如何通过认证连接Bricklink API?请求头参数配置报错排查
Bricklink API OAuth认证请求报错:Invalid header name 解决方案
错误原因分析
你遇到的ValueError: Invalid header name b'Authorization: OAuth realm'是因为HTTP头的键格式错误:
- 你把
Authorization: OAuth realm作为了header的键,但合法的HTTP头名称只能是Authorization,而OAuth的所有认证参数应该作为这个头的值来传递,不能拆分成多个独立的header键。 - 另外请求URL的查询参数格式也有误:
?/direction:in/不符合HTTP规范,正确格式是?direction=in。
修正后的代码示例
手动拼接Authorization头的正确写法:
import requests as r # 所有OAuth参数统一放在Authorization头的取值中,格式为OAuth + 空格 + 键值对列表 headers = { "Authorization": 'OAuth realm="", oauth_consumer_key="############", oauth_token="AC40C8C32A1748E0AE1EFA13CCCFAC3A", oauth_signature_method="HMAC-SHA1", oauth_signature="0IeNpR5N0kTEBURcuUMGTDPKU1c%3D", oauth_timestamp="1191242096", oauth_nonce="kllo9940pd9333jh", oauth_version="1.0"' } # 修正查询参数格式:去掉多余的斜杠,用=连接参数名和值 response = r.get("https://api.bricklink.com/api/store/v1/orders?direction=in", headers=headers) print(response.status_code) print(response.text)
更可靠的实现方式(推荐)
手动拼接OAuth参数容易出错,建议使用专门的OAuth 1.0库requests-oauthlib来自动处理签名、时间戳和随机串:
from requests_oauthlib import OAuth1Session # 替换为你的实际密钥信息 consumer_key = "############" consumer_secret = "你的Consumer Secret" token = "AC40C8C32A1748E0AE1EFA13CCCFAC3A" token_secret = "你的Token Secret" # 创建OAuth1会话,自动处理认证参数生成 bricklink_session = OAuth1Session(consumer_key, client_secret=consumer_secret, resource_owner_key=token, resource_owner_secret=token_secret) # 发送GET请求 response = bricklink_session.get("https://api.bricklink.com/api/store/v1/orders?direction=in") print(response.status_code) print(response.json())
关键注意事项
- 时效性参数:
oauth_timestamp必须是当前的Unix时间戳,oauth_nonce是每次请求唯一的随机字符串,固定值会导致认证失败。 - 签名正确性:
oauth_signature需要用你的Consumer Secret和Token Secret结合请求信息生成,手动计算容易出错,推荐用库自动生成。
内容的提问来源于stack exchange,提问作者logan_9997
相关产品推荐
相关产品推荐

