AI Agent Hub
Back to skills
Alipay Open Platform Key Tool icon

Alipay Open Platform Key Tool

Development Updated 2026.08.29

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md to install @user_ddb6809c/alipay-open-platform-keys.

About this skill

Problem

When integrating with the Alipay Open Platform, RSA2 key setup often breaks down at three points: choosing between public-key mode and certificate mode, validating that a local private/public PEM pair matches, and diagnosing whether signature or callback verification failures come from the app-side key, the Alipay platform key/certificate, or parameter encoding. This skill narrows the local key-preparation workflow to a scripted flow and reduces the risk of manually misconfiguring OpenSSL or committing private keys.

How It Works

  • Public-key mode: run scripts/generate_alipay_rsa2_keys.sh to generate the app private key and public PEM, upload the app public key in the console, and keep the Alipay public key for verification.
  • Certificate mode: add --cert and --subj (or ALIPAY_CSR_SUBJ) to generate the private key and app.csr, upload the CSR, download the app public-key certificate, Alipay public-key certificate, and root certificate if provided, then configure the SDK paths.
  • Pair validation: use scripts/verify_alipay_rsa2_keypair.sh or alipay_rsa2.rsa_keys_match locally to check whether the key pair matches; prefer local user execution to keep private keys out of the chat context.
  • Environment setup: common variables include ALIPAY_APP_ID, ALIPAY_APP_PRIVATE_KEY or *_PATH, and ALIPAY_PLATFORM_PUBLIC_KEY or *_PATH. Use --no-print in CI to reduce the chance that PEM material is echoed.

Boundaries And Caveats

The skill covers local key/CSR generation, workflow guidance, and troubleshooting hints, but it does not replace console-side key or certificate configuration, Alipay public key/certificate download, gateway permissions, or product signing. Ensure openssl is available; the scripts do not require Python. Do not commit private keys, and ignore *.pem, *.csr, and alipay_keys_* in .gitignore. For signature failures, separate request-side app key/certificate mismatches from callback-side stale Alipay keys/certificates or encoded parameters that alter the signable string.

Use Cases

  • Generate local RSA2 private and public PEM files before integrating Alipay payments and upload the app public key.
  • Use certificate mode with --cert to create an app CSR, then verify the downloaded app and Alipay certificates.
  • When signature verification fails, separate app key mismatch from stale Alipay public key or certificate.
  • Generate keys in CI with --no-print to keep private PEM material out of logs.

Best For

  • Java or Node backend engineers integrating Alipay payments who need to generate RSA2 keys and configure SDKs.
  • Platform engineers rotating Alipay app keys who need to distinguish public-key mode from certificate mode and create a CSR.
  • Backend developers troubleshooting callback signature failures who need to verify app and Alipay key/certificate matches.
  • Engineers maintaining CI payment integrations who need secure key generation without printing private PEMs.