You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IdentityServer4 User-Info端点返回Forbidden状态的排查求助

排查User-Info端点返回Forbidden的问题

我帮你梳理下几个关键问题点,这应该就是导致403的核心原因:

1. Token请求参数顺序完全错误,导致获取的Token缺少必要Scope

你调用RequestResourceOwnerPasswordAsync的参数顺序搞反了!这个方法的正确签名是:

public Task<TokenResponse> RequestResourceOwnerPasswordAsync(string userName, string password, string scope = null, CancellationToken cancellationToken = default);

而你现在的调用是:

tokenClient.RequestResourceOwnerPasswordAsync("api1","admin","admin")

这相当于把api1当成了用户名、admin当成密码、第二个admin当成scope——完全不符合方法要求!正确的写法应该把用户名、密码放在前两位,最后传入需要的权限范围:

tokenClient.RequestResourceOwnerPasswordAsync("admin","admin", "api1 openid profile")

User-Info端点要求Access Token必须包含openid这个Scope,你之前的错误调用根本没拿到包含该权限的Token,自然会被拒绝访问。

2. 验证Token的Scope是否正确

拿到tokenResponse后,你可以把tokenResponse.AccessToken复制到JWT解析工具(比如本地离线的解析工具)里查看,确认scope字段是否包含openid和profile。如果没有这些值,IdentityServer会直接拒绝UserInfo的访问请求。

3. 额外检查身份资源的注册

确认你的IdentityServer已经正确注册了身份资源,也就是OpenId和Profile必须被添加到配置中,示例代码如下:

public static IEnumerable<IdentityResource> GetIdentityResources()
{
    return new List<IdentityResource>
    {
        new IdentityResources.OpenId(),
        new IdentityResources.Profile()
    };
}

如果没注册这些身份资源,即使你请求了对应的Scope,Token里也不会包含相关权限,同样会导致UserInfo端点返回403。

你先修正Token请求的参数顺序,确保拿到包含openid Scope的Token,再试一次应该就能解决问题了。

内容的提问来源于stack exchange,提问作者buff

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:42:03