咨询LinkedIn OAuth1.0a流程中USER_TOKEN与USER_SECRET的获取方式
解决LinkedIn OAuth 1.0a的USER_TOKEN和USER_SECRET获取问题
Hey there! I get why this is confusing—LinkedIn’s old OAuth 1.0a flow doesn’t just hand you USER_TOKEN and USER_SECRET upfront, even when you’re trying to access your own profile. Let’s walk through exactly how to get them:
Step 1: First, set up your app’s callback URL
Before anything else, jump into your LinkedIn app dashboard:
- Navigate to the Auth tab
- Add a valid callback URL (something like
http://localhost:3000/callbackworks great for local testing) - Save your changes—this is non-negotiable, because LinkedIn needs a place to send you after you authorize the app.
Step 2: Generate a temporary Request Token
You’ll need to send a signed request to LinkedIn’s OAuth request token endpoint using your CLIENT_ID and CLIENT_SECRET:
- Endpoint:
https://api.linkedin.com/oauth/requestToken - Your code from the "Developer Authentication" section should handle the OAuth 1.0a signature required for this request (if it’s properly set up).
- The response will give you a temporary
oauth_tokenandoauth_token_secret—don’t mix these up with your final user tokens yet, they’re just intermediaries.
Step 3: Authorize the temporary token
Now you need to grant your own app permission to access your data:
- Redirect yourself to LinkedIn’s authorization page, appending the temporary
oauth_tokenyou just received:https://www.linkedin.com/oauth/authorize?oauth_token=YOUR_TEMP_TOKEN - Log into your LinkedIn account (if you aren’t already) and click "Allow" to grant access to your profile.
- After authorizing, LinkedIn will send you back to your callback URL, and you’ll see an
oauth_verifierparameter in the URL—copy this value immediately.
Step 4: Exchange for permanent User Tokens
Finally, send one last signed request to LinkedIn’s access token endpoint to get your permanent tokens:
- Endpoint:
https://api.linkedin.com/oauth/accessToken - Include these parameters: the temporary
oauth_token, temporaryoauth_token_secret,oauth_verifier, plus your originalCLIENT_IDandCLIENT_SECRET. - The response will give you the actual
oauth_token(this is yourUSER_TOKEN) andoauth_token_secret(yourUSER_SECRET) that your code needs to run.
A quick heads-up
LinkedIn has largely shifted to OAuth 2.0 now, so if you’re starting this project from scratch, you might want to switch to that flow—it’s more straightforward for most modern use cases. But if you’re tied to OAuth 1.0a for your existing code, the steps above will get you the tokens you need.
内容的提问来源于stack exchange,提问作者Aakash Basu

