You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何避免Riot Games认证API返回'invalid_session_id'错误?

解决Riot Games认证API返回invalid_session_id错误的方案

以下是针对问题的具体解决步骤:

1. 确保会话初始化请求被正确处理

你的代码中丢弃了第一个POST请求的响应,这会导致会话可能未正确建立。必须等待该请求完成并确认会话初始化成功,再执行后续的PUT登录请求。

2. 使用随机Nonce值

固定的nonce: "1"会触发会话验证失败,每次请求都应生成唯一的随机字符串作为Nonce。浏览器环境可以用crypto.randomUUID(),Node.js环境可以用uuid库生成。

3. 补充必要的请求头

Riot的API会校验User-Agent头,模拟浏览器UA可以避免被拦截。

4. 确保Cookie正确传递

  • 浏览器环境下,credentials: "include"是正确的,但要确保浏览器允许跨域Cookie(注意SameSite属性限制)。
  • Node.js环境下,原生fetch不自动管理Cookie,需要使用fetch-cookie配合tough-cookie来保存和传递会话Cookie。

修正后的浏览器环境代码示例

// 生成随机nonce
const nonce = crypto.randomUUID();

// 初始化会话,确认响应状态
const initResponse = await fetch("https://auth.riotgames.com/api/v1/authorization", {
  method: "POST",
  credentials: "include",
  headers: {
    "Content-Type": "application/json",
    "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
  },
  body: JSON.stringify({
    client_id: "play-valorant-web-prod",
    nonce: nonce,
    redirect_uri: "https://playvalorant.com/opt_in",
    response_type: "token id_token"
  })
});

if (!initResponse.ok) {
  throw new Error(`会话初始化失败: ${initResponse.status} ${initResponse.statusText}`);
}

// 执行登录请求
const loginResponse = await fetch("https://auth.riotgames.com/api/v1/authorization", {
  method: "PUT",
  credentials: "include",
  headers: {
    "Content-Type": "application/json",
    "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
  },
  body: JSON.stringify({
    type: "auth",
    username: this._username,
    password: this._password
  })
});

const json = await loginResponse.json();
console.log(json);

Node.js环境Cookie管理示例

const fetch = require('node-fetch');
const { CookieJar } = require('tough-cookie');
const fetchCookie = require('fetch-cookie');
const { v4: uuidv4 } = require('uuid');

const cookieJar = new CookieJar();
const fetchWithCookie = fetchCookie(fetch, cookieJar);

const nonce = uuidv4();

// 初始化会话
const initResponse = await fetchWithCookie("https://auth.riotgames.com/api/v1/authorization", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
  },
  body: JSON.stringify({
    client_id: "play-valorant-web-prod",
    nonce: nonce,
    redirect_uri: "https://playvalorant.com/opt_in",
    response_type: "token id_token"
  })
});

if (!initResponse.ok) {
  throw new Error(`会话初始化失败: ${initResponse.status} ${initResponse.statusText}`);
}

// 执行登录请求
const loginResponse = await fetchWithCookie("https://auth.riotgames.com/api/v1/authorization", {
  method: "PUT",
  headers: {
    "Content-Type": "application/json",
    "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
  },
  body: JSON.stringify({
    type: "auth",
    username: this._username,
    password: this._password
  })
});

const json = await loginResponse.json();
console.log(json);

注意:Riot Games的非公开API没有官方支持,使用这类API可能违反服务条款,存在账号被封禁的风险。

内容的提问来源于stack exchange,提问作者darkdarcool

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 10:30:41