You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Walmart Orders API遇UNAUTHORIZED.GMP_GATEWAY_API错误求排查

Walmart Orders API 获取Token时的未授权问题排查

我尝试调用Walmart Orders API,需要先生成访问令牌(token),编写了如下代码:

import requests
import base64

# Replace with your API key and secret key
api_key = "AAA"
secret_key = "BBB"

key = api_key + ':' + secret_key
encoded_bytes = base64.b64encode(key.encode("utf-8"))
encoded_str = encoded_bytes.decode("utf-8")


# Walmart OAuth2.0 token endpoint
token_endpoint = "https://sandbox.walmartapis.com/v3/token"
headers = {
    'WM_SVC.NAME': 'Walmart Marketplace',
    'Authorization': 'Basic ' + encoded_str,
    'Content-Type': 'application/json',
    'Accept': 'application/json',
    'WM_SVC.VERSION': '1.0.0',
    'WM_QOS.CORRELATION_ID': '76080106-eaf2-4ec1-a7dd-ffa0473182c5',
    'grant_type': 'client_credentials'}


# Define the OAuth2.0 client credentials grant request parameters
grant_type = "client_credentials"
scope = "https://marketplace.walmartapis.com/v3/orders.readonly"

# Send the OAuth2.0 client credentials grant request to the token endpoint
response = requests.post(
    token_endpoint,
    headers=headers
)

# Check if the request was successful
if response.status_code == 200:
    # Extract the access token from the response
    access_token = response.json()["access_token"]
    # Use the access token to authenticate requests to the Order Management API
    # ...
else:
    print("Failed to get access token:", response.text)

执行后出现如下错误:

Failed to get access token: {"error":[{"code":"UNAUTHORIZED.GMP_GATEWAY_API","field":"UNAUTHORIZED","description":"Unauthorized","info":"Unauthorized","severity":"ERROR","category":"DATA","causes":[],"errorIdentifiers":{}}]}

问题排查与修正方案

核心错误点

  • 请求参数位置错误:grant_type和scope被放在了请求头中,但根据Walmart的OAuth2.0规范,这两个参数应该作为表单数据(x-www-form-urlencoded)放在请求体里,而非请求头。
  • Content-Type不匹配:当前请求头设置的Content-Type为application/json,但实际需要传输表单数据,应改为application/x-www-form-urlencoded。
  • 未传递必要请求体:原代码未携带grant_type和scope参数的请求体,导致服务端无法识别授权类型,直接返回未授权。

修正后的代码

import requests
import base64

# 替换为你的沙箱环境API密钥和密钥
api_key = "AAA"
secret_key = "BBB"

key = api_key + ':' + secret_key
encoded_bytes = base64.b64encode(key.encode("utf-8"))
encoded_str = encoded_bytes.decode("utf-8")

# Walmart沙箱OAuth2.0令牌端点
token_endpoint = "https://sandbox.walmartapis.com/v3/token"
headers = {
    'WM_SVC.NAME': 'Walmart Marketplace',
    'Authorization': 'Basic ' + encoded_str,
    'Content-Type': 'application/x-www-form-urlencoded',
    'Accept': 'application/json',
    'WM_SVC.VERSION': '1.0.0',
    'WM_QOS.CORRELATION_ID': '76080106-eaf2-4ec1-a7dd-ffa0473182c5'
}

# OAuth2.0客户端凭证模式的请求参数
payload = {
    'grant_type': 'client_credentials',
    'scope': 'https://marketplace.walmartapis.com/v3/orders.readonly'
}

# 发送请求
response = requests.post(
    token_endpoint,
    headers=headers,
    data=payload
)

# 处理响应
if response.status_code == 200:
    access_token = response.json()["access_token"]
    print("获取到的访问令牌:", access_token)
else:
    print("获取访问令牌失败:", response.text)

额外验证点

  • 确认api_key和secret_key是沙箱环境的有效密钥,不要混用生产环境的密钥。
  • 检查WM_QOS.CORRELATION_ID是否为有效的UUID格式(虽一般不是未授权的直接原因,但需符合规范)。

内容的提问来源于stack exchange,提问作者user1636588

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 14:48:24