请求OneDrive Access Token时遭遇AADSTS70000错误求排查
OneDrive获取Access Token时AADSTS70000错误(code无效)排查
我正在用Python脚本调用API将PDF文件上传到个人OneDrive账户,已按官方流程通过授权端点拿到了授权码,但请求Access Token时返回AADSTS70000错误,提示:
The provided value for the
codeparameter is not valid.
我的凭证定义和请求脚本如下:
# onedrive credentials onedrive_id = "example-ABCD" #application (client) ID onedrive_secret = "example-1234" onedrive_scopes = ["Files.ReadWrite.All"] redirect_uri = "https://login.live.com/oauth20_desktop.srf" auth_code = "example-XYZ" token_endpoint = "https://login.microsoftonline.com/consumers/oauth2/v2.0/token"
import requests def onedrive_access(): # data for the token request token_data = { "client_id": onedrive_id, "redirect_uri": redirect_uri, "client_secret": onedrive_secret, "code": auth_code, "grant_type": "authorization_code", } result = requests.post(token_endpoint, data=token_data) if result.status_code == 200: token_response = result.json() access_token = token_response.get('access_token') refresh_token = token_response.get('refresh_token') print("Access Token: ", access_token) print("Refresh Token: ", refresh_token) else: print(f"Failed to obtain access token: {result.status_code}") print(result.text)
我已确认:请求体包含文档要求的必填参数client_id、redirect_uri、client_secret和code;redirect_uri与Azure目录中注册的一致;授权码从获取到使用仅耗时1-2分钟,不存在过期问题。请问该错误可能由哪些原因导致?
可能的原因排查:
- 授权码已被使用:授权码是一次性凭证,无论第一次请求成功还是失败,再次使用同一个code都会触发无效错误,必须重新获取新的授权码。
- Scope不匹配:获取授权码的请求中,必须包含和换token时一致的scope(即
Files.ReadWrite.All)。如果授权码生成时未指定该scope,或者scope不一致,会导致code验证失败。 - 应用类型配置错误:由于你使用了桌面应用专用的redirect_uri(
https://login.live.com/oauth20_desktop.srf),需确认Azure应用注册时是否选择了「桌面和设备」类型。若误选Web应用类型,会导致授权码无法被正确验证。 - 授权码编码问题:获取授权码时如果存在URL编码(比如包含
%20等转义字符),未正确解码就直接传入请求,会导致code值无效。检查auth_code是否是完整、解码后的字符串。 - 租户/端点不匹配:个人OneDrive需使用
consumers租户的端点,确认获取授权码时的端点和换token的端点是否一致,避免混用工作/学校账户的端点。
内容的提问来源于stack exchange,提问作者T.PC
相关产品推荐
相关产品推荐

