You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用FusionAuth授权码模式获取AccessToken时未返回RefreshToken求助

Trouble getting refresh_token from FusionAuth with Scribe Java Library

Problem Details

I'm using FusionAuth for authentication and have set up an OAuth-configured application. My authorization URL is:
http://localhost:9011/oauth2/authorize?access_type=offline&prompt=consent&response_type=code&client_id=9ecc54b7-6f79-4105-a208-ca61e6157b58&redirect_uri=http%3A%2F%2Flocalhost%3A8080%2Fipos%2Frest%2FfusionAuth%2FcallBack

After accessing this URL and entering credentials, the callback hits my Java Jersey API endpoint with these parameters:

  • code: dZgq5Xd0YmAQXZ2JIzkih832iojimgLUPwT7yoH9-TY
  • locale: en_US
  • userState: AuthenticatedNotRegistered

I'm using the Scribe Java library to handle OAuth flow. When exchanging the authorization code for an access token (with grant_type=authorization_code), the response looks like this:

{
 "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImRRZTA1Uk1vN19oVjZUUnpLVUQ1aXpRU2NSOCJ9.eyJhdWQiOiI5ZWNjNTRiNy02Zjc5LTQxMDUtYTIwOC1jYTYxZTYxNTdiNTgiLCJleHAiOjE1Nzc3MTg0NjgsImlhdCI6MTU3NzcxODM0OCwiaXNzIjoiYWNtZS5jb20iLCJzdWIiOiI3ZWE3OWRhZi1hZjExLTQ1MTUtODljYS1iOGFjYTFjN2I5YTEiLCJhdXRoZW50aWNhdGlvblR5cGUiOiJQQVNTV09SRCIsImVtYWlsIjoiZGhhdmFsYmhvb3Q5M0BnbWFpbC5jb20iLCJlbWFpbF92ZXJpZmllZCI6dHJ1ZSwicHJlZmVycmVkX3VzZXJuYW1lIjoiZGhhdmFsYmhvb3QifQ.eA0Xi6nEZhWaTMd-P26ESdE3NsyXNRNVBKBdBvHxvzfHgXYJiN2pf-16mY8JK-4-1g3vZF7Cwv-SkP4iZAIJCYYc3uBW8Qlcjjn9cyi7_RggBBBsErcs2acRIt-D5NpnVJfkxHwGAs9fO6a2Win98GGYyv1nzBG9OhWkyZJTy4QxzlgXNrkQIzTuzRwLkRFzKCT95pqfsOYb_MXPuAksg5q1SHIj8qtbO7EO-vMbpmiok1C-Wflbiq2X_tq17QBKbO4JAMLm9_pCZse1tqLyNP4fIh3VHTz7OdbbXvug2Tpk_yTWLVL_29XC87-91R5iXeezLjADkdi1yXMUdHioOw",
 "expires_in": 119,
 "token_type": "Bearer",
 "userId": "7ea79daf-af11-4515-89ca-b8aca1c7b9a1"
}

No matter if it's the user's first login or subsequent ones, the response never includes a refresh_token. I've already shortened the JWT expiration to 120 seconds and enabled the "Generate refresh tokens" option in the application's OAuth settings. I'm stuck on this issue—any help would be appreciated.


Possible Fixes & Troubleshooting Steps

Let's work through this step by step, since you've already checked the main FusionAuth setting ("Generate refresh tokens") and added access_type=offline to your auth URL.

  1. Verify the access_type=offline parameter is actually being sent
    Your auth URL has access_type=offline but uses & (HTML-escaped ampersands). Make sure when the request is sent to FusionAuth, this parameter is properly parsed. Sometimes escaped characters can cause the parameter to be ignored. Use a tool like Chrome DevTools (Network tab) to inspect the actual authorization request URL—confirm access_type=offline is present as a query parameter without any escaping issues.

  2. Ensure Scribe Java is properly including the access_type parameter
    Scribe's default OAuth2 flow might not handle the access_type parameter out of the box. You'll need to explicitly add it when building the authorization URL or configuring your OAuthService. Here's how to do it:

    // Example: Adding custom parameters to the authorization URL
    OAuthService service = new ServiceBuilder("your-client-id")
        .apiSecret("your-client-secret")
        .callback("your-redirect-uri")
        .build(FusionAuthApi.instance()); // You'll need a custom Api class for FusionAuth
    
    // Explicitly add access_type and prompt parameters
    Map<String, String> additionalParams = new HashMap<>();
    additionalParams.put("access_type", "offline");
    additionalParams.put("prompt", "consent");
    String authUrl = service.getAuthorizationUrl(additionalParams);
    

    If your Scribe version is older, you might need to manually append the parameters to the URL string to ensure they're included.

  3. Double-check FusionAuth application settings
    Beyond enabling "Generate refresh tokens", confirm these settings:

    • In your application's Token Configuration, ensure the Refresh token TTL is set to a non-zero value (e.g., 86400 seconds for 1 day). If this is 0 or empty, FusionAuth won't generate a refresh token.
    • Confirm Grant Types includes Authorization Code (you're already using this, but it's worth a quick check).
  4. Test with a clean session
    Even with prompt=consent, cached user sessions might prevent FusionAuth from issuing a refresh token. Try initiating the flow in incognito/private browsing mode, or clear your browser's cookies/cache for the FusionAuth domain. This ensures you're starting a fresh authorization flow.

  5. Validate the token exchange request (bypass Scribe temporarily)
    To rule out Scribe as the issue, test the token exchange directly with a tool like Postman:

    • Method: POST
    • URL: http://localhost:9011/oauth2/token
    • Headers:
      • Content-Type: application/x-www-form-urlencoded
      • For confidential applications, add Authorization: Basic [base64-encoded client_id:client_secret]
    • Form Data:
      • grant_type: authorization_code
      • code: Your authorization code from the callback
      • redirect_uri: Your exact callback URL
      • client_id: Your application's client ID
      • client_secret: Your application's client secret (if confidential)

    If Postman returns a refresh_token, the problem is in your Scribe configuration. If not, the issue is with your FusionAuth setup or initial authorization request.


Final Notes

The most common culprit here is the access_type=offline parameter not being correctly passed to FusionAuth. Start with verifying the actual request parameters, then work through the other steps to narrow down the issue.

内容的提问来源于stack exchange,提问作者Dhaval Bhoot

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 09:10:17