You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PayPal OAuth2获取发票权限被拒,求正确Scope及查询方式

PayPal OAuth2调用发票接口权限拒绝问题排查

问题情况

我尝试通过已登录用户的PayPal OAuth2身份调用发票列表接口,执行以下curl命令:

curl -v -X GET https://api-m.paypal.com/v2/invoicing/invoices\?total_required\=true \
-H 'Authorization: Bearer <ACCESS_TOKEN>' \
-H 'Content-Type: application/json'

返回权限拒绝错误:

{"localizedMessage":"No permission for the requested operation. ","suppressed":[],"name":"PERMISSION_DENIED","message":"No permission for the requested operation. ","details":[{"field":null,"value":null,"location":null,"issue":"No permission for the requested operation. ","description":null}],"information_link":"https://developer.paypal.com/docs/classic/products/permissions/","debug_id":"3b3e0813dca9f"}%        

查看Access Token响应,确实缺少发票相关权限:

{
"scope": "https://uri.paypal.com/services/checkout/one-click-with-merchant-issued-token https://uri.paypal.com/services/payments/realtimepayment https://uri.paypal.com/services/payments/payment/authcapture openid profile https://uri.paypal.com/services/payments/refund https://api.paypal.com/v1/vault/credit-card https://uri.paypal.com/services/reporting/search/read https://api.paypal.com/v1/vault/credit-card/.* https://uri.paypal.com/services/subscriptions https://uri.paypal.com/services/applications/webhooks https://uri.paypal.com/services/paypalattributes email",
"access_token": "MY_ACCESS_TOKEN",
"token_type": "Bearer",
"expires_in": 28800,
"refresh_token": "MY_REFRESH_TOKEN",
"nonce": "2023-09-08T19:49:05abcdefghijklmn",
"state": "some-state"
}

但我在OAuth流程开始前已尝试多种发票相关Scope组合:

let SCOPES:string[] = [
    ...
    "https://uri.paypal.com/services/invoicing/invoices/readwrite",
    "https://uri.paypal.com/services/invoicing/invoices/read",
    "https://uri.paypal.com/services/invoicing",
    "https://uri.paypal.com/services/.*",
    "https://uri.paypal.com/v2/invoicing/invoices",
    "https://uri.paypal.com/v2/invoicing/invoices/.*",
    ...
]

解决方案

1. 修正Scope值

你用的发票相关Scope格式错误,PayPal V2发票接口对应的合法Scope是:

  • 只读权限:https://uri.paypal.com/services/invoicing/read
  • 读写权限:https://uri.paypal.com/services/invoicing/write

PayPal的Scope是按服务层级划分,不是接口路径,之前的invoices/read、v2/invoicing/invoices这类格式都不被识别。

2. 确保权限生效

  • 重新引导用户授权:如果用户之前已经授权过你的应用,旧的授权记录里没有新添加的发票权限,需要让用户重新完成授权流程,清除旧的授权会话或者让用户在授权页面明确同意新的权限。
  • 检查应用功能配置:登录PayPal开发者平台,进入你的应用详情页,在“功能”选项卡中确认是否开启了“发票”功能。如果未开启,即使请求了对应Scope,也不会被纳入Access Token的权限范围。

3. 获取最新Scope列表的方式

登录PayPal开发者平台,进入你的应用,在“API权限”相关页面可以查看所有支持的Scope;另外,在PayPal官方API文档的OAuth2章节,会列出对应服务的合法Scope值,注意查看V2版本的文档内容。

内容的提问来源于stack exchange,提问作者floyergilmour

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 03:55:53