You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

埃及电子发票SDK认证报unauthorized_client错误:PHP代码异常排查

调用埃及电子发票SDK收据认证接口返回{"error":"unauthorized_client"}问题排查

问题详情

调用埃及电子发票SDK的收据认证接口时,PHP代码返回{"error":"unauthorized_client"}错误,但同一段代码调用SDK的发票接口完全正常,且Postman测试该收据认证接口可成功获取access_token。相关接口为POS认证接口,官方文档有对应说明。

问题代码

$postData = array(
    'grant_type' => 'client_credentials',
    'client_id' => $client_id,
    'client_secret' => $client_secret
    );

$headerData = array(
    'Content-Type' => 'application/x-www-form-urlencoded',
    'Content-Type' => 'application/json;charset=UTF-8',
    'posserial' => 'PC0RWSX8',
    'pososversion' => 'windows',
    'posmodelframework' => '',
    'presharedkey' => ''
    );

$url = 'https://id.eta.gov.eg/connect/token';

$ch = curl_init();
curl_setopt_array($ch, array(
    CURLOPT_URL => $url,
    CURLOPT_RETURNTRANSFER => 1,
    CURLOPT_POST => 1,
    CURLOPT_POSTFIELDS => $postData
));

curl_setopt($ch, CURLOPT_HTTPHEADER, $headerData);
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);

排查与修复方案

核心问题:重复且错误的Content-Type请求头

代码中重复设置了Content-Type字段,最终生效的是application/json;charset=UTF-8,但client_credentials模式的token接口要求参数以application/x-www-form-urlencoded格式传递,这会导致服务端无法正确解析client_id、client_secret等核心参数,直接返回未授权错误。而Postman中你应该是设置了正确的表单格式头,所以能成功请求。

修复步骤:

  1. 移除重复的Content-Type,只保留application/x-www-form-urlencoded格式头
  2. 规范请求头格式:将请求头数组的每个元素改为key: value的字符串形式,避免数组键名重复覆盖的问题
  3. 添加curl错误捕获逻辑,方便排查网络或请求发送过程中的其他问题

修复后的代码

$postData = array(
    'grant_type' => 'client_credentials',
    'client_id' => $client_id,
    'client_secret' => $client_secret
);

// 修复重复Content-Type,统一使用表单格式头,规范头字段写法
$headerData = array(
    'Content-Type: application/x-www-form-urlencoded',
    'posserial: PC0RWSX8',
    'pososversion: windows',
    'posmodelframework:',
    'presharedkey:'
);

$url = 'https://id.eta.gov.eg/connect/token';

$ch = curl_init();
curl_setopt_array($ch, array(
    CURLOPT_URL => $url,
    CURLOPT_RETURNTRANSFER => 1,
    CURLOPT_POST => 1,
    CURLOPT_POSTFIELDS => $postData, // curl会自动将数组编码为urlencoded格式
    CURLOPT_HTTPHEADER => $headerData,
    CURLOPT_SSL_VERIFYHOST => 0,
    CURLOPT_SSL_VERIFYPEER => 0
));

$response = curl_exec($ch);
// 捕获curl错误,便于排查问题
if(curl_errno($ch)){
    echo 'Curl错误:' . curl_error($ch);
}
curl_close($ch);

var_dump($response);

额外检查项

  • 确认posserial、pososversion等POS相关头参数的值和Postman中使用的完全一致,包括空值字段的处理是否符合接口要求
  • 生产环境建议开启SSL验证(移除CURLOPT_SSL_VERIFYHOST和CURLOPT_SSL_VERIFYPEER的0值设置),避免安全风险

内容的提问来源于stack exchange,提问作者user3515102

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 07:16:06