如何通过cURL正确向REST API发送POST请求?Webex令牌获取异常排查
Let's break down the issues in your code and fix them step by step to get your access token request working:
1. Fix PHP Syntax Errors (The Most Likely Cause of Blank Page)
Looking at your $postRequest array, you've got misplaced commas and comments that break PHP's parser:
// Your original problematic line: "client_id" => ""//actual client id,
The comma sits after the comment, which PHP doesn't recognize as valid syntax. This triggers a fatal error, and if error display is disabled, your page will load as blank.
Fix the array by placing comments correctly and ensuring all key-value pairs end with a comma (except the last one):
$postRequest = array( "client_id" => "your_real_client_id", // Keep comments after the comma "client_secret" => "your_real_client_secret", "code" => $_GET["code"], "redirect_uri" => "http://localhost/test/webex_integration_test/callback.php", "grant_type" => "authorization_code", // Add this missing required parameter "code_verifier" => "your_valid_code_verifier" );
2. Correct the Curl Request Structure
You're currently passing parameters both in the URL and via CURLOPT_POSTFIELDS, which creates conflicting request data. Webex's OAuth2 token endpoint expects a POST request with parameters encoded as application/x-www-form-urlencoded in the request body, not the URL.
- Remove all parameters from the
curl_initURL (just usehttps://api.webex.com/v1/oauth2/token) - Use
http_build_query()to convert your parameter array into a properly encoded string for the POST body - Explicitly set
CURLOPT_POSTtotrueto ensure it's a POST request
3. Enable Error Debugging to Diagnose Issues
Blank pages often hide errors that aren't being displayed. Add these lines at the top of your script to show PHP errors and curl issues:
error_reporting(E_ALL); ini_set('display_errors', 1);
Also, add a check for curl errors after executing the request:
if(curl_errno($cURLConnection)){ echo 'Curl Error: ' . curl_error($cURLConnection); }
4. Validate Critical Parameters
- redirect_uri: Make sure this matches exactly what you configured in the Webex Developer Portal (case, slashes, and all). You don't need to URL-encode it manually—
http_build_query()will handle that. - code_verifier: If you used PKCE during the authorization step (when you sent the user to Webex's login page), this verifier must be the exact same string you used to generate the
code_challenge. Using a hardcoded "abc" will fail unless that's the actual verifier you used earlier.
Full Corrected Code Example
Here's the revised script incorporating all these fixes:
<?php // Enable error display for debugging error_reporting(E_ALL); ini_set('display_errors', 1); // Check if the code parameter exists if (!isset($_GET["code"])) { die("Error: Authorization code is missing from the request!"); } $code = $_GET["code"]; // Your Webex app credentials $client_id = "your_actual_client_id"; $client_secret = "your_actual_client_secret"; $redirect_uri = "http://localhost/test/webex_integration_test/callback.php"; $code_verifier = "your_valid_code_verifier"; // Match this to your authorization step's code_challenge // Build POST parameters $postData = [ "grant_type" => "authorization_code", "client_id" => $client_id, "client_secret" => $client_secret, "code" => $code, "redirect_uri" => $redirect_uri, "code_verifier" => $code_verifier ]; // Initialize curl request $curl = curl_init("https://api.webex.com/v1/oauth2/token"); // Configure curl options curl_setopt($curl, CURLOPT_POST, true); curl_setopt($curl, CURLOPT_POSTFIELDS, http_build_query($postData)); curl_setopt($curl, CURLOPT_RETURNTRANSFER, true); curl_setopt($curl, CURLOPT_HTTPHEADER, [ 'Content-Type: application/x-www-form-urlencoded', 'Connection: Keep-Alive' ]); // Execute request $response = curl_exec($curl); // Check for curl errors if (curl_errno($curl)) { echo "Curl Request Failed: " . curl_error($curl); } // Close curl connection curl_close($curl); // Parse and display the response $jsonResponse = json_decode($response, true); if (json_last_error() !== JSON_ERROR_NONE) { echo "Failed to parse JSON response:<br>"; echo "Raw Response: " . htmlspecialchars($response); } else { echo "Access Token Response:<br>"; print_r($jsonResponse); } ?>
Run this revised script, and you should either get a valid access token response or clear error messages that will help you resolve any remaining issues (like mismatched code_verifier or incorrect credentials).
内容的提问来源于stack exchange,提问作者Neeraj Malwal

