You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用OAuth2 Hybrid Flow请求CodeIdTokenToken时无法获取refresh_token

解决IdentityServer4 Hybrid Flow下无法获取Refresh Token的问题

检查IdentityServer4客户端核心配置

  • 必须开启AllowOfflineAccess并添加offline_access权限,这是颁发Refresh Token的核心前提:
    new Client
    {
        ClientId = "你的客户端ID",
        // 其他基础配置...
        AllowOfflineAccess = true,
        AllowedScopes = { "openid", "profile", "你的API权限", "offline_access" }
    }
    

验证OWIN客户端的Scope请求

在MVC 5.2的OWIN配置中,要显式指定offline_access作为请求Scope,否则IdentityServer不会返回Refresh Token:

app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions
{
    ClientId = "你的客户端ID",
    Authority = "你的IdentityServer地址",
    RedirectUri = "你的客户端回调地址",
    ResponseType = "code id_token token", // 对应你使用的CodeIdTokenToken模式
    Scope = "openid profile 你的API权限 offline_access", // 必须包含offline_access
    // 其他配置...
    TokenValidationParameters = new TokenValidationParameters
    {
        NameClaimType = "name",
        RoleClaimType = "role"
    }
});

确认客户端授权类型配置

确保IdentityServer客户端的AllowedGrantTypes设置为Hybrid类型:

AllowedGrantTypes = GrantTypes.Hybrid,

补充:Refresh Token存储(可选)

如果需要长期保留Refresh Token,需确保IdentityServer配置了有效的存储方案(比如Entity Framework存储),但这一步不影响初始获取,仅关系后续刷新操作的可用性。


内容的提问来源于stack exchange,提问作者Erwin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 02:46:22