调用Letterboxd API获取认证令牌时持续返回400 Bad Request错误求助
问题分析与修正
你的代码存在三个关键错误,导致400 Bad Request:
- URL拼接错误:你错误地把请求头(headers)编码后拼接到API URL后面,请求头是独立于URL的请求参数,应该通过
requests.post的headers参数传递,而非URL的一部分。 - 请求体格式冲突:你设置了
Content-Type: application/x-www-form-urlencoded,但用json.dumps(body)把请求体转成了JSON字符串,这和声明的内容类型不匹配。表单格式的请求只需直接传递字典给data参数,requests会自动完成编码。 - 缺少客户端认证参数:根据Letterboxd API的密码授权规则,必须提供
client_id和client_secret(通过Basic认证或表单参数传递),你的代码里完全没包含这两个必要参数。
修正后的代码
import requests import base64 # 替换为你在Letterboxd开发者平台申请的客户端ID和密钥 CLIENT_ID = "your_client_id" CLIENT_SECRET = "your_client_secret" headers = { 'Content-Type': 'application/x-www-form-urlencoded', 'Accept': 'application/json' } # 构建Basic认证请求头(推荐方式) auth_credentials = f"{CLIENT_ID}:{CLIENT_SECRET}" encoded_auth = base64.b64encode(auth_credentials.encode()).decode() headers['Authorization'] = f"Basic {encoded_auth}" url = 'https://api.letterboxd.com/api/v0/auth/token' body = { 'grant_type': 'password', 'username': 'myname', 'password': 'mypassword' } # 正确传递请求头和表单数据 response = requests.post(url, headers=headers, data=body) print('\n') print(response.text)
额外说明
- 你需要先在Letterboxd开发者平台注册应用,获取属于自己的
CLIENT_ID和CLIENT_SECRET,否则无法通过API的认证校验。 - 如果不想用Basic认证,也可以把
client_id和client_secret作为键值对添加到body字典中,但官方推荐使用Basic认证方式。
内容的提问来源于stack exchange,提问作者iskra
相关产品推荐
相关产品推荐

