View a markdown version of this page

故障診斷 AgentCore 付款 - Amazon Bedrock AgentCore

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

故障診斷 AgentCore 付款

本節提供使用 Amazon Bedrock AgentCore AWS 付款時常見錯誤的解決方案。

驗證錯誤

建立或更新付款資源時,服務會傳回 ValidationException。下表列出常見的驗證錯誤及其解決方法。

錯誤訊息 Resolution

roleArn must contain a valid account ID

roleArn 必須是具有 12 位數帳戶 ID 的有效 IAM 角色 ARN。驗證格式:arn:aws:iam::<accountId>:role/<roleName>。

roleArn must belong to your account

中的帳戶 ID roleArn 必須符合發起人的帳戶。不支援跨帳戶角色。

Invalid role ARN: {roleArn}

roleArn 無法剖析 。驗證 ARN 格式。

credentialProviderConfigurations list cannot be empty

在建立或更新付款連接器時,至少提供一個登入資料提供者組態。

credentialProviderArn is required but not found in the request

每個登入資料提供者組態都必須包含 credentialProviderArn。先使用建立登入資料提供者建立一個。

Connector type '{type}' does not match the provided credentialProviderConfiguration

登入資料提供者組態變體必須符合連接器類型。例如,CoinbaseCDP連接器需要 coinbaseCDP組態,而不是 stripePrivy。

也會強制執行欄位命名限制:

  • 付款管理員名稱必須以字母開頭,且只能包含英數字元 (最多 48 個字元)。

  • 付款連接器名稱遵循相同的規則,但也允許底線。

  • 描述允許英數字元和空格 (最多 4096 個字元)。

許可錯誤

錯誤訊息 Resolution

Access denied due to account security restrictions. Contact AWS Support for assistance.

您的帳戶已受到限制。請聯絡 AWS Support 以解決此問題。

Access denied for {CREATE|UPDATE} due to account security restrictions. Contact AWS Support for assistance.

您的帳戶處於有限存取狀態。允許讀取和列出操作,但建立和更新操作會受到限制,直到限制解決為止。

IAM SigV4 授權失敗

確保呼叫主體具有適當的bedrock-agentcore:許可。服務使用 SigV4 簽署搭配bedrock-agentcore簽署名稱。

PassRole 失敗

提供 時roleArn,發起人必須具有角色的iam:PassRole許可。角色的信任政策必須允許 bedrock-agentcore.amazonaws.com做為服務主體。

AWS Marketplace 訂閱錯誤

當您使用 Coinbase 做為付款提供者時,您的帳戶必須擁有 AWS Marketplace 中 Coinbase Wallets for AgentCore Payments 清單的有效訂閱。如果訂閱遺失,服務會傳回SubscriptionRequiredException具有 HTTP 403 狀態碼的 。

此錯誤會在兩個位置強制執行:

  • 當您使用 建立 Coinbase 付款連接器時CreatePaymentConnector。

  • 當您在資料平面上執行 Coinbase 錢包操作時,例如 CreatePaymentInstrument或 ProcessPayment。

例外狀況包括具有 AWS Marketplace 清單連結subscriptionUrl的欄位,以及識別需要訂閱之產品productName的欄位。

錯誤訊息 Resolution

SubscriptionRequiredException (HTTP 403)

您的帳戶沒有 Coinbase 的作用中 AWS Marketplace 訂閱。若要解決問題:

  1. 在錯誤中subscriptionUrl傳回的 開啟 AWS Marketplace 清單,或前往 Coinbase Wallets for AgentCore Payments 清單。

  2. 訂閱清單。訂閱身分需要 AWSMarketplaceManageSubscriptions許可。

  3. 訂閱處於作用中狀態後,請重試 操作。

如需詳細資訊,請參閱訂閱 Coinbase Wallets for AgentCore Payments in AWS Marketplace。

快速建立授權錯誤

快速建立可讓您設定 Coinbase 付款連接器,而無需自行管理登入資料。當您呼叫 時CreatePaymentConnector,服務會傳回 authorizationUrl。開啟 URL (或提供給您應用程式的使用者) 以完成 Coinbase 授權。在此流程中,連接器會移動至下列Quick-create-specific狀態:

