Kong基于客户端凭证获取AccessToken报路由匹配错误求助
解决Kong OAuth2获取Token时的路由匹配错误问题
核心问题分析
你遇到的no Route matched with those values错误,本质是请求的URL和主机头与已配置的Kong路由完全不匹配,具体原因有两点:
- 配置的路由
test-endcustomer只匹配主机ordering.com和路径/endcustomerslist,但请求时既没携带Host: ordering.com头,路径用的是/test-service/oauth2/token,完全不符合路由规则; - OAuth2插件的
/oauth2/token端点没有被任何路由覆盖,Kong无法将该请求转发到对应的服务。
具体解决步骤
1. 调整路由配置,让/oauth2/token被匹配
有两种可选方案:
方案A:修改现有路由,添加/oauth2/token路径
用Admin API给test-endcustomer路由新增路径规则:
curl -X PATCH http://localhost:8001/routes/test-endcustomer \ -d "paths[]=/endcustomerslist" \ -d "paths[]=/oauth2/token"
方案B:新建专门的OAuth2端点路由
如果不想修改原有路由,可以创建一个单独的路由来处理Token请求:
curl -X POST http://localhost:8001/routes \ -d "name=test-oauth-token" \ -d "service.name=test-service" \ -d "hosts[]=ordering.com" \ -d "paths[]=/oauth2/token"
2. 修正获取Token的curl命令
请求必须携带Host: ordering.com头,同时修正原命令中的格式错误(去掉多余的?\):
curl -X POST "https://localhost:8443/oauth2/token" \ -H "Host: ordering.com" \ -d "grant_type=client_credentials" \ -d "client_id=PbgKKXnP1kqMiJwrXn8erCYwiJmt9DMg2" \ -d "client_secret=LRTI2CRTjpnppLBLYp3FoZVITLIoRs9b" \ --insecure
3. 验证路由配置(可选)
可以用Admin API确认路由配置是否正确:
curl http://localhost:8001/routes/test-endcustomer
检查返回结果中的hosts是否包含ordering.com,paths是否包含你添加的/oauth2/token,以及service.id是否关联到test-service的ID。
额外说明
- Kong的路由匹配是基于请求的Host头和路径,而不是服务名称,所以不要在URL中使用服务名
test-service; client_credentials授权模式下,redirect_uri不是强制必填项,但若插件配置中开启了mandatory_redirect_uri,则需要确保该参数正确配置。
内容的提问来源于stack exchange,提问作者karthick
相关产品推荐
相关产品推荐

