如何编写Python代码获取AWS Cognito访问令牌?代码调试求助
I have a working Postman POST request to get an access token from Amazon Cognito. The request URL is phmo-test/auth.us-east-1.amazoncognito.com/oauth2/token?grant_type=client_credentials, using Client ID and Client Secret for authorization. When I convert this to Python requests code, the script doesn't return a status code at all. Here's my code:
base_url = 'http://phmo-test.auth.us-east-1.amazoncognito.com/oauth2/token' client_id=<my client ID> client_secret=<My client secret> grant_type='client_credentials' headers = {'Content-Type':'application/x-www-form-urlencoded', 'cookie':'XSRF-TOKEN=27293445-d70d-4907-bfc5-62ba8a84697c'} response = requests.post(base_url, auth={'Username':client_id, 'Password':client_secret}, params={'grant_type':grant_type}, headers = headers) print("WAHHHHHHHHHHHHHHHHHHH",response.status_code)
What am I doing wrong?
Let's walk through the issues in your code that are blocking you from getting a valid response status code:
Wrong URL protocol: Amazon Cognito's APIs exclusively use HTTPS. Using
http://will either make your request hang indefinitely (since Cognito doesn't listen on HTTP ports) or fail silently—this is almost certainly why you're not seeing any status code at all. Switch tohttps://for the base URL.Incorrect auth parameter format: For Cognito's Client Credentials flow, you need to use HTTP Basic Authentication. The
requests.post()method expects theauthparameter to be a tuple of(client_id, client_secret), not a dictionary withUsernameandPasswordkeys. The dictionary format is meant for other auth schemes (like Digest Auth) and won't work here.Unnecessary XSRF cookie: The
XSRF-TOKENcookie is only required for browser-based flows (like Authorization Code with PKCE). For server-to-server Client Credentials flow, this cookie is irrelevant and can be removed entirely—it might even cause unexpected validation issues.Grant type in the wrong place: The
grant_type=client_credentialsshould be sent as form-encoded data in the request body, not as a URL query parameter. Even if your Postman request had it in the URL, Cognito expects this parameter in the body for this flow. Use thedataparameter instead ofparams.
Here's the fixed code:
import requests base_url = 'https://phmo-test.auth.us-east-1.amazoncognito.com/oauth2/token' client_id = '<your client ID>' client_secret = '<your client secret>' grant_type = 'client_credentials' # Only keep the necessary Content-Type header headers = {'Content-Type': 'application/x-www-form-urlencoded'} response = requests.post( base_url, auth=(client_id, client_secret), data={'grant_type': grant_type}, headers=headers ) print("Status Code:", response.status_code) # Add this to debug any error messages from Cognito print("Response Details:", response.json())
If you still hit issues after these changes, double-check that your Cognito app client is configured to allow the Client Credentials flow (make sure the flow is enabled in the app client settings and the client has the appropriate permissions for your resources).
内容的提问来源于stack exchange,提问作者user8882700

