Github App用户访问令牌调用SSH公钥创建API权限问题排查
问题排查:GitHub App令牌调用创建SSH公钥API报权限错误
背景
我正在开发一个项目,不想让用户手动生成个人访问令牌(Personal Access Token)——用户需要选择正确权限并手动复制,出错概率太高。我改用GitHub App完成认证,已验证流程可行:
- 将用户引导至授权地址:
https://github.com/login/oauth/authorize?client_id=<GITHUB_APP_CLIENT_ID> - 用户点击授权按钮后,会重定向到指定回调端点,获取
code参数 - 携带
code向https://github.com/login/oauth/access_token发送POST请求,请求体如下:
{ "client_id": "fohgljbgkjsfbglfghdif", "client_secret": "sd,gjhralighrlgugfiljdgkdfgdifydfighidsds", "code": "dgusifughodshgodlsbvjdbv" }
- 该请求成功返回令牌:
access_token=ghu_sfiuhdsuighfdisbgsdgdhsdshjsdfshdjf&expires_in=28800&refresh_token=ghr_fhiugigudsgisugdigusdig&refresh_token_expires_in=15724800&scope=&token_type=bearer
遇到的错误
我的核心需求是调用GitHub创建SSH公钥API,使用上述令牌发送请求后报错:
/tmp % curl -L -X POST -H "Accept: application/vnd.github+json" -H "Authorization: Bearer ghu_sfiuhdsuighfdisbgsdgdhsdshjsdfshdjf" -H "X-GitHub-Api-Version: 2022-11-28" https://api.github.com/user/keys -d '{"title":"ssh-rsa AAAAB3NzaC1yc2EAAA","key":"2Sg8iYjAxxmI2LvUXpJjkYrMxURPc8r+dB7TJyvv1234"}'
错误响应:
{ "message": "Resource not accessible by integration", "documentation_url": "https://docs.github.com/rest/users/keys#create-a-public-ssh-key-for-the-authenticated-user" }
已排查内容
- 确认该错误与令牌权限相关,我拥有GitHub App的控制权
- 已按照文档要求配置
write:public_key权限,权限配置截图如下:
- 旧Stack Overflow问题因GitHub令牌权限更新已不适用,求当前可行的排查方向
内容的提问来源于stack exchange,提问作者notacorn
相关产品推荐
相关产品推荐

