VB.NET Web应用调用PayPal API仅获user_id,如何获取完整用户信息?
Hey there! The reason you're only getting the user_id back is likely due to two key oversights: missing required scopes when requesting your access token, and a missing prefix in your Authorization header. Let's fix this step by step.
1. Ensure Your Access Token Includes Required Scopes
When you first request an access token from PayPal's OAuth2 endpoint, you need to explicitly ask for scopes that grant access to user details. Without these, PayPal will only return the basic user_id. Include these scopes in your token request:
openid(required for OpenID Connect flow)profile(grants access to name, profile details)email(grants access to the user's email address)
For example, when building your token request body:
Dim postData As String = "grant_type=authorization_code&code=YOUR_AUTH_CODE&redirect_uri=YOUR_REDIRECT_URI&scope=openid%20profile%20email"
2. Fix the Authorization Header in Your User Info Request
Your current code adds the access token directly to the Authorization header, but PayPal requires the Bearer prefix before the token. This is a common mistake that restricts the data returned.
Here's the corrected version of your user info request code:
Dim url As String = "https://api.sandbox.paypal.com/v1/oauth2/token/userinfo?schema=openid" Dim req As HttpWebRequest = DirectCast(WebRequest.Create(url), HttpWebRequest) ' GET requests don't strictly need Content-Type, but it's safe to leave it req.ContentType = "application/json" ' Add the critical Bearer prefix to your access token req.Headers.Add("Authorization", "Bearer " & accesstoken) req.Method = "GET" Dim responseData As String = "" Using response As HttpWebResponse = DirectCast(req.GetResponse(), HttpWebResponse) Using reader As New StreamReader(response.GetResponseStream()) responseData = reader.ReadToEnd