You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Salesforce社区用户JWT Bearer流获取access token报错排查

社区用户JWT Bearer OAuth流配置报错修复方案

返回错误说明

接口返回的错误内容翻译如下:

{
  "error": "invalid_grant",
  "error_description": "受众参数无效"
}

核心问题修复点

1. 替换错误的令牌请求端点

当前使用的https://login.salesforce.com/services/oauth2/token是Salesforce全局内部用户授权端点,仅支持内部标准用户授权,社区/体验云用户的JWT授权请求必须发送到社区自身域名下的OAuth端点,格式为:
https://<你的社区完整域名>/services/oauth2/token
以你给出的社区地址https://my-community.force.com/customers为例,正确的请求端点是https://my-community.force.com/customers/services/oauth2/token。
请求中携带的Cookie头属于冗余内容,服务端到服务端的JWT流不需要浏览器Cookie参数,可直接移除。修正后的参考请求:

curl --location --request POST 'https://my-community.force.com/customers/services/oauth2/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer' \
--data-urlencode 'assertion=<生成的合法JWT字符串>'

2. 修正JWT Payload参数

你当前构造的JWT Payload存在三处不符合规范的问题:

  • aud(受众)参数值错误:aud的值必须匹配授权端点的根域名,不能携带路径后缀。社区场景下固定填社区根地址即可,你当前填写的https://my-community.force.com/customers带了路径后缀,是触发本次invalid audience错误的核心原因,正确值应为https://my-community.force.com。
  • exp(过期时间)参数格式错误:exp必须是整数类型的Unix时间戳,你当前传入的是字符串格式,部分校验逻辑会直接判定格式非法。
  • sub(主体)参数匹配要求:sub字段必须和目标社区用户的Username字段值完全一致,注意社区用户的用户名不一定等于用户的联系邮箱,不能直接填用户邮箱,需要到用户详情页确认准确的Username值,也可以填用户的18位Salesforce ID或者配置的联邦ID。

修正后的参考Payload:

{
  "iss": "<Connected App对应的Consumer Key值>",
  "sub": "目标社区用户的准确Username",
  "aud": "https://my-community.force.com",
  "exp": 1654818853,
  "scope": "web api openid id"
}

3. 前置配置校验

修正参数后如果仍报错,逐一核对以下配置项:

  • JWT必须使用RS256算法签名,签名用的私钥必须和上传到Connected App的数字证书是匹配的密钥对。
  • Connected App必须开启JWT授权流程:在Connected App设置页勾选「Use digital signatures」选项,上传对应公钥证书。
  • Connected App的访问策略设置为「Admin approved users are pre-authorized」,并将目标社区用户所属的Profile、Permission Set加入允许访问列表,避免用户未授权报错。
  • 目标社区用户为激活状态,已被加入对应社区的成员列表,有社区访问权限。

令牌使用说明

成功获取access_token后,访问frontdoor.jsp必须使用社区域名,不能使用全局login域名,访问格式为:
https://<你的社区完整域名>/secur/frontdoor.jsp?sid=<获取到的access_token值>

内容的提问来源于stack exchange,提问作者Alejandro Sanchez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.30 10:57:14