You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Reddit API刷新令牌请求访问令牌时报400 Bad Request问题咨询

错误产生原因
  • 授权流不匹配:Reddit的client_credentials授权流属于仅应用级授权,本身不支持刷新令牌机制,duration='permanent'参数仅对需要用户授权的authorization_code授权流生效。你使用client_credentials流即便拿到了形似refresh_token的返回值,该值也不具备刷新access_token的效力,调用刷新接口必然报错。
  • 请求格式错误:你在请求中传入了空的files参数,会导致requests自动将请求头Content-Type设置为multipart/form-data,而Reddit的/api/v1/access_token接口仅接受application/x-www-form-urlencoded格式的参数,格式不匹配会触发400错误。
  • Basic认证配置错误:Reddit要求Authorization的Basic认证值为client_id:client_secret拼接后的Base64编码值,如果仅编码了client_secret、拼接格式错误或者密钥对不匹配,都会返回400错误。
解决方案
  • 确认授权流选择:如果你需要代表用户执行操作,必须切换为authorization_code授权流,走用户授权流程后拿到的refresh_token才可以正常用于刷新令牌;如果你仅需要应用级别的无用户授权调用,无需使用refresh_token,每次access_token过期后重新发起client_credentials流申请新的令牌即可,该流返回的access_token有效期为2小时,直接重新申请成本极低。
  • 修正请求代码:删除请求中的空files参数,保证请求格式为application/x-www-form-urlencoded,修正后的代码示例如下:
import requests

url = "https://www.reddit.com/api/v1/access_token"
payload = {
    'grant_type': 'refresh_token',
    'refresh_token': '你的有效refresh_token'
}
headers = {
    'User-Agent': 'winserp',
    'Authorization': 'Basic 你的正确Base64编码后的client_id:client_secret值'
}

response = requests.post(url, headers=headers, data=payload)
print(response.text)
  • 校验认证信息:确认Basic认证的编码逻辑正确,示例编码逻辑如下:
import base64
client_id = "你的应用client_id"
client_secret = "你的应用client_secret"
auth_str = f"{client_id}:{client_secret}"
b64_auth = base64.b64encode(auth_str.encode()).decode()
# 最终Authorization头值为 f"Basic {b64_auth}"
  • 刷新令牌失效处理:如果确认是authorization_code流拿到的有效refresh_token仍然报错,说明该令牌已被回收(用户取消授权、接口滥用被封禁等),需要重新走用户授权流程获取新的refresh_token。

内容的提问来源于stack exchange,提问作者Zain Nagi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.23 21:45:04