You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Kusto中使用http_request_post插件获取Bearer Token的可行性及替代方案咨询

问题解答

你的理解是否正确?

你的理解完全正确。OAuth 2.0标准中,/oauth2/token端点(包括微软Defender等主流服务的实现)要求请求的Content-Type必须为application/x-www-form-urlencoded,且请求体需以key=value的键值对格式传递参数。如果http_request_post插件硬编码了application/json的Content-Type,发送的请求会因为格式不符合要求被端点拒绝。

可行替代方案

  • 替换为支持自定义请求头的HTTP插件
    放弃当前的http_request_post插件,选择允许手动配置请求头的HTTP请求工具/插件。这类工具可以直接设置Content-Type: application/x-www-form-urlencoded,并将授权参数(如client_id、grant_type等)拼接成key1=value1&key2=value2的格式放入请求体。

  • 编写自定义脚本构造请求
    如果你的环境支持自定义代码执行,可以直接绕过插件,用脚本构造符合要求的请求:

    • PowerShell示例:
      $tokenUrl = "https://your-oauth-endpoint/oauth2/token"
      $requestBody = @{
          client_id     = "你的客户端ID"
          client_secret = "你的客户端密钥"
          grant_type    = "client_credentials" # 根据你的授权流调整,比如authorization_code
          scope         = "所需权限范围"
      }
      $tokenResponse = Invoke-RestMethod -Uri $tokenUrl -Method Post -Body $requestBody -ContentType "application/x-www-form-urlencoded"
      $bearerToken = $tokenResponse.access_token
      
    • Python示例:
      import requests
      
      token_endpoint = "https://your-oauth-endpoint/oauth2/token"
      payload = {
          "client_id": "你的客户端ID",
          "client_secret": "你的客户端密钥",
          "grant_type": "client_credentials",
          "scope": "所需权限范围"
      }
      response = requests.post(token_endpoint, data=payload)
      bearer_token = response.json().get("access_token")
      
  • 修改现有插件源码(若有权限)
    如果你能获取http_request_post插件的源码,可以修改硬编码Content-Type的部分,添加一个可配置项,让用户能根据需求切换application/json或application/x-www-form-urlencoded类型。

内容的提问来源于stack exchange,提问作者dueland

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 11:36:59