Laravel与Postman调用N-Genius网关获取AccessToken报400错误求助
Problem Context
When implementing the N-Genius payment gateway's access token request in a Laravel project using the provided PHP/cURL code, a 400 Bad Request error with badTokenRequest is returned. The same error occurs in Postman.
Code Used
$apikey = "[your-api-key]"; // enter your API key here $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://api-gateway.sandbox.ngenius-payments.com/identity/auth/access-token"); curl_setopt($ch, CURLOPT_HTTPHEADER, array( "accept: application/vnd.ni-identity.v1+json", "authorization: Basic ".$apikey, "content-type: application/vnd.ni-identity.v1+json" )); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, "{\"realmName\":\"ni\"}"); $output = json_decode(curl_exec($ch)); $access_token = $output->access_token;
Error Response
{ "message": "Bad Request", "code": 400, "errors": [ { "message": "Bad token request", "localizedMessage": "Bad token request", "errorCode": "badTokenRequest", "domain": "identity" } ] }
Solutions
Here are the key fixes and checks to resolve this issue:
1. Correctly Encode the API Key for Basic Auth
N-Genius requires the API key (formatted like sk_xxxx) to be Base64-encoded with a trailing colon : for Basic Authentication. This follows the standard Base64("username:password") format, where the password field is left empty for N-Genius.
Incorrect:
"authorization: Basic ".$apikey,
Correct:
$encodedApiKey = base64_encode($apikey . ':'); // Add to headers "authorization: Basic " . $encodedApiKey,
2. Use Reliable JSON Generation for Request Body
Manual JSON string concatenation can lead to hidden syntax errors. Replace the hardcoded string with json_encode:
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode(["realmName" => "ni"]));
3. Validate API Key and Environment
- Ensure you're using a sandbox environment API key (not a production key).
- Verify the API key is copied correctly from the N-Genius merchant dashboard, with no extra spaces or characters.
4. Full Fixed Code Example
$apikey = "sk_your_valid_sandbox_api_key"; $encodedApiKey = base64_encode($apikey . ':'); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://api-gateway.sandbox.ngenius-payments.com/identity/auth/access-token"); curl_setopt($ch, CURLOPT_HTTPHEADER, array( "accept: application/vnd.ni-identity.v1+json", "authorization: Basic " . $encodedApiKey, "content-type: application/vnd.ni-identity.v1+json" )); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode(["realmName" => "ni"])); // Add curl error handling for debugging if(curl_errno($ch)) { die('Curl Error: ' . curl_error($ch)); } $response = curl_exec($ch); curl_close($ch); $output = json_decode($response); if(isset($output->access_token)) { $access_token = $output->access_token; // Proceed with token usage } else { var_dump($output); // Inspect full error details }
5. Postman Configuration Check
If Postman also fails, verify these settings:
- Go to the Authorization tab, select
Basic Auth, enter your API key as the username, and leave the password field blank. - Add these headers:
accept: application/vnd.ni-identity.v1+jsoncontent-type: application/vnd.ni-identity.v1+json
- Set the body to
raw>JSONand input{"realmName":"ni"}.
内容的提问来源于stack exchange,提问作者Mohammed Ali

