You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

LinkedIn OpenID Connect集成403错误:配置权限后仍提示r_emailaddress/r_liteprofile权限不足

LinkedIn OpenID Connect集成403错误:配置权限后仍提示r_emailaddress/r_liteprofile权限不足

碰到过一模一样的LinkedIn集成坑,结合你的代码和问题描述,几个关键点你逐一排查,应该能解决:

1. 最致命的错误:调用API时没携带Access Token

看你的代码,获取到$token之后,调用邮箱API的file_get_contents完全没在请求头里加Authorization: Bearer <access_token>!LinkedIn的API根本不知道你是哪个用户,直接返回403是必然的。

修正这部分代码,给file_get_contents加上请求头:

// 拿到access_token后,调用邮箱API必须带授权头
$access_token = $token['access_token'];
$email_url = 'https://api.linkedin.com/v2/emailAddress?q=members&projection=(elements*(handle~))';

// 构造带Authorization头的请求上下文
$context = stream_context_create([
    'http' => [
        'header' => "Authorization: Bearer {$access_token}\r\n"
    ]
]);

// 带上下文请求API
$email_response = file_get_contents($email_url, false, $context);
if ($email_response === false) {
    // 调试错误信息
    $error = error_get_last();
    var_dump($error);
} else {
    $email_data = json_decode($email_response, true);
    // 提取用户邮箱
    $user_email = $email_data['elements'][0]['handle~']['emailAddress'] ?? null;
}

如果要获取用户基本信息(对应r_liteprofile权限),调用/v2/me端点时同样要带这个头:

$profile_url = 'https://api.linkedin.com/v2/me?projection=(id,firstName(localized(en_US)),lastName(localized(en_US)))';
$profile_response = file_get_contents($profile_url, false, $context);
$profile_data = json_decode($profile_response, true);

2. 确认授权请求中正确传递了Scopes

你提到scope = 'openid profile email',但要确保这个Scope参数是在用户跳转到LinkedIn登录的授权URL里传递的,而不是只在后端的Token请求里设置。很多人会犯这个错:

正确的授权URL应该类似(注意URL编码后的Scope参数):

https://www.linkedin.com/oauth/v2/authorization?
response_type=code
&client_id=你的ClientID
&redirect_uri=https://staging.masticationpedia.org/linkedin-callback.php
&scope=openid%20profile%20email  // 这里必须明确传,且URL编码

如果授权时没传对Scope,LinkedIn不会给你r_emailaddress和r_liteprofile权限,拿到的Token自然没有这些权限,调用API就会403。

3. 解码Access Token验证权限

LinkedIn的OpenID Token是JWT格式,你可以解码中间的Base64部分(比如用在线JWT工具,或者自己用PHP解码),查看Payload里的scope字段是否包含r_emailaddress和r_liteprofile。

示例解码后的Payload应该有类似内容:

{
  "scope": "r_liteprofile r_emailaddress openid",
  // 其他字段...
}

如果没有这两个权限,回到第2步检查授权URL的Scope参数;如果有,那就是API调用的问题(比如第1步的头没加对)。

4. 最后确认应用的产品关联状态

虽然你说"Sign In with LinkedIn using OpenID Connect"已启用,但再去LinkedIn开发者后台:

  • 进入你的应用 → 产品标签 → 确认"Sign In with LinkedIn"的状态是"Active"
  • 确保没有未完成的应用审核(非盈利应用的基础权限通常是即时通过的,但偶尔会有延迟)

按这四步排查,尤其是前两步,应该能解决你的403问题。

内容来源于stack exchange

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.08 09:33:08