apache/seatunnel · error · DingTalkConnectorException
GET_SIGN_FAILED
GET_SIGN_FAILED
Error message
Get signature from DinkTalk server failed
What it means
When secret-key signing mode is enabled, getSign computes an HmacSHA256 signature over '<timestamp>\n<secret>' and URL-encodes the base64 result. Any exception (NoSuchAlgorithmException, InvalidKeyException, charset problems) is wrapped as DingTalkConnectorException(GET_SIGN_FAILED, 'Get signature from DinkTalk server failed').
Solutions
- Check the secret value: non-empty, correct SEC... key copied from the DingTalk robot 'sign' security setting
- Verify the JVM supports HmacSHA256 (default JCE policy); use a standard JDK
- Confirm the secret contains no trailing whitespace or newlines from copy-paste
Example fix
// before secret = "" // empty -> InvalidKeyException // after secret = "SECxxxxxxxxxxxxxxxxxxxxxxxx"
Defensive patterns
Strategy: validation
Validate before calling
if (secret == null || secret.trim().isEmpty()) { throw new IllegalStateException("DingTalk secret must be the non-empty SEC... key from the robot sign setting"); } Try / catch
try { writer.write(row); } catch (DingTalkConnectorException e) { if ("GET_SIGN_FAILED".equals(e.getErrorCode())) log.error("Signature computation failed - check secret/JCE", e); throw e; } Prevention
- Copy the secret exactly from the DingTalk robot security config, no trailing whitespace
- Use a standard JDK with default JCE policy (HmacSHA256 available)
- Prefer webhook token auth over sign mode if signing keeps failing
When it happens
Trigger: Calling getSign (via sign) when Mac.getInstance("HmacSHA256") or mac.init fails, or the secret is null/empty causing SecretKeySpec construction to throw — any failure while computing the signature for the secured robot webhook.
Common situations: Blank or malformed secret in the sink config (SecretKeySpec rejects empty keys); JVM lacking HmacSHA256 (restricted crypto policies); trailing whitespace/newlines in copy-pasted secrets.
Related errors
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/b6abff212e87145a.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-connectors-v2/connector-dingtalk/src/main/java/org/apache/seatunnel/connectors/seatunnel/sink/DingTalkWriter.java:102
e);
}
}
public String getUrl() throws IOException {
Long timestamp = System.currentTimeMillis();
String sign = getSign(timestamp);
return url + "×tamp=" + timestamp + "&sign=" + sign;
}
public String getSign(Long timestamp) throws IOException {
try {
String stringToSign = timestamp + "\n" + secret;
Mac mac = Mac.getInstance("HmacSHA256");
mac.init(new SecretKeySpec(secret.getBytes(StandardCharsets.UTF_8), "HmacSHA256"));
byte[] signData = mac.doFinal(stringToSign.getBytes(StandardCharsets.UTF_8));
return URLEncoder.encode(Base64.getEncoder().encodeToString(signData), "UTF-8");
} catch (Exception e) {
throw new DingTalkConnectorException(
DingTalkConnectorErrorCode.GET_SIGN_FAILED,
"Get signature from DinkTalk server failed",
e);
}
}
}
}
View on GitHub (pinned to cf67b549a7)