> ## Documentation Index
> Fetch the complete documentation index at: https://apidocs.returnhelper.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 获取 Signing Key

<Warning>
  此页面由 AI 自动翻译。API 技术规格以英文呈现为标准。如有任何疑问，请参阅[英文版本](/api-reference/apiaccount/get-signing-key)。
</Warning>

返回您所使用的 API Key 对应账户的签名密钥。该密钥为 Base64 编码，用于验证传入 webhook 通知的 `ReturnHelper-Signature` 请求头——它**不**用于验证您的 API 请求。

相同的值也会显示在 Return Helper 用户门户的 **Settings → Signing Key and API Token** 界面。若您希望以程序方式读取密钥，而不是从门户复制，请使用本端点。

<Warning>
  您的签名密钥属于机密信息。请妥善保管，切勿在客户端代码中暴露，也不要写入日志。
</Warning>

<h2 id="related">
  相关
</h2>

* [Webhooks → 签名验证](/zh-Hans/webhooks#signature-verification) — 密钥的使用方式。
* [认证](/zh-Hans/introduction#authentication) — API Key 与 Token，与签名密钥是不同的凭证。


## OpenAPI

````yaml get /api/ApiAccount/GetSigningKey
openapi: 3.1.0
info:
  title: Return Helper API
  description: API documentation for Return Helper — covering User and Public endpoints.
  version: 1.0.0
servers:
  - url: https://api.returnshelper.com/uat/user
    description: Sandbox — User API
  - url: https://api.returnshelper.com/uat/public
    description: Sandbox — Public API
  - url: https://api.returnhelpercentre.com/v1/user
    description: Production — User API
  - url: https://api.returnhelpercentre.com/v1/public
    description: Production — Public API
  - url: https://api.returnhelperchina.com/user
    description: Production — User API (China)
security:
  - ApiKey: []
    ApiToken: []
paths:
  /api/ApiAccount/GetSigningKey:
    get:
      tags:
        - ApiAccount
      summary: Get signing key
      operationId: ReturnUserApi_GetSigningKey
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/General_UserGetSigningKeyReply'
        '401':
          description: >-
            Authentication failed. Returned when the `x-rr-apikey` or
            `x-rr-apitoken` header is missing or invalid. The body uses the
            standard `ApiResponse` envelope with `meta.error.message` describing
            the auth failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse'
      security:
        - ApiKey: []
          ApiToken: []
      servers:
        - url: https://api.returnshelper.com/uat/user
          description: Sandbox — User API
components:
  schemas:
    General_UserGetSigningKeyReply:
      type: object
      properties:
        data:
          $ref: '#/components/schemas/UserGetSigningKeyReply'
    ApiResponse:
      type: object
      description: >-
        Universal response envelope. Successful responses include the business
        payload as additional top-level fields alongside `correlationId` and
        `meta`. Failed responses (auth errors, validation errors) only populate
        `correlationId` and `meta`, with `meta.errorCode` and `meta.error`
        describing the failure.
      properties:
        correlationId:
          type:
            - string
            - 'null'
          description: >-
            Unique correlation ID for tracing the request through Return Helper
            systems.
        meta:
          $ref: '#/components/schemas/ApiResponseMeta'
    UserGetSigningKeyReply:
      type: object
      properties:
        signingKey:
          type:
            - string
            - 'null'
          description: >-
            Base64-encoded signing key used to verify the ReturnHelper-Signature
            header on webhook notifications.
    ApiResponseMeta:
      type: object
      description: >-
        Application-level metadata for every API response. Inspect `status` and
        `errorCode` to detect soft-error responses (validation failures arrive
        as HTTP 200 with `meta.status: 400`).
      properties:
        status:
          type: integer
          description: >-
            Application-level status code. For successful operations this
            mirrors the HTTP status (e.g. 200). For validation failures it
            reports the logical status (e.g. 400) even though the wire HTTP
            status is 200.
        data:
          type: object
          additionalProperties:
            type: string
          description: Reserved free-form metadata key/value pairs. Usually empty.
        errorCode:
          type:
            - string
            - 'null'
          description: >-
            Machine-readable error code (e.g. `VALIDATION_FAILED`). Non-null
            only when the operation failed.
        error:
          type: object
          additionalProperties: true
          description: >-
            Field-level or message-level error detail keyed by request property
            name. Empty object on success.
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: x-rr-apikey
      description: Your API key
    ApiToken:
      type: apiKey
      in: header
      name: x-rr-apitoken
      description: Your API token — keep this private

````