You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Letterboxd API获取认证令牌时持续返回400 Bad Request错误求助

问题分析与修正

你的代码存在三个关键错误,导致400 Bad Request:

  • URL拼接错误:你错误地把请求头(headers)编码后拼接到API URL后面,请求头是独立于URL的请求参数,应该通过requests.post的headers参数传递,而非URL的一部分。
  • 请求体格式冲突:你设置了Content-Type: application/x-www-form-urlencoded,但用json.dumps(body)把请求体转成了JSON字符串,这和声明的内容类型不匹配。表单格式的请求只需直接传递字典给data参数,requests会自动完成编码。
  • 缺少客户端认证参数:根据Letterboxd API的密码授权规则,必须提供client_id和client_secret(通过Basic认证或表单参数传递),你的代码里完全没包含这两个必要参数。

修正后的代码

import requests
import base64

# 替换为你在Letterboxd开发者平台申请的客户端ID和密钥
CLIENT_ID = "your_client_id"
CLIENT_SECRET = "your_client_secret"

headers = {
    'Content-Type': 'application/x-www-form-urlencoded',
    'Accept': 'application/json'
}

# 构建Basic认证请求头(推荐方式)
auth_credentials = f"{CLIENT_ID}:{CLIENT_SECRET}"
encoded_auth = base64.b64encode(auth_credentials.encode()).decode()
headers['Authorization'] = f"Basic {encoded_auth}"

url = 'https://api.letterboxd.com/api/v0/auth/token'

body = {
    'grant_type': 'password',
    'username': 'myname',
    'password': 'mypassword'
}

# 正确传递请求头和表单数据
response = requests.post(url, headers=headers, data=body)
print('\n')
print(response.text)

额外说明

  1. 你需要先在Letterboxd开发者平台注册应用,获取属于自己的CLIENT_ID和CLIENT_SECRET,否则无法通过API的认证校验。
  2. 如果不想用Basic认证,也可以把client_id和client_secret作为键值对添加到body字典中,但官方推荐使用Basic认证方式。

内容的提问来源于stack exchange,提问作者iskra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 22:24:30