You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Postman中自动获取OAuth 2.0 AccessToken,替代手动点击

如何在Postman中通过前置脚本自动刷新OAuth 2.0 AccessToken?

完全可以通过前置脚本实现AccessToken的自动获取,不用每次手动点击按钮。核心思路是在集合的前置脚本里调用OAuth2的token接口,将获取到的token存入环境变量,让集合内的请求自动引用这个变量。

具体步骤:

  1. 确认OAuth2 token接口信息
    你需要明确授权服务器的token端点(通常是/oauth/token),以及请求所需参数:

    • client_id和client_secret(客户端凭证模式必填)
    • grant_type(比如client_credentials、password等,根据你的授权类型选择)
    • 可选的scope参数(按需添加)
  2. 编写集合前置脚本
    打开Postman集合的「前置脚本」标签,粘贴以下代码,替换成你的实际配置:

// 配置token请求参数
const tokenReq = {
    url: 'https://你的授权服务器地址/oauth/token',
    method: 'POST',
    header: {
        'Content-Type': 'application/x-www-form-urlencoded'
    },
    body: {
        mode: 'urlencoded',
        urlencoded: [
            { key: 'client_id', value: '你的client_id' },
            { key: 'client_secret', value: '你的client_secret' },
            { key: 'grant_type', value: 'client_credentials' }, // 按实际授权类型调整
            { key: 'scope', value: '你的权限范围' } // 可选
        ]
    }
};

// 发送请求获取token
pm.sendRequest(tokenReq, (err, res) => {
    if (err) {
        console.error('获取token失败:', err);
        pm.test('AccessToken获取失败', () => {
            throw new Error('请求token接口出错: ' + err.message);
        });
        return;
    }

    const tokenData = res.json();
    // 将token存入环境变量
    pm.environment.set('access_token', tokenData.access_token);
    // 存储token过期时间(用于后续判断是否需要刷新)
    pm.environment.set('token_expires_at', Date.now() + (tokenData.expires_in * 1000));
    console.log('AccessToken已自动更新');
});
  1. 配置集合授权方式
    进入集合的「Authorization」标签,选择「Bearer Token」,在「Token」输入框中填写{{access_token}},这样集合下的所有请求都会自动使用这个环境变量里的token。

  2. (可选)优化token刷新逻辑
    如果token有效期较长,不想每次请求都调用token接口,可以添加过期判断,只在token即将过期时刷新:

const expiresAt = pm.environment.get('token_expires_at');
// 提前30秒刷新,避免网络延迟导致请求时token已过期
if (!expiresAt || Date.now() >= expiresAt - 30000) {
    // 执行上面的token请求代码
} else {
    console.log('AccessToken未过期,跳过刷新');
}

注意事项:

  • 不要硬编码client_id和client_secret,建议存入Postman环境变量,用{{client_id}}、{{client_secret}}引用,提升安全性。
  • 如果使用password授权类型,需要在请求体中添加username和password参数。
  • 确保授权服务器允许Postman所在IP发起请求,避免被拦截。

内容的提问来源于stack exchange,提问作者IshuVisha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 08:45:35