> For the complete documentation index, see [llms.txt](https://docs.coda.co/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.coda.co/https-coda-payments.gitbook.io-zhong-wen-coda-private-technical-documentation/codapay/hou-duan-api-ji-cheng/direct-card-api-ji-cheng/ru-men-zhi-nan/ru-he-sheng-cheng-x-qian-ming.md).

# 如何生成 x 签名

对于每一笔费用请求通知，Coda 系统都会执行验证流程以确保其完整性。Coda 会将请求中&#x7684;***x-signature***&#x6807;头与请求正文的签名进行比较。如果签名不匹配，系统将拒绝该请求并返回错误。此流程旨在确保费用请求的完整性和安全性，降低有效载荷被篡改的风险。

**步骤：**

1. 将下列值以字符串形式附加到请求体上，格式如下：*“{requestTime}.{requestBody}”。例如：*

```
// Java
RequestTime = 1700486578888
RequestBody = {"type":"charge.status.succeeded","data":{"id":"evt_sg18c678ba5af0019"}}
String message =
"1700486578888.{"type":"charge.status.succeeded","data":{"id":"evt_sg18c678ba5af0019"}}"
```

2. 使用您的签名密钥作为密钥，计算字符串的 HMAC-SHA512 哈希值。签名密钥是为您的 Webhook 端点配置的预共享密钥。HMAC-SHA512 算法将返回一个字节数组值。

*例子：*

```
// Java
SigningSecret = "BbCVjTu59yVUMMon8mgN9C37piCGfijN"
```

3. 将字节数组值转换为十六进制字符串。结果类似于：

“a0c2d905877e9282a3954743f918f98f991c144020c535458c84767b6e146cf8 cad4433accc2047258f6d5c4be07264596cfc58cfeea9e8551090f26e828e6bd“

**验证签名**

1. 从 webhook 请求中提取 X-Request-Time 和 X-Signature 标头
2. 获取原始请求体字符串（未经任何解析）
3. 按照上述步骤 1-3 生成预​​期签名。
4. 使用恒定时间比较算法，将生成的签名与 X-Signature 标头值进行比较。
5. 验证 X-Request-Time 是否在可接受的时间范围内（例如，最近 5 分钟内），以防止重放攻击。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.coda.co/https-coda-payments.gitbook.io-zhong-wen-coda-private-technical-documentation/codapay/hou-duan-api-ji-cheng/direct-card-api-ji-cheng/ru-men-zhi-nan/ru-he-sheng-cheng-x-qian-ming.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
