Sonos API OAuth流程中请求令牌遇client_invalid错误求助
Hey Felix, sorry to hear you're hitting snags with the Sonos Authorization API for your IoT remote—let's walk through the most likely issues and get you back on track.
First, that short authorization code (like ZGyr3PrM) instead of the expected UUID-style code is a red flag—it means something's off in how you're requesting the code in the first place. Here's what to check step by step:
Verify your authorization request parameters
Make sure your initial "Create Authorization Code" request usesresponse_type=code(this is required for the authorization code flow Sonos uses). If you accidentally usedresponse_type=token(for implicit flow), you'd get a short token instead of a valid authorization code.Double-check
client_idand environment consistency
Ensure you're using the exactclient_idfrom your Sonos Developer Account, and that you're using the same environment (sandbox vs production) for both the authorization code request and the token exchange. Mixing endpoints or using the wrong client ID can lead to invalid codes.Match the
redirect_uriexactly
Sonos enforces strict matching for theredirect_uriparameter. The URI you use to request the authorization code must be identical to the one you send when exchanging the code for a token—even small differences like a trailing slash, capitalization, or a typo will cause errors.Validate your token exchange request
When requesting the token, make sure you're:- Sending a
POSTrequest to the correct Sonos token endpoint - Using
application/x-www-form-urlencodedcontent type - Including all required parameters:
grant_type=authorization_codecode=[your authorization code]client_id=[your client ID]client_secret=[your client secret]redirect_uri=[exact same URI as before]
A common mistake here is passing parameters in the URL instead of the request body, or mixing upclient_idandclient_secret.
- Sending a
Check authorization code expiration
Sonos authorization codes have a short lifespan (usually around 10 minutes). If you waited too long to exchange the code for a token, it might have expired—though this typically throws aninvalid_granterror, it's still worth ruling out.
If you've gone through all these steps and still see the client_invalid error, try testing the flow manually with a tool like Postman: replicate the authorization code request, copy the code immediately, then send the token exchange request to see if you get the same error. This can help isolate whether the issue is in your request setup or something else.
内容的提问来源于stack exchange,提问作者Felix Gillen

