You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

获取OneDrive文件下载OAuth授权码及刷新令牌遇阻求助

问题描述

用户目标是下载个人OneDrive所有文件,但在通过Azure AD获取访问令牌时遇到两个问题:

  1. 授权码模式请求令牌时,提示缺少code参数,不清楚该参数的定义及获取路径:
    运行代码:

    import requests
    
    token_params = {
        'client_id': 'ClientID',
        'grant_type': 'authorization_code',
        'scope': 'https://graph.microsoft.com/.default',
        'client_secret': 'ClientSecret',
        'redirect_uri': 'https://jwt.ms'
    }
    
    tenant = 'TenantID'
    token = requests.post(url=f'https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token', data=token_params)
    

    返回错误:

    "error":"invalid_request","error_description":"AADSTS900144: The request body must contain the following parameter: 'code'.
    
  2. 此前尝试刷新令牌模式,因refresh_token为空导致失败:
    运行代码:

    import requests
    
    params = {
              'grant_type': 'refresh_token',
              'client_id': 'ClientID',
              'refresh_token': ''
             }
    
    response = requests.post('https://login.microsoftonline.com/common/oauth2/v2.0/token', data=params)
    

    返回错误:

    "error":"invalid_request","error_description":"AADSTS900144: The request body must contain the following parameter: 'refresh_token'.
    

用户曾参考相关技术问答,但关联页面无法访问,急需解决令牌获取问题以推进文件下载任务。

解决方案

1. 明确核心参数作用

  • code:授权码,是用户完成身份验证并授权应用后,Azure AD返回的临时凭证,用于换取访问令牌(access_token)和刷新令牌(refresh_token)。
  • refresh_token:长期凭证,用于在access_token过期后(默认1小时),无需用户重新登录即可获取新的access_token。

2. 完整流程:从获取令牌到下载文件

步骤1:注册Azure AD应用

  • 登录Azure门户,搜索“应用注册”并创建新注册:
    • 名称自定义;
    • 支持账户类型选择“任何组织目录中的账户和个人Microsoft账户(例如Skype、Xbox)”;
    • 重定向URI选择“Web”,填写https://jwt.ms(需与后续代码保持一致);
  • 注册完成后,记录客户端ID(client_id);在“证书和密码”菜单创建客户端密码(client_secret),务必保存该密码(仅显示一次)。

步骤2:获取授权码code

构造授权URL,替换YOUR_CLIENT_ID为你的客户端ID:

https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=YOUR_CLIENT_ID&response_type=code&redirect_uri=https://jwt.ms&scope=Files.Read.All offline_access
  • 将URL复制到浏览器,用个人Microsoft账户登录并授权应用访问OneDrive;
  • 跳转至https://jwt.ms后,从浏览器地址栏提取code=xxxxxx部分的字符串,这就是所需的code。

步骤3:用code换取access_token和refresh_token

修改授权码模式代码,补充code参数:

import requests

token_params = {
    'client_id': '你的ClientID',
    'grant_type': 'authorization_code',
    'scope': 'Files.Read.All offline_access',
    'client_secret': '你的ClientSecret',
    'redirect_uri': 'https://jwt.ms',
    'code': '从地址栏提取的code'
}

response = requests.post(url='https://login.microsoftonline.com/common/oauth2/v2.0/token', data=token_params)
token_data = response.json()
print(token_data)  # 从中可获取access_token和refresh_token

步骤4:调用Graph API下载OneDrive文件

使用access_token请求文件列表并下载:

import requests

access_token = token_data['access_token']
headers = {'Authorization': f'Bearer {access_token}'}

# 获取根目录文件列表
folder_response = requests.get('https://graph.microsoft.com/v1.0/me/drive/root/children', headers=headers)
files = folder_response.json().get('value', [])

# 逐个下载文件
for file in files:
    if '@microsoft.graph.downloadUrl' in file:
        download_res = requests.get(file['@microsoft.graph.downloadUrl'])
        with open(file['name'], 'wb') as f:
            f.write(download_res.content)
        print(f"已下载:{file['name']}")

步骤5:用refresh_token刷新令牌

当access_token过期后,使用refresh_token获取新令牌:

refresh_params = {
    'grant_type': 'refresh_token',
    'client_id': '你的ClientID',
    'refresh_token': token_data['refresh_token'],
    'scope': 'Files.Read.All offline_access'
}

refresh_response = requests.post('https://login.microsoftonline.com/common/oauth2/v2.0/token', data=refresh_params)
new_token_data = refresh_response.json()
new_access_token = new_token_data['access_token']
new_refresh_token = new_token_data['refresh_token']  # 替换旧的refresh_token,下次刷新用这个

内容的提问来源于stack exchange,提问作者Saeed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 06:55:11