You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP店铺插件实现PayPal账户关联获取API密钥方案咨询

实现客户一键关联PayPal账户收款的PHP方案提示

首先得纠正一个核心认知:Login with PayPal(OAuth授权)不会返回客户的Client ID和Secret——这是PayPal账户的敏感私密信息,绝对不会对外暴露。你要做的不是获取这些凭证,而是通过OAuth授权流程拿到代表客户账户的访问令牌(Access Token),用这个令牌替客户调用PayPal API完成收款操作。

下面是具体实现步骤:

1. 配置OAuth授权基础

  • 先在你的PayPal开发者账户里创建一个支持OAuth的应用,开启Login with PayPal功能,同时设置好回调URL(比如https://你的插件域名.com/paypal-callback),这个URL要能被PayPal正常访问到。
  • 授权时必须请求必要的API权限范围,比如收款需要payment:create、payment:execute,如果想后续不用客户再授权就能调用,还要加上refresh_token权限。

2. 引导客户完成授权

  • 生成PayPal授权URL,让客户跳转过去登录并授权你的插件访问其账户:
    $your_client_id = "你的应用Client ID";
    $redirect_uri = "https://你的插件域名.com/paypal-callback";
    $required_scope = "openid payment:create payment:execute"; // 按需添加权限
    $auth_url = "https://www.paypal.com/signin/authorize?client_id=$your_client_id&response_type=code&redirect_uri=$redirect_uri&scope=$required_scope";
    // 把客户跳转到这个URL就行
    
  • 回调页面处理授权码,换取访问令牌和刷新令牌:
    $auth_code = $_GET['code']; // PayPal回调时带的授权码
    $your_client_id = "你的应用Client ID";
    $your_client_secret = "你的应用Secret Key";
    $redirect_uri = "https://你的插件域名.com/paypal-callback";
    
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_URL, "https://api-m.paypal.com/v1/oauth2/token");
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
    curl_setopt($ch, CURLOPT_POST, true);
    curl_setopt($ch, CURLOPT_POSTFIELDS, "grant_type=authorization_code&code=$auth_code&redirect_uri=$redirect_uri");
    curl_setopt($ch, CURLOPT_USERPWD, "$your_client_id:$your_client_secret");
    
    $response = curl_exec($ch);
    curl_close($ch);
    $token_data = json_decode($response, true);
    
    // 把$token_data['access_token']和$token_data['refresh_token']加密后存在客户的插件配置里
    // refresh_token用来后续刷新过期的access_token,不用客户再授权
    

3. 用客户的访问令牌执行收款

创建订单时,用客户的access_token代替你自己的凭证:

$customer_access_token = "从客户配置里取出的access_token";
$order_data = [
    "intent" => "CAPTURE",
    "purchase_units" => [
        [
            "amount" => [
                "currency_code" => "USD",
                "value" => "10.00"
            ]
        ]
    ]
];

$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://api-m.paypal.com/v2/checkout/orders");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($order_data));
curl_setopt($ch, CURLOPT_HTTPHEADER, [
    "Content-Type: application/json",
    "Authorization: Bearer $customer_access_token"
]);

$response = curl_exec($ch);
curl_close($ch);
$order = json_decode($response, true);
// 把订单ID返回给前端,引导客户完成支付

4. 处理令牌过期

access_token默认有效期8小时,过期后用之前保存的refresh_token换取新的,不用客户再授权:

$customer_refresh_token = "从客户配置里取出的refresh_token";
$your_client_id = "你的应用Client ID";
$your_client_secret = "你的应用Secret Key";

$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://api-m.paypal.com/v1/oauth2/token");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, "grant_type=refresh_token&refresh_token=$customer_refresh_token");
curl_setopt($ch, CURLOPT_USERPWD, "$your_client_id:$your_client_secret");

$response = curl_exec($ch);
curl_close($ch);
$new_token_data = json_decode($response, true);
// 更新客户配置里的access_token为$new_token_data['access_token']

重要注意事项

  • 客户的refresh_token和access_token必须加密存储,绝对不能明文保存,避免泄露后被滥用。
  • 授权时请求的权限要最小化,只拿你需要的API权限,符合PayPal的安全规范。
  • 测试阶段先用PayPal沙箱环境验证流程,没问题再切到生产环境。

内容的提问来源于stack exchange,提问作者jakob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 14:03:11