Magento 2.4.1集成Instagram登录报错:Invalid scope及相关问题求助
Alright, let's work through your Instagram login issues with Magento 2.4.1 and HybridAuth step by step—there are a few key fixes needed since Instagram has deprecated its old API endpoints and scopes.
1. Fix the "Invalid scope: ['basic']" Error
Instagram retired the legacy basic scope and its old api.instagram.com/v1/ API years ago. You need to switch to the Instagram Basic Display API, which uses updated scopes and endpoints:
Update the scope: Replace your current
$scopevalue with the valid Basic Display scopes:public $scope = "user_profile,user_media";user_profileis required to fetch user account details, anduser_mediais optional if you need access to their posts.Replace outdated API endpoints: The legacy endpoints in your
initialize()method no longer work. Update them to match the Basic Display API:public function initialize() { parent::initialize(); // Updated Instagram Basic Display API endpoints $this->api->api_base_url = "https://graph.instagram.com/"; $this->api->authorize_url = "https://api.instagram.com/oauth/authorize"; $this->api->token_url = "https://api.instagram.com/oauth/access_token"; }
2. Resolve the "Oops, an error occurred" Authorization Page Issue
This error almost always comes from misconfigured app settings or incorrect API implementation. Let's fix both:
Fix App Configuration in Facebook Developer Dashboard
Even if your app shows as "Live", the Instagram Basic Display section needs proper setup:
- Go to your Facebook Developer Dashboard → Your App → Instagram Basic Display tab.
- Ensure your Valid OAuth Redirect URI is an exact match to what you're using:
https://127.0.0.1/magento_241/sociallogin/social/callback/?hauth.done=Instagram(trailing slashes and query parameters matter—copy-paste it to avoid typos). - Add Test Users (even for live apps, Instagram restricts access to test users unless you complete full app review).
- Confirm you've filled out all required app details (like privacy policy URL) in the app settings—missing info can block authorization.
Update the getUserProfile() Method
The legacy users/self/ endpoint doesn't exist in Basic Display. Replace the method with this code to fetch user data correctly:
public function getUserProfile() { // Fetch user profile using Basic Display API fields $data = $this->api->api("me?fields=id,username,full_name,bio,profile_picture,website"); if (!isset($data['id'])) { throw new \Exception("User profile request failed! {$this->providerId} returned an invalid response.", 6); } $this->user->profile->identifier = $data['id']; $this->user->profile->displayName = $data['full_name'] ?: $data['username']; $this->user->profile->description = $data['bio']; $this->user->profile->photoURL = $data['profile_picture']; $this->user->profile->webSiteURL = $data['website']; $this->user->profile->username = $data['username']; return $this->user->profile; }
Note: The Basic Display API returns JSON as arrays (not objects), so we use array access ($data['id']) instead of object syntax ($data->id).
Remove or Disable the getUserContacts() Method
Instagram no longer allows fetching a user's followers/follows via the Basic Display API. The legacy users/{id}/follows endpoint is gone, so this method will throw errors. Comment it out or remove it entirely if you don't need contact sync functionality.
3. Final Checks
- Use HTTPS: Instagram requires all redirect URIs to use HTTPS. If you're testing locally, use a tool like ngrok to expose your Magento site over HTTPS (some browsers block HTTP OAuth redirects even for
127.0.0.1). - Clear Magento Cache: After making code changes, run
bin/magento cache:flushto ensure your updates take effect. - Verify Credentials: Double-check that your HybridAuth config uses the correct
client_idandclient_secretfrom the Instagram Basic Display section (these are different from your main Facebook app credentials).
Once you implement all these fixes, test the Instagram login flow again—it should work as expected.
内容的提问来源于stack exchange,提问作者Mohit Rane