  • PENDING_AUTHENTICATION  — 連接器正在等待您 (或您應用程式的使用者) 完成 Coinbase 授權。

  • PROVISIONING — 授權已完成,且服務正在佈建連接器。

  • AUTHENTICATION_EXPIRED — 在授權完成之前authorizationUrl已過期。

  • AUTHENTICATION_FAILED — Coinbase 授權未成功。

下表列出常見的快速建立授權問題及其解決方案。

連接器狀態 Resolution

連接器卡在 PENDING_AUTHENTICATION

快速建立授權尚未完成。若要解決問題:

  1. 開啟 authorizationUrl傳回的 CreatePaymentConnector。

  2. 登入並完成 Coinbase 授權。

中的連接器 AUTHENTICATION_EXPIRED

authorizationUrl 過期,大約會在 CreatePaymentConnector 傳回 10 分鐘後發生。若要解決問題:

  1. 使用 重新建立連接器CreatePaymentConnector,以取得新的 authorizationUrl。

  2. 開啟新的 authorizationUrl並立即完成 Coinbase 授權。

找不到資源錯誤

錯誤訊息 Resolution

Payment manager not found: {managerId}

指定的付款管理員不存在。呼叫 來驗證 IDListPaymentManagers。

Payment connector not found: connectorId={connectorId}, managerId={managerId}

指定的連接器不存在於指定的管理員下。使用 驗證兩個 IDsListPaymentConnectors。

在 期間找不到資源 CreatePaymentConnector

父系付款管理員不存在。首先建立付款管理員。

衝突錯誤

當ConflictException兩個請求同時修改相同的資源,或建立已存在的資源時,服務會傳回 。重試 請求。建立和更新操作支援 clientToken進行安全重試。

服務配額錯誤

當您達到帳戶的付款管理員或連接器數量上限"{limitType} limit exceeded for account {accountId}"時,服務會傳回 。刪除未使用的資源或聯絡 AWS Support 請求提高限制。

限流錯誤

當請求率超過允許的限制"Rate exceeded"時,服務會傳回 。在重試邏輯中實作具有抖動的指數退避。如果您持續達到限制,請聯絡 AWS Support。

付款處理錯誤

如果外部付款供應商拒絕簽署請求,服務會傳回 AccessDeniedException或 ValidationException。SubscriptionRequiredException 如果您的帳戶沒有 Coinbase 的作用中 AWS Marketplace 訂閱,付款處理也會失敗。下表列出常見的錯誤及其解決方法。

錯誤訊息 Resolution

Delegated signing grant is not active for the end user wallet. Please redirect end user to the WalletHub to grant the permissions.

您尚未授予委派許可,讓您的代理程式代表您簽署交易,或者您之前已將其撤銷。若要解決問題:

  1. 從 CreatePaymentInstrument或GetPaymentInstrument回應內文擷取 WalletHub URL (paymentInstrumentDetails.redirectUrl)。

  2. 將使用者重新導向至 WalletHub。

  3. 登入並將簽署許可授予代理程式。

如需處理委派授予流程之前端實作的詳細資訊,請參閱 GitHub 網站上的 Coinbase AgentCore 範本。如需為錢包提供資金的詳細資訊,請參閱為錢包提供資金。

Delegated signing is not enabled for your Coinbase project. Please enable delegated signing in your Coinbase project policies.

您的 Coinbase 開發人員平台專案未設定委派簽署。若要解決問題:

  1. 在 Coinbase 網站上登入 Coinbase 開發人員平台。

  2. 導覽至專案的政策設定。

  3. 啟用委派簽署切換。

您必須完成此步驟,您的代理才能代表使用者簽署交易。

Privy credentials are invalid. Please verify the credential configuration.

