You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

LinkedIn应用权限修改方法及令牌授权异常技术问询

Hey there, let's break down your two questions step by step based on my experience with LinkedIn's v2 API and partner programs:

1. How to Request the Additional Scopes for Your LinkedIn App

Since you're part of the Marketing Partner Program, direct scope adjustments via the developer portal are locked—this is standard for partner-managed apps. Here's the process you'll need to follow:

  • Document detailed use cases: For every new scope you're requesting (like r_liteprofile, w_member_social, rw_ads, etc.), write clear, specific explanations of exactly how your app will use each permission. LinkedIn’s review team needs concrete examples to approve scope requests, especially for write-access or user data-focused scopes.
  • Connect with your dedicated Partner Manager: As a Marketing Partner, you should have an assigned LinkedIn contact. If you don’t know who that is, reach out through the Partner Program’s dedicated support channel (not general developer support).
  • Submit a formal scope request: Your Partner Manager will walk you through the official request workflow, which will require you to share technical details, use case documentation, and confirm compliance with LinkedIn’s API Terms of Service and data privacy policies.
  • Await review and approval: LinkedIn’s team will assess your request to ensure it aligns with platform rules and your partner program status. Some scopes (like w_member_social or rw_organization_admin) may need extra validation of your app’s functionality before being approved.

2. Why You’re Getting a 403 Forbidden Despite Having r_emailaddress in the User Token

This is actually expected behavior under LinkedIn’s two-layer permission model, and here’s the breakdown:

You noted you’re seeing 403 errors when calling these endpoints:

https://api.linkedin.com/v2/clientAwareMemberHandles?q=members&projection=(elements*(primary,type,handle~))

or

https://api.linkedin.com/v2/emailAddress?q=members&projection=(elements*(handle~))

LinkedIn’s token system has two critical checks:

  1. User consent: When a user authorizes your app, they agree to the scopes you request (in this case, r_emailaddress), so the token will include this scope to reflect their approval.
  2. App-level authorization: Your app itself must be explicitly granted access to each scope by LinkedIn. Even if a user consents to a scope, if your app hasn’t been approved to use that permission, the API will block the call with a 403 error.

In your scenario, your app’s current scopes don’t include r_emailaddress—so even though the user’s token has that scope, LinkedIn rejects the request because your app isn’t authorized to access email data. To fix this, you’ll need to include r_emailaddress in your scope request (from question 1), get LinkedIn’s approval for your app, then re-request authorization from users (to generate a token that pairs the user’s consent with your app’s approved scopes).

内容的提问来源于stack exchange,提问作者Szasza Palmer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 09:04:03