You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用BitUnix API修改保证金模式时出现10007签名错误

BitUnix API修改保证金模式时签名错误(错误码10007)

调用BitUnix期货账户修改保证金模式的API时,始终返回签名错误,错误信息如下:

{'code': 10007, 'data': None, 'msg': 'Signature Error'}

相关Python代码如下:

def auth_headers(self, query_params: dict = None, body: dict = None) -> dict:
    """
    Generate signed authentication headers for Bitunix API using strict formatting:
    - query_params: dict used in signature (for GET requests or query parameters)
    - body: dict used in signature (for POST requests)
    """
    import json
    import hashlib

    def sha256_hex(input_string):
        return hashlib.sha256(input_string.encode('utf-8')).hexdigest()

    # Generate nonce (32-bit random string) and timestamp
    nonce = str(int(time.time() * 1000))[-6:]  # Last 6 digits like "123456"
    timestamp = str(int(time.time() * 1000))  # Milliseconds timestamp

    # 1. Sort query params in ascending ASCII order by key
    query_str = ""
    if query_params:
        # Convert all values to strings and sort by key
        sorted_params = sorted(query_params.items())
        query_str = ''.join(f"{k}{str(v)}" for k, v in sorted_params)

    # 2. Convert body to string with no spaces (if present)
    body_str = "uid1234"
    if body:
        body_str = json.dumps(body, separators=(',', ':'), ensure_ascii=True)
        print(body_str)

    # 3. First hash: SHA256(nonce + timestamp + apiKey + queryParams + body)
    pre_digest = nonce + timestamp + self.api_key + query_str + body_str
    digest = sha256_hex(pre_digest)

    # 4. Final sign: SHA256(digest + secretKey)
    sign = sha256_hex(digest + self.secret_key)

    # Debug info
    print("Nonce:", nonce)
    print("Timestamp:", timestamp)
    print("Query String:", query_str)
    print("Body String:", body_str)
    print("Pre-digest:", pre_digest)
    print("Digest:", digest)
    print("Sign:", sign)

    return {
        'api-key': self.api_key,
        'sign': sign,
        'nonce': nonce,
        'timestamp': timestamp,
        'Content-Type': 'application/json'
    }


def change_marginmode(self):
    """
    Change margin mode following the exact signature pattern from documentation.
    """
    url = 'https://fapi.bitunix.com/api/v1/futures/account/change_margin_mode'
        
    # Query parameters must be included in signature
    query_params = {
        "symbol": "BTCUSDT",
        "marginCoin": "USDT",
        "marginMode": "ISOLATION"
    }

问题排查与修复方案

1. 修正Nonce生成规则

BitUnix要求nonce是32位随机字符串,当前代码生成的是6位数字,不符合要求。替换为标准生成方式:

import secrets
nonce = secrets.token_hex(16)  # 生成32位十六进制随机字符串

2. 移除Body默认固定值

当前代码默认body_str = "uid1234",空body时应使用空字符串,否则会引入无关内容导致签名错误:

body_str = ""
if body:
    body_str = json.dumps(body, separators=(',', ':'), ensure_ascii=True)

3. 核对签名拼接顺序

严格按照BitUnix官方文档的签名规则调整pre_digest的拼接顺序,部分交易所要求顺序为timestamp + nonce + apiKey + ...,而非当前的nonce + timestamp + ...,需以官方文档为准。

4. 补全请求发送逻辑

change_marginmode方法仅定义了参数,未完成请求发送。以POST请求为例(参数放在body中),补充完整逻辑:

def change_marginmode(self):
    url = 'https://fapi.bitunix.com/api/v1/futures/account/change_margin_mode'
    
    # POST请求参数放在body中
    body = {
        "symbol": "BTCUSDT",
        "marginCoin": "USDT",
        "marginMode": "ISOLATION"
    }
    
    headers = self.auth_headers(body=body)
    
    # 发送请求(需提前安装requests库)
    import requests
    response = requests.post(url, headers=headers, json=body)
    print(response.json())

5. 校准服务器时间

确保本地服务器时间与UTC时间同步,timestamp偏差过大也会触发签名错误,可通过NTP服务校准时间。

6. 验证签名算法细节

  • 确认所有参与签名的参数(query/body)都已正确转成字符串并按ASCII升序排序;
  • 检查两次SHA256哈希的拼接逻辑是否与文档完全一致;
  • 确认API密钥和Secret Key未输入错误或泄露。

内容的提问来源于stack exchange,提问作者LennyH

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 03:23:21