You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

UPS API OAuth令牌请求失败:10400错误(无效/缺失授权头)

UPS OAuth令牌获取:解决10400 "Invalid/Missing Authorization Header"错误

问题核心

你遇到的10400错误,本质是请求缺少OAuth Client Credentials模式要求的Basic Auth授权头,和grant_type的取值无关(grant_type固定为client_credentials,不是你的Client Secret)。

错误原因

UPS的OAuth Client Credentials流程要求:

  • 除了x-merchant-id(填你的Client Id)和grant_type=client_credentials表单参数外,必须通过Authorization头传递Client Id和Client Secret的Base64编码值。
  • 官方"Try it out"功能会自动帮你生成这个授权头,但手动构造请求时容易遗漏。

解决步骤

  1. 构造Basic Auth字符串:

    • 把你的Client Id和Client Secret用冒号拼接:{你的Client Id}:{你的Client Secret}
    • 对拼接后的字符串做Base64编码(可通过编程语言内置方法或在线工具完成)
  2. 修正请求头:

    • 添加Authorization: Basic <Base64编码后的字符串>头
  3. 正确的curl请求示例:

    curl -X POST "https://wwwcie.ups.com/security/v1/oauth/token" 
         -H "accept: application/json" 
         -H "x-merchant-id: {你的Client Id}" 
         -H "Authorization: Basic {Base64(ClientId:ClientSecret)}"
         -H "Content-Type: application/x-www-form-urlencoded" 
         -d "grant_type=client_credentials"
    

验证要点

  • 确保x-merchant-id严格匹配你的应用Client Id
  • grant_type必须是client_credentials,不要替换成Client Secret
  • Authorization头的Base64编码没有额外空格或换行
  • 请求的Content-Type必须是application/x-www-form-urlencoded

内容的提问来源于stack exchange,提问作者ConfuedProblemSolver

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 00:41:12