You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

首次开发YouTube API上传脚本遇OAuth 2 HTTPS安全传输错误求助

解决YouTube API授权时的InsecureTransportError问题

问题背景

首次编写调用YouTube API的视频上传脚本,已设置HTTPS的redirect_uri且client_secrets.json中所有URL均为HTTPS,但输入授权码时触发如下错误:

Traceback (most recent call last):
  File "uploadtoyoutube2.py", line 90, in <module>
    upload_video(video_file)
  File "uploadtoyoutube2.py", line 57, in upload_video
    youtube = get_authenticated_service()
              ^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "uploadtoyoutube2.py", line 40, in get_authenticated_service
    flow.fetch_token(authorization_response=authorization_response)
  File "\Python\Python311\Lib\site-packages\google_auth_oauthlib\flow.py", line 285, in fetch_token
    return self.oauth2session.fetch_token(self.client_config["token_uri"], **kwargs)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "Python\Python311\Lib\site-packages\requests_oauthlib\oauth2_session.py", line 244, in fetch_token
    self._client.parse_request_uri_response(
  File "Python\Python311\Lib\site-packages\oauthlib\oauth2\rfc6749\clients\web_application.py", line 220, in parse_request_uri_response
    response = parse_authorization_code_response(uri, state=state)
               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "Python\Python311\Lib\site-packages\oauthlib\oauth2\rfc6749\parameters.py", line 272, in parse_authorization_code_response
    raise InsecureTransportError()
oauthlib.oauth2.rfc6749.errors.InsecureTransportError: (insecure_transport) OAuth 2 MUST utilize https.

脚本授权部分核心代码:

def get_authenticated_service():
    """Gets an authenticated YouTube API service."""
    flow = Flow.from_client_secrets_file(client_secrets_file, scopes)
    flow.redirect_uri = 'https://localhost:8080'
    authorization_url, state = flow.authorization_url(
        access_type='offline',
        include_granted_scopes='true')
    print('Please go to this URL: {}'.format(authorization_url))
    authorization_response = input('Enter the authorization code: ')
    flow.fetch_token(authorization_response=authorization_response)
    credentials = flow.credentials
    return build(api_service_name, api_version, credentials=credentials)

错误原因

你使用的是Web应用类型的OAuth Flow,这类流程要求redirect_uri必须是带有可信SSL证书的HTTPS地址。虽然你设置了https://localhost:8080,但本地localhost的HTTPS通常没有有效的公共SSL证书,OAuth库会判定其为不安全传输,从而抛出错误。

解决方案

方案1:使用桌面应用专用授权流程(推荐)

Google提供InstalledAppFlow,专门为桌面/命令行应用设计,无需手动处理HTTPS证书问题,会自动打开浏览器完成授权,无需手动输入授权码。

修改步骤:

  1. 补充导入InstalledAppFlow:
from google_auth_oauthlib.flow import Flow, InstalledAppFlow
  1. 替换get_authenticated_service函数:
def get_authenticated_service():
    """Gets an authenticated YouTube API service."""
    flow = InstalledAppFlow.from_client_secrets_file(
        client_secrets_file, scopes)
    # 启动本地服务器自动处理授权回调
    credentials = flow.run_local_server(port=8080)
    return build(api_service_name, api_version, credentials=credentials)

该流程会自动打开浏览器跳转至Google授权页面,授权完成后自动将token返回给本地服务器,无需手动复制授权码,且OAuth库默认信任本地localhost的HTTP传输(仅针对桌面应用场景)。

方案2:临时绕过HTTPS检查(仅开发测试用)

如果坚持使用原有Web Flow,可通过设置环境变量让OAuth库跳过不安全传输检查,但仅适合本地开发测试,绝对不能用于生产环境:

在脚本开头添加:

import os
# 仅开发环境使用,生产环境禁止
os.environ['OAUTHLIB_INSECURE_TRANSPORT'] = '1'

额外注意事项

  • 确保Google Cloud控制台中,你的OAuth客户端ID类型是桌面应用(而非Web应用),否则可能触发其他授权错误。
  • 授权完成后,credentials会自动保存到本地token.json文件,后续运行脚本无需重复授权。

内容的提问来源于stack exchange,提问作者YTQuiet

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 06:47:10