OKX request-signature failures often come from signing one representation of a request and sending another. Build the outgoing path and body once, then use those exact values for authentication and transport.
The authentication documentation specifies a Base64-encoded HMAC-SHA256 signature using the secret key over timestamp, uppercase method, request path and body. Requests carry the key, signature, timestamp and passphrase headers.
Preserve the signed bytes
For a query request, finalize parameter encoding and ordering before signing its path. Do not let a second serializer reorder parameters or change spaces after the signature has been computed. For a body request, serialize once; semantically identical JSON with different whitespace is still a different byte sequence.
Use the same timestamp string in the signature input and timestamp header. Keep server clocks synchronized. On a retry, create a fresh authenticated request according to the documented validity requirements rather than replaying stale headers indefinitely.
Keep secrets behind the application boundary
Perform signing in a backend component that holds the API secret. A browser bundle cannot keep that secret confidential. The backend should accept a constrained swap request, not an arbitrary URL and body that turns it into a general signing proxy.
Allowlist provider paths and methods, validate amounts and addresses, and apply your own request budget. These controls limit misuse of the application's provider access.
Debug without printing credentials
Compare sanitized method, path, timestamp format and body length between the signed request and actual transport. Use a digest of the serialized body when a byte-integrity check is needed. Do not log the secret, passphrase or complete authentication headers.
A deterministic fixture with a fixed timestamp and harmless sample request can expose serialization drift. Passing that fixture verifies your signing construction, not live account authorization or provider availability.
Sources & verification (1)
Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.
- Authentication
OKX HMAC construction and request headers
https://web3.okx.com/onchainos/dev-docs/home/api-access-and-usage