LinkedIn登录返回null AccessToken求助:原正常应用也无法获取
Let’s break down the most likely causes and fixes for this frustrating issue, since you’ve already verified the core configuration (Bundle ID, hashes, App ID):
1. Check for State Parameter Mismatches or CSRF Validation Issues
LinkedIn’s OAuth 2.0 flow requires a unique state parameter to prevent CSRF attacks. When you cloned the app, it’s possible your implementation either reused a stale state value, or failed to properly validate the returned state against the one you sent. Even after restoring the original app, leftover cached state values could be causing misalignment.
- Fix steps:
- Ensure your app generates a new random
statevalue for every login attempt. - Double-check that after receiving the authorization code, you’re validating that the returned
statematches exactly the one you sent in the initial request. - Clear any persisted state data in your app’s local storage (SharedPreferences on Android, UserDefaults on iOS) and test again.
- Ensure your app generates a new random
2. Verify Token Request Format & Parameters
The null access token with expiresOn:0 often points to a malformed request to LinkedIn’s token endpoint. Even small formatting errors can cause silent failures.
- Key checks:
- Make sure the token request uses
Content-Type: application/x-www-form-urlencoded(not JSON). - Confirm all required parameters are included:
grant_type=authorization_code,code=<your-authorization-code>,redirect_uri=<your-configured-redirect-uri>,client_id=<your-app-id>,client_secret=<your-app-secret>. - On Android, ensure you’re not accidentally URL-encoding parameters multiple times (some networking libraries do this automatically).
- Make sure the token request uses
3. Reconfirm Signature Hashes (Android) & Provisioning Profiles (iOS)
Even if you checked these earlier, subtle changes can slip in:
- Android:
- If your cloned app used a different keystore (e.g., debug vs release), double-check that all relevant hashes are added in the LinkedIn Developer Console. Sometimes restoring the original app might switch back to a debug build but the console only has the release hash.
- Regenerate the hash using the exact keystore you’re using for testing:
keytool -exportcert -alias <your-key-alias> -keystore <your-keystore-path> | openssl sha1 -binary | openssl base64
- iOS:
- Ensure your provisioning profile includes the correct Bundle ID and that the app is signed with the matching certificate. Sometimes cloning can mess up Xcode’s signing configuration.
- Verify the redirect URI in LinkedIn Console matches exactly what’s configured in your
Info.plist(e.g.,li<your-app-id>://auth).
4. Check LinkedIn App Permissions & Token Version
It’s possible that during the cloning process, you accidentally modified the app’s permission scopes in the LinkedIn Console, or LinkedIn’s token version changed unexpectedly.
- Fix steps:
- Go to your LinkedIn App’s "Auth" tab and confirm that the scopes you’re requesting (e.g.,
r_liteprofile,r_emailaddress) are still enabled. - Ensure you’re requesting the correct scopes in your login flow—missing required scopes can lead to empty tokens.
- Try revoking all existing authorizations for your app (under LinkedIn’s "Settings & Privacy" > "Third-party apps") and test with a fresh account.
- Go to your LinkedIn App’s "Auth" tab and confirm that the scopes you’re requesting (e.g.,
5. Clear Cached Data (Device & App)
Cached data from the LinkedIn app or your own app can cause persistent issues:
- On Android/iOS, force close the LinkedIn app and clear its cache.
- Uninstall your app, clear any leftover app data (Android: Settings > Apps > Your App > Storage > Clear Data), then reinstall and test.
内容的提问来源于stack exchange,提问作者Matej Košút