您的登入資料提供者具有無效或過期的 Privy 錢包授權金鑰。若要解決問題:

  1. 登入 Privy 網站上的 Privy 儀表板。

  2. 導覽至您應用程式的設定,並確認授權金鑰處於作用中狀態。

  3. 使用目前的金鑰更新 AgentCore Identity 中的登入資料提供者。若要這樣做,請在 Secrets Manager 中呼叫UpdatePaymentConnector或更新 AWS 秘密。

如需登入資料組態的詳細資訊,請參閱 GitHub 網站上的 Privy AgentCore 開發套件。

SubscriptionRequiredException (HTTP 403)

您的帳戶沒有 Coinbase 的作用中 AWS Marketplace 訂閱。針對 Coinbase 錢包處理付款需要作用中的訂閱,因此如果從未建立訂閱或稍後取消訂閱,可能會發生此錯誤。若要解決問題:

  1. 訂閱 Coinbase Wallets for AgentCore Payments 清單,或在錯誤中subscriptionUrl傳回的 開啟 AWS Marketplace 清單。

  2. 訂閱處於作用中狀態後,請重試付款。

如需詳細資訊,請參閱訂閱 Coinbase Wallets for AgentCore Payments in AWS Marketplace 和 AWS Marketplace 訂閱錯誤。

x402 付款請求錯誤

當您使用 x402 通訊協定處理付款時,服務會在保留預算或簽署paymentInput.cryptoX402之前驗證您轉送的付款承載。如果承載格式不正確或不受支援,服務會傳回 ValidationException且不會耗用預算。下表列出常見的 x402 付款請求錯誤及其解決方法。幾列描述執行時間或和解失敗,例如拒絕的 Permit2 額度交易,可能會在簽署開始後發生,而不是在簽署前驗證期間發生。

錯誤訊息 Resolution

X402 Payload for signing is invalid.

無法剖析或驗證 x402 付款承載。將商家的 x402 承載從402 Payment Required回應複製到paymentInput.cryptoX402完全相同的接收,無需修改。

Payment instrument network is required

付款工具不會指定網路。使用符合商家付款承載的網路建立付款工具。

Network mismatch '{network}' is not supported for paymentNetwork '{paymentNetwork}'. Supported networks: {networks}

付款工具的網路與承載中的網路不相符。使用網路符合商家付款請求的付款工具。

Payment currency is required

承載不會指定貨幣。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Currency '{currency}' is not supported. Supported currencies: {currencies}

承載會請求不支援的貨幣。使用請求支援貨幣的商家端點。

Payment amount is required

承載不會指定金額。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment amount must be a positive number. Received: {value}

承載數量不是正數。逐字轉送商家的承載;請勿修改金額。

Payment amount exceeds maximum allowed value. Received: {value}, Maximum: {max}

承載數量高於允許的最大值。使用金額在允許範圍內的商家端點。

Payment asset is required

承載不會指定資產。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment asset address is invalid. Expected valid address format for the specified network. Received: {value}

承載資產地址不是網路的有效地址。逐字轉送商家的承載;請勿修改資產地址。

Payment asset is not a supported USDC token address for network '{network}'. Received: {value}. Expected: {expected}

承載會為網路請求正式 USDC 以外的字符。使用請求正式 USDC 的商家端點,並確認付款工具的網路符合承載。

Payment scheme is required

承載不會指定結構描述。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment scheme not supported. Supported scheme: {scheme}

承載會請求不支援的結構描述。AgentCore 付款支援 exact和 upto方案。請參閱支付 x402 付款請求。

Payment scheme 'upto' is only supported on x402 protocol version 2

此upto方案需要 x402 通訊協定第 2 版。在 2中version將 設定為 paymentInput.cryptoX402,或使用支援第 2 版的商家端點。

Payment scheme 'upto' is only supported on EVM networks. Received network: {network}

僅在 EVM 網路上支援此upto方案。使用 EVM 網路上的商家端點進行upto配置。

permit2AllowanceLimit is only supported for payment scheme 'upto'. Received scheme: {scheme}

您permit2AllowanceLimit為 以外的配置設定 upto。permit2AllowanceLimit 僅為upto配置設定 。請參閱最多 筆付款的 Permit2 額度。

permit2AllowanceLimit must be a positive integer in the asset’s smallest denomination. Received: {value}

permit2AllowanceLimit 值不是正整數。在資產的最小面額中,以正整數提供額度。例如, 會以 6 個小數位數1000000授予 1 USDC,而 115792089237316195423570985008687907853269984665640564039457584007913129639935(uint256最大值) 授予無限制的額度。

付款供應商拒絕 Permit2 額度交易。

當 ProcessPayment廣播upto付款approve的交易時,錢包提供者可以拒絕它。例如,如果未授予委派簽署,或者如果來自相同錢包的先前交易尚未確認,則提供者可以拒絕。若要解決問題:

