PayPal OAuth2获取发票权限被拒,求正确Scope及查询方式
PayPal OAuth2调用发票接口权限拒绝问题排查
问题情况
我尝试通过已登录用户的PayPal OAuth2身份调用发票列表接口,执行以下curl命令:
curl -v -X GET https://api-m.paypal.com/v2/invoicing/invoices\?total_required\=true \ -H 'Authorization: Bearer <ACCESS_TOKEN>' \ -H 'Content-Type: application/json'
返回权限拒绝错误:
{"localizedMessage":"No permission for the requested operation. ","suppressed":[],"name":"PERMISSION_DENIED","message":"No permission for the requested operation. ","details":[{"field":null,"value":null,"location":null,"issue":"No permission for the requested operation. ","description":null}],"information_link":"https://developer.paypal.com/docs/classic/products/permissions/","debug_id":"3b3e0813dca9f"}%
查看Access Token响应,确实缺少发票相关权限:
{ "scope": "https://uri.paypal.com/services/checkout/one-click-with-merchant-issued-token https://uri.paypal.com/services/payments/realtimepayment https://uri.paypal.com/services/payments/payment/authcapture openid profile https://uri.paypal.com/services/payments/refund https://api.paypal.com/v1/vault/credit-card https://uri.paypal.com/services/reporting/search/read https://api.paypal.com/v1/vault/credit-card/.* https://uri.paypal.com/services/subscriptions https://uri.paypal.com/services/applications/webhooks https://uri.paypal.com/services/paypalattributes email", "access_token": "MY_ACCESS_TOKEN", "token_type": "Bearer", "expires_in": 28800, "refresh_token": "MY_REFRESH_TOKEN", "nonce": "2023-09-08T19:49:05abcdefghijklmn", "state": "some-state" }
但我在OAuth流程开始前已尝试多种发票相关Scope组合:
let SCOPES:string[] = [ ... "https://uri.paypal.com/services/invoicing/invoices/readwrite", "https://uri.paypal.com/services/invoicing/invoices/read", "https://uri.paypal.com/services/invoicing", "https://uri.paypal.com/services/.*", "https://uri.paypal.com/v2/invoicing/invoices", "https://uri.paypal.com/v2/invoicing/invoices/.*", ... ]
解决方案
1. 修正Scope值
你用的发票相关Scope格式错误,PayPal V2发票接口对应的合法Scope是:
- 只读权限:
https://uri.paypal.com/services/invoicing/read - 读写权限:
https://uri.paypal.com/services/invoicing/write
PayPal的Scope是按服务层级划分,不是接口路径,之前的invoices/read、v2/invoicing/invoices这类格式都不被识别。
2. 确保权限生效
- 重新引导用户授权:如果用户之前已经授权过你的应用,旧的授权记录里没有新添加的发票权限,需要让用户重新完成授权流程,清除旧的授权会话或者让用户在授权页面明确同意新的权限。
- 检查应用功能配置:登录PayPal开发者平台,进入你的应用详情页,在“功能”选项卡中确认是否开启了“发票”功能。如果未开启,即使请求了对应Scope,也不会被纳入Access Token的权限范围。
3. 获取最新Scope列表的方式
登录PayPal开发者平台,进入你的应用,在“API权限”相关页面可以查看所有支持的Scope;另外,在PayPal官方API文档的OAuth2章节,会列出对应服务的合法Scope值,注意查看V2版本的文档内容。
内容的提问来源于stack exchange,提问作者floyergilmour
相关产品推荐
相关产品推荐

