如何在PHP Laravel中通过Twitter API获取授权用户的详情信息
Got it, let's walk through exactly how to get the user details you need using the oauth_token and oauth_verifier you already have. Twitter's OAuth 1.0a flow requires one more key step to exchange those temporary tokens for permanent access credentials, then you can fetch the user profile data you're after.
Step 1: Exchange Temporary Tokens for Permanent Access Tokens
First, you need to swap your temporary oauth_token and oauth_verifier for a permanent access token pair (consisting of oauth_token and oauth_token_secret). This is done via a signed POST request to Twitter's token exchange endpoint.
Critical note: OAuth 1.0a requires request signing (HMAC-SHA1), so don't try to build this request manually unless you're deeply familiar with OAuth signing rules. Use a trusted library instead to avoid authentication failures.
Example with Python's requests-oauthlib:
from requests_oauthlib import OAuth1Session # Replace these with your app's credentials from the Twitter Developer Portal CLIENT_KEY = "YOUR_CONSUMER_KEY" CLIENT_SECRET = "YOUR_CONSUMER_SECRET" # The tokens you received from your callback TEMP_OAUTH_TOKEN = "PVHUBxxxxxxxxxxxxxxx" OAUTH_VERIFIER = "5vlkG3xxxxxxxxxx" # Initialize the OAuth session with your temp token twitter_session = OAuth1Session(CLIENT_KEY, CLIENT_SECRET, resource_owner_key=TEMP_OAUTH_TOKEN) # Exchange tokens for permanent access credentials token_response = twitter_session.fetch_access_token( "https://api.twitter.com/oauth/access_token", verifier=OAUTH_VERIFIER ) # Extract the permanent tokens and basic user info (bonus!) access_token = token_response["oauth_token"] access_token_secret = token_response["oauth_token_secret"] user_id = token_response["user_id"] screen_name = token_response["screen_name"]
Step 2: Fetch Full User Profile Details
With your permanent access token and secret, you can now call Twitter's account/verify_credentials.json endpoint to get the user's full profile data, including name, avatar, and user ID.
Example continuation of the Python code:
# Re-initialize the session with permanent tokens twitter_session = OAuth1Session(CLIENT_KEY, CLIENT_SECRET, access_token, access_token_secret) # Fetch user profile details (skip irrelevant fields to keep response clean) profile_response = twitter_session.get( "https://api.twitter.com/1.1/account/verify_credentials.json", params={"include_entities": False, "skip_status": True} ) user_profile = profile_response.json() # Extract the fields you need full_name = user_profile["name"] user_id = user_profile["id_str"] # Use id_str instead of id to avoid integer overflow issues avatar_url = user_profile["profile_image_url_https"] # HTTPS URL for the user's avatar # Print or use the data as needed print(f"Full Name: {full_name}") print(f"User ID: {user_id}") print(f"Avatar URL: {avatar_url}")
Key Tips to Avoid Issues:
- Library First: Always use a maintained OAuth library (like
requests-oauthlibfor Python,oauth-1.0afor JavaScript) to handle signing—manual implementation is almost guaranteed to fail. - Permissions: If you need additional data (like email), make sure your app has the required permissions enabled in the Twitter Developer Portal, and add
include_email=trueto theverify_credentialsrequest params. - Response Fields: The
verify_credentialsendpoint returns dozens of fields (likelocation,description,followers_count). Check Twitter's official API docs for the full list of available data.
内容的提问来源于stack exchange,提问作者Sandeep Sudhakaran

