使用LinkedIn API获取access_token时未返回refresh_token求助
LinkedIn API获取access_token时缺少refresh_token相关字段的问题
按照LinkedIn官方授权文档,调用accessToken接口交换授权码时,应返回以下字段:
access_tokenexpires_inrefresh_tokenrefresh_token_expires_inscope
但实际调用后仅收到access_token、expires_in和scope三个字段,请问原因是什么?
相关代码
const data = { grant_type: "authorization_code", code, redirect_uri, client_id, client_secret: process.env.LINKEDIN_CLIENT_SECRET, } const authorization = await axios.post( `https://www.linkedin.com/oauth/v2/accessToken?${querystring.stringify(data)}`); console.log("authorization.data", authorization.data);
返回日志
authorization.data { access_token: 'AQX09XfxIcceXWHz9Mutkbjfsj3iqJptsAxrpGxW3anWD-rIh..., expires_in: 5183999, scope: 'r_liteprofile,w_member_social' }
原因及解决办法
- 缺少
offline_access权限:LinkedIn的refresh_token必须在授权流程中请求offline_access权限才能返回。你当前的scope只有r_liteprofile,w_member_social,没有包含这个关键权限。 - 修改授权请求的scope:在引导用户跳转授权页面获取authorization code的请求中,需要把
offline_access加入scope参数,例如:scope=r_liteprofile,w_member_social,offline_access。重新走授权流程后,再交换token就能拿到refresh_token和refresh_token_expires_in字段了。 - 验证应用配置:确认你的LinkedIn应用已经开启了允许获取refresh_token的相关设置,部分受限应用可能无法获取该字段。
内容的提问来源于stack exchange,提问作者Cylecq
相关产品推荐
相关产品推荐

