Shopify API密钥/访问令牌无效问题排查求助
问题排查:Shopify GraphQL API上传图片时的认证错误
我使用以下Python代码调用Shopify GraphQL API上传图片,但始终返回认证错误。已确认使用Shopify应用后台生成的API密钥和Admin API访问令牌,且开启了write files/read files权限,求问题排查思路。
代码示例
import requests # Replaced with my actual Shopify credentials and file information!!! API_KEY = 'text' # using my Shopify App "API key" ACCESS_TOKEN = 'text' # using my Shopify App "Admin API access token" SHOP_NAME = 'text.myshopify.com' # using the root myshopify URL file_path = r"C:\text\API-TEST-1.jpg" url = f'https://{SHOP_NAME}/admin/api/2023-04/graphql.json' query = """ mutation stagedUploadsCreate($input: [StagedUploadInput!]!) { stagedUploadsCreate(input: $input) { stagedTargets { resourceUrl url parameters { name value } } } } """ variables = { 'input': [ { 'resource': 'IMAGE', 'filename': 'your-image.jpg', 'mimeType': 'image/jpeg', 'httpMethod': 'POST', } ] } headers = { 'Content-Type': 'application/json', 'Authorization': f'Bearer {ACCESS_TOKEN}', } response = requests.post(url, json={'query': query, 'variables': variables}, headers=headers) data = response.json() staged_targets = data.get('data', {}).get('stagedUploadsCreate', {}).get('stagedTargets', []) if staged_targets: target = staged_targets[0] params = target['parameters'] upload_url = target['url'] resource_url = target['resourceUrl'] with open(file_path, 'rb') as file: file_data = file.read() headers = { 'Content-Type': 'application/octet-stream', 'Content-Length': str(len(file_data)), 'X-Shopify-Access-Token': ACCESS_TOKEN, } headers.update(params) response = requests.put(upload_url, headers=headers, data=file_data) if response.status_code == 200: print('Image uploaded successfully.') else: print('Failed to upload the image.') print(response.text) else: print('Failed to generate upload URL and parameters.') print(response.text)
错误信息
Failed to generate upload URL and parameters. {"errors":"[API] Invalid API key or access token (unrecognized login or wrong password)"}
排查思路
- 验证ACCESS_TOKEN有效性
- 确认使用的是Shopify应用后台的Admin API access token,而非API_KEY(GraphQL请求仅需Bearer令牌,API_KEY在此处无用)
- 检查令牌是否过期:自定义应用的令牌默认永久有效,公共应用的令牌需确认是否完成OAuth刷新
- 检查SHOP_NAME格式
- 确保是
xxxx.myshopify.com格式,不要添加http/https前缀或额外路径
- 确保是
- 核对请求头正确性
- 确认第一个请求的
Authorization头格式为Bearer {ACCESS_TOKEN},注意Bearer后必须有空格,令牌无多余空格或换行
- 确认第一个请求的
- 确认应用权限与安装状态
- 除
write files/read files外,若后续需关联产品,需确保有write products权限;同时确认自定义应用已安装到目标店铺,公共应用已完成店铺授权
- 除
- 排查API版本兼容性
- 代码使用2023-04版本,确认该版本的
stagedUploadsCreatemutation参数要求无变更,是否存在权限调整
- 代码使用2023-04版本,确认该版本的
- 验证网络与请求可用性
- 用Postman发送简单查询请求测试令牌,排除代码逻辑问题:
query { shop { name } } - 检查是否有代理、防火墙拦截请求,导致令牌未正确传递
- 用Postman发送简单查询请求测试令牌,排除代码逻辑问题:
- 修正代码语法问题
- 原代码中使用
//注释,这是Python语法错误,需替换为#,避免因语法错误导致令牌未正确加载
- 原代码中使用
内容的提问来源于stack exchange,提问作者king_anton
相关产品推荐
相关产品推荐

