Salesforce PubSub API认证异常:访问令牌无效的排查求助
解决Salesforce gRPC PubSub API开发者实例认证错误问题
问题概述
对接Salesforce开发者实例(Sandbox)的gRPC PubSub API时,收到认证错误:
An authentication exception occurred. Provide valid authentication via metadata headers
当前配置细节:
- 请求地址:
https://api.pubsub.salesforce.com:7443 - gRPC请求头:
accesstoken:从开发者实例获取的访问令牌instanceurl:https://blah-dev-ed.develop.my.salesforce.comtenantid:00xxxxxxxxxxxxx
- 令牌获取流程:授权码交换,授权端点为开发者实例的OAuth地址,令牌端点使用
login.salesforce.com - 已尝试权限范围:
api web openid offline_access id
解决方案
1. 替换为开发者实例专属的PubSub API地址
开发者实例(Sandbox)不能使用生产环境的PubSub地址,正确的Sandbox地址是:
api.pubsub.salesforce-sandbox.com:7443
2. 修正令牌获取的端点地址
你当前使用生产环境的令牌端点login.salesforce.com,这会导致生成的令牌无法在Sandbox环境的PubSub API中使用。必须替换为Sandbox专属的令牌端点:
https://test.salesforce.com/services/oauth2/token
权限范围保留api即可,这是PubSub API所需的核心权限,其他范围非必须。
3. 确认gRPC请求头的正确性
确保请求头的键名严格为小写(gRPC头大小写敏感),且参数值准确:
accesstoken:使用从Sandbox令牌端点获取的有效访问令牌instanceurl:必须是你的开发者实例完整URL(如https://blah-dev-ed.develop.my.salesforce.com)tenantid:你的Org ID(格式通常以00D开头)
4. 验证访问令牌有效性
调用开发者实例的用户信息端点验证令牌:
- 发送GET请求到
https://blah-dev-ed.develop.my.salesforce.com/services/oauth2/userinfo - 携带请求头:
Authorization: Bearer <你的访问令牌> - 检查返回结果中的
organization_id是否与tenantid一致,instance_url是否匹配你的开发者实例地址。
内容的提问来源于stack exchange,提问作者DomH
相关产品推荐
相关产品推荐

