Django Rest Auth集成Facebook登录报错:需access_token或code
Hey there! Let's break down what's likely missing in your setup to get Facebook JWT login working smoothly. That error usually points to either incorrect request data or a configuration gap—since your regular login works, we can focus on the Facebook-specific bits. Here are the key areas to check:
1. Ensure You're Sending the Right Request Parameters
This is the most common cause. When logging in with Facebook, your frontend first needs to fetch a valid user access token from Facebook's SDK, then send it as a POST parameter to the /rest-auth/facebook/ endpoint.
Your request body should look like this (JSON format):
{ "access_token": "YOUR_FACEBOOK_USER_ACCESS_TOKEN" }
If you're using the authorization code flow instead, send a code parameter instead of access_token—just make sure your Facebook app has the correct redirect URI configured to handle the code exchange.
2. Verify django-rest-auth & django-allauth Configuration
Double-check your settings.py to ensure all required Facebook provider settings are in place:
INSTALLED_APPS = [ # ... your other apps 'rest_auth', 'rest_auth.registration', 'allauth', 'allauth.account', 'allauth.socialaccount', 'allauth.socialaccount.providers.facebook', ] # Enable JWT support REST_USE_JWT = True JWT_AUTH_COOKIE = 'jwt-auth' # Optional, if you want to store JWT in a cookie # Configure Facebook social provider SOCIALACCOUNT_PROVIDERS = { 'facebook': { 'METHOD': 'oauth2', 'SCOPE': ['email', 'public_profile'], 'FIELDS': [ 'id', 'email', 'name', 'first_name', 'last_name', 'picture', ], 'EXCHANGE_TOKEN': True, 'VERSION': 'v18.0', # Use the latest Facebook Graph API version matching your app 'VERIFIED_EMAIL': False, # Set to True if you only want verified emails } }
Critical notes:
- Make sure
allauth.socialaccount.providers.facebookis inINSTALLED_APPS. - The
VERSIONmust match the Graph API version your Facebook app uses (old versions may break token validation).
3. Check Your Facebook App Settings
Head to your Facebook Developer Dashboard for your app and verify these:
- OAuth Redirect URIs: Add the callback URL for your app (e.g.,
http://localhost:8000/accounts/facebook/login/callback/for local testing). This is required for both token and code flows. - App Status: If your app is in "Development" mode, only test users can log in. Add yourself as a test user or set the app to "Live" (requires app review for certain permissions).
- Permissions: Ensure the
emailandpublic_profilescopes you're requesting are enabled in your app's permission settings.
4. Confirm URL Routing is Correct
Ensure your urls.py includes all necessary rest-auth and allauth routes:
from django.urls import path, include urlpatterns = [ # ... your other URLs path('rest-auth/', include('rest_auth.urls')), path('rest-auth/registration/', include('rest_auth.registration.urls')), path('accounts/', include('allauth.urls')), # Handles social login callbacks ]
The /rest-auth/facebook/ endpoint (used for Facebook login) is included via rest_auth.urls—make sure this route isn't being overridden by another pattern.
5. Avoid Breaking the Login Serializer
If you've customized the Facebook login serializer, ensure it doesn't remove the access_token or code fields. The default serializer handles these fields correctly, but custom implementations can accidentally omit them:
from rest_auth.registration.serializers import FacebookLoginSerializer class CustomFacebookLoginSerializer(FacebookLoginSerializer): # Add your custom logic here, but keep the base fields intact pass
If you use a custom serializer, register it in settings.py:
REST_AUTH_SERIALIZERS = { 'FACEBOOK_LOGIN_SERIALIZER': 'your_app.serializers.CustomFacebookLoginSerializer', }
6. Check Network Access to Facebook's API
django-allauth needs to validate the Facebook access token by calling Facebook's Graph API. If your server can't reach Facebook (e.g., firewall restrictions), this validation fails and can trigger the error. Test connectivity by running this curl command on your server:
curl "https://graph.facebook.com/debug_token?input_token=USER_ACCESS_TOKEN&access_token=YOUR_APP_ID|YOUR_APP_SECRET"
If this request fails, you'll need to fix your server's network access to Facebook's APIs.
内容的提问来源于stack exchange,提问作者Kishan M

