You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerBI REST API 在指定网关创建数据源报Base64无效错误求助

问题根因

你收到的Base64格式错误是因为创建Power BI网关数据源的接口要求credentialDetails.credentials字段必须为使用对应网关公钥加密后的Base64编码字符串,你当前直接传入了明文的凭证JSON结构,不符合接口要求。

解决步骤

  • 先调用网关查询接口获取目标网关的公钥、公钥指数参数,加密时必须使用接口返回的参数
  • 构造明文凭证JSON结构,使用RSA-OAEP算法+网关公钥加密明文内容
  • 将加密后的二进制内容转换为Base64字符串,填充到请求体的credentials字段中再提交请求

可运行PowerShell实现代码

# 1. 配置基础参数
$gatewayId = "你的网关ID"
$accessToken = "你的Power BI访问令牌"
$apiBaseUrl = "https://api.powerbi.com/v1.0/myorg/gateways"

# 2. 获取网关公钥信息
$getGatewayUrl = "$apiBaseUrl/$gatewayId"
$headers = @{
    "Authorization" = "Bearer $accessToken"
}
$gatewayInfo = Invoke-RestMethod -Uri $getGatewayUrl -Headers $headers -Method Get
$publicKey = $gatewayInfo.publicKey
$modulusBytes = [Convert]::FromBase64String($publicKey.modulus)
$exponentBytes = [Convert]::FromBase64String($publicKey.exponent)

# 3. 构造RSA公钥参数
$rsa = New-Object System.Security.Cryptography.RSACryptoServiceProvider
$rsaParams = New-Object System.Security.Cryptography.RSAParameters
$rsaParams.Modulus = $modulusBytes
$rsaParams.Exponent = $exponentBytes
$rsa.ImportParameters($rsaParams)

# 4. 构造明文凭证并加密
$plainCredentials = @{
    credentialData = @(
        @{name = "username"; value = "你的数据库用户名"},
        @{name = "password"; value = "你的数据库密码"}
    )
} | ConvertTo-Json -Compress
$plainBytes = [System.Text.Encoding]::UTF8.GetBytes($plainCredentials)
$encryptedBytes = $rsa.Encrypt($plainBytes, $true) # 第二个参数为true表示使用OAEP填充
$encryptedCredentials = [Convert]::ToBase64String($encryptedBytes)

# 5. 构造创建数据源的请求体
$createDatasourceUrl = "$apiBaseUrl/$gatewayId/datasources"
$postBody = @{
    connectionDetails = '{"server":"aaa","database":"bbb"}'
    credentialDetails = @{
        credentialType = "Basic"
        credentials = $encryptedCredentials
        encryptedConnection = "Encrypted"
        encryptionAlgorithm = "RSA-OAEP"
        privacyLevel = "None"
        useEndUserOAuth2Credentials = "False"
    }
    datasourceName = "ddd"
    dataSourceType = "Sql"
} | ConvertTo-Json -Depth 10

# 6. 提交请求创建数据源
Invoke-RestMethod -Uri $createDatasourceUrl -Headers $headers -Method Post -Body $postBody -ContentType "application/json"

注意事项

  • 访问令牌需要有Dataset.ReadWrite.All或者Gateway.ReadWrite.All权限
  • 加密时必须使用RSA-OAEP填充,不要使用PKCS#1填充,否则还是会报格式错误
  • 如果网关是本地数据网关,需要确保网关运行状态正常,且你有网关的管理员权限

内容的提问来源于stack exchange,提问作者RaN

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 23:15:03