdp_api_key.json") as f:
    cfg = json.load(f)

key_name = cfg["name"]
private_key = cfg["privateKey"]

def auth_get(path, params=None):
    q = ""
    if params:
        q = "?" + urlencode(params)
    full = f"{path}{q}"

    now = int(time.time())
    payload = {
        "sub": key_name,
        "iss": "cdp",
        "nbf": now,
        "exp": now + 120,
        "uri": f"GET api.coinbase.com{full}",
    }
    headers = {
        "kid": key_name,
        "nonce": secrets.token_hex(16),
    }
    token = jwt.encode(payload, private_key, algorithm="ES256", headers=headers)

    return requests.get(
        "https://api.coinbase.com" + path,
        headers={"Authorization": f"Bearer {token}"},
        params=params,
        timeout=30,
    )

r1 = auth_get("/v2/accounts/<btc_account_id>/transactions")
cursor = r1.json()["pagination"]["next_starting_after"]

r2 = auth_get(
    "/v2/accounts/<btc_account_id>/transactions",
    {"starting_after": cursor},
)

print(r1.status_code)  # 200
print(r2.status_code)  # 401
print(r2.text)

额外观察

  • GET /v2/user请求正常,显示Coinbase用户关联旧真实账户
  • GET /v2/accounts请求返回结果不完整,未包含BTC/ETH/USD账户
  • 但直接调用GET /v2/accounts/BTC、ETH、USD可正常获取账户信息
  • 部分带查询参数的/v2/accounts请求也会从200变为401

技术问询

是否有人成功使用CDP JWT认证实现Coinbase App V2交易接口的分页功能?我希望确定以下哪种情况导致问题:

  1. 存在查询参数时uri声明格式错误;
  2. CDP密钥不支持V2分页或该功能存在故障;
  3. 这些接口仅通过OAuth用户令牌才能正常分页。

内容的提问来源于stack exchange,提问作者Sobo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.01 17:14:51