  1. 確認最終使用者已在 WalletHub 中授予代理程式簽署許可。請參閱本節前面的委派簽署授予錯誤,並為錢包提供資金並授予代理程式許可。

  2. 如果錢包剛獲得資金或使用,請等待幾秒鐘讓先前的交易確認,然後使用新的 重試clientToken。

  3. 如果錢包已核准使用 Permit2,請在後續呼叫permit2AllowanceLimit時省略 ,如此就不會廣播新的approve交易。

Payment payTo address is required

承載不會指定payTo地址。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment payTo address is invalid. Expected valid address format for the specified network. Received: {value}

承載payTo地址不是網路的有效地址。逐字轉送商家的承載;請勿修改payTo地址。

Payment maxTimeoutSeconds is required

承載不會指定 maxTimeoutSeconds。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment maxTimeoutSeconds must be positive. Received: {value}

承載maxTimeoutSeconds值不是正值。逐字轉送商家的承載;請勿修改該值。

Payment maxTimeoutSeconds {value} exceeds maximum allowed value of {max}

承載maxTimeoutSeconds值高於允許的最大值。使用逾時在允許範圍內的商家端點。

Payment feePayer is required for SVM payments

Solana (SVM) 付款的承載未指定 feePayer。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment extra field is required

承載不包含必要extra欄位。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment extra.name is required for EVM payments

EVM 付款的承載不包含 extra.name。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment extra.version is required for EVM payments

EVM 付款的承載不包含 extra.version。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment extra.facilitatorAddress is required for the upto scheme

upto 結構描述承載不包含 extra.facilitatorAddress。逐字轉送商家的承載。如果錯誤仍然存在,表示商家的承載格式錯誤;請聯絡商家。

Payment extra.facilitatorAddress is invalid. Expected valid address format for the specified network. Received: {value}

承載extra.facilitatorAddress不是網路的有效地址。逐字轉送商家的承載;請勿修改地址。

MPP 挑戰錯誤

當您使用機器付款通訊協定 (MPP) 處理付款時,服務會驗證您在 中轉送WWW-Authenticate: Payment的挑戰paymentInput.mpp。它會在持有預算或簽署之前驗證挑戰。如果挑戰格式錯誤、不支援或過期,服務會傳回 ValidationException,且不會耗用預算。下表列出常見的 MPP 挑戰錯誤及其解決方案。有些資料列描述執行時間或存取錯誤,例如錢包餘額不足、未啟用 MPP 存取,或登入資料建置失敗,而不是預先簽署驗證錯誤。

錯誤訊息 Resolution

MPP wwwAuthenticateHeaders is required and must contain exactly one WWW-Authenticate header.

為 wwwAuthenticateHeaders 欄位提供剛好一個標頭。逐字複製商家WWW-Authenticate: Payment的挑戰;不要傳送多個標頭。

WWW-Authenticate header is not a 'Payment' challenge.

轉送的標頭不是Payment挑戰。從商家的402 Payment Required回應轉送WWW-Authenticate標頭,而不修改其結構描述。

MPP challenge is missing required field: {field}

挑戰缺少必要欄位。對於 evm方法, methodDetails.chainId和 realm 都是必要的。在轉送之前,請確認商家的挑戰包含具名欄位。

MPP challenge 'request' is not valid base64url: {value}

挑戰request值不是有效的 base64url。轉送挑戰與商家傳回挑戰完全相同。請勿解碼、重新編碼或修改值。

MPP challenge 'request' is not valid JSON: {value}

解碼的挑戰request不是有效的 JSON。逐字轉送挑戰。如果錯誤仍然存在,表示商家的挑戰格式不正確;請聯絡商家。

MPP challenge 'id' exceeds the maximum allowed length of {max} characters. Received length: {length}.

挑戰id太長。轉送未修改的挑戰。如果錯誤仍然存在,表示商家的挑戰格式不正確;請聯絡商家。

MPP challenge methodDetails.chainId must be a JSON integer, not a string or decimal. Received: {value}

挑戰methodDetails.chainId中的 必須是 JSON 整數。逐字轉送挑戰;請勿引用或重新格式化值。

MPP challenge 'request' JSON contains a duplicate key, which is not allowed (RFC 8785 JCS requires unique member names): {key}

挑戰 request JSON 包含重複的金鑰。逐字轉送挑戰。如果錯誤仍然存在,表示商家的挑戰格式不正確;請聯絡商家。

MPP challenge WWW-Authenticate header contains a duplicate auth-param: {param}

WWW-Authenticate 標頭包含重複的參數。逐字轉送 標頭。如果錯誤仍然存在,表示商家的挑戰格式不正確;請聯絡商家。

MPP challenge field '{field}' contains a disallowed control character (0x{code}).

挑戰欄位包含不允許的控制字元。逐字轉送挑戰。如果錯誤仍然存在,表示商家的挑戰格式不正確;請聯絡商家。

MPP supports only the 'charge' intent. Received: {intent}

挑戰會請求不支援的意圖。AgentCore 付款僅支援 MPP 的charge意圖。

MPP supports only the 'evm', 'tempo', and 'solana' methods. Received: {method}

挑戰會請求不支援的付款方式。AgentCore 付款僅支援 MPP 的 tempo、 evm和 solana方法。

MPP supports only pull mode; challenge supportedModes did not include 'pull'.

挑戰不提供提取模式。AgentCore 付款僅支援 MPP 的提取模式。

MPP version is required.

在 中提供 version 欄位paymentInput.mpp。

MPP EVM/Tempo charge supports only the canonical USDC token on network '{network}'. Received currency: {currency}

挑戰會為網路請求正式 USDC 以外的字符。使用請求正式 USDC 的挑戰。確認付款工具的網路符合挑戰方法。

This MPP challenge does not offer seller-sponsored network fees (methodDetails.feePayer=false), so the blockchain network (gas) fees would be charged to the buyer’s wallet in addition to the payment amount. Set buyerPaysGasFees=true to authorize paying them, or obtain a challenge whose seller sponsors the fees.

賣方不贊助此挑戰的瓦斯費。設定 buyerPaysGasFees=true paymentInput.mpp以授權從買方錢包支付瓦斯,或取得賣方贊助費用的挑戰。當賣方不贊助費用時,tempo這是方法的必要項目。

MPP challenge has expired ('expires' is in the past). Obtain a fresh challenge and retry.

挑戰為短期且已過期。再次請求付費資源以取得新的挑戰,然後重試。過期的挑戰不會消耗任何預算。

MPP Solana charge supports only the 'mainnet' and 'devnet' networks. Received: {network}

Solana 挑戰會請求不支援的網路。AgentCore devnet 付款僅支援 mainnet和 Solana MPP 費用。

MPP Solana charge currently supports only server-sponsored fees (methodDetails.feePayer=true). Client-paid fees (feePayer=false) are not yet supported.

Solana 挑戰會請求客戶支付的費用。solana 方法目前僅支援伺服器贊助費用。使用賣方贊助費用的挑戰。

Solana MPP payments are not supported for Coinbase-managed payment instruments.

Coinbase CDP 付款工具不支援 solana方法。使用 Stripe (Privy) 付款工具支付 Solana MPP 費用。請參閱處理付款中每種方法的提供者支援。

Insufficient balance in the payer wallet to cover the token transfer and gas fee.

買方的錢包餘額不足以支付付款金額和網路 (瓦斯) 費用。使用額外的 USDC 為錢包提供資金。請參閱為錢包提供資金並授予代理程式許可。

Access to MPP (Machine Payments Protocol) payment processing is not enabled for this account. Contact AWS Support for access.

您的帳戶未啟用 MPP 付款處理。請聯絡 AWS Support 請求存取。

Failed to build MPP payment credential: {reason}

服務無法從挑戰中建置付款憑證。確認您已逐字轉送挑戰。如果錯誤仍然存在,請聯絡 AWS Support 並提供來自x-amzn-requestid回應標頭的請求 ID。

伺服器錯誤

服務"Something went wrong in processing your request"會針對內部錯誤傳回 。在短暫延遲後重試請求。如果錯誤仍然存在,請聯絡 AWS Support 並提供x-amzn-requestid回應標頭中的請求 ID。