PHP店铺插件实现PayPal账户关联获取API密钥方案咨询
实现客户一键关联PayPal账户收款的PHP方案提示
首先得纠正一个核心认知:Login with PayPal(OAuth授权)不会返回客户的Client ID和Secret——这是PayPal账户的敏感私密信息,绝对不会对外暴露。你要做的不是获取这些凭证,而是通过OAuth授权流程拿到代表客户账户的访问令牌(Access Token),用这个令牌替客户调用PayPal API完成收款操作。
下面是具体实现步骤:
1. 配置OAuth授权基础
- 先在你的PayPal开发者账户里创建一个支持OAuth的应用,开启
Login with PayPal功能,同时设置好回调URL(比如https://你的插件域名.com/paypal-callback),这个URL要能被PayPal正常访问到。 - 授权时必须请求必要的API权限范围,比如收款需要
payment:create、payment:execute,如果想后续不用客户再授权就能调用,还要加上refresh_token权限。
2. 引导客户完成授权
- 生成PayPal授权URL,让客户跳转过去登录并授权你的插件访问其账户:
$your_client_id = "你的应用Client ID"; $redirect_uri = "https://你的插件域名.com/paypal-callback"; $required_scope = "openid payment:create payment:execute"; // 按需添加权限 $auth_url = "https://www.paypal.com/signin/authorize?client_id=$your_client_id&response_type=code&redirect_uri=$redirect_uri&scope=$required_scope"; // 把客户跳转到这个URL就行 - 回调页面处理授权码,换取访问令牌和刷新令牌:
$auth_code = $_GET['code']; // PayPal回调时带的授权码 $your_client_id = "你的应用Client ID"; $your_client_secret = "你的应用Secret Key"; $redirect_uri = "https://你的插件域名.com/paypal-callback"; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://api-m.paypal.com/v1/oauth2/token"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, "grant_type=authorization_code&code=$auth_code&redirect_uri=$redirect_uri"); curl_setopt($ch, CURLOPT_USERPWD, "$your_client_id:$your_client_secret"); $response = curl_exec($ch); curl_close($ch); $token_data = json_decode($response, true); // 把$token_data['access_token']和$token_data['refresh_token']加密后存在客户的插件配置里 // refresh_token用来后续刷新过期的access_token,不用客户再授权
3. 用客户的访问令牌执行收款
创建订单时,用客户的access_token代替你自己的凭证:
$customer_access_token = "从客户配置里取出的access_token"; $order_data = [ "intent" => "CAPTURE", "purchase_units" => [ [ "amount" => [ "currency_code" => "USD", "value" => "10.00" ] ] ] ]; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://api-m.paypal.com/v2/checkout/orders"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($order_data)); curl_setopt($ch, CURLOPT_HTTPHEADER, [ "Content-Type: application/json", "Authorization: Bearer $customer_access_token" ]); $response = curl_exec($ch); curl_close($ch); $order = json_decode($response, true); // 把订单ID返回给前端,引导客户完成支付
4. 处理令牌过期
access_token默认有效期8小时,过期后用之前保存的refresh_token换取新的,不用客户再授权:
$customer_refresh_token = "从客户配置里取出的refresh_token"; $your_client_id = "你的应用Client ID"; $your_client_secret = "你的应用Secret Key"; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://api-m.paypal.com/v1/oauth2/token"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, "grant_type=refresh_token&refresh_token=$customer_refresh_token"); curl_setopt($ch, CURLOPT_USERPWD, "$your_client_id:$your_client_secret"); $response = curl_exec($ch); curl_close($ch); $new_token_data = json_decode($response, true); // 更新客户配置里的access_token为$new_token_data['access_token']
重要注意事项
- 客户的refresh_token和access_token必须加密存储,绝对不能明文保存,避免泄露后被滥用。
- 授权时请求的权限要最小化,只拿你需要的API权限,符合PayPal的安全规范。
- 测试阶段先用PayPal沙箱环境验证流程,没问题再切到生产环境。
内容的提问来源于stack exchange,提问作者jakob
相关产品推荐
相关产品推荐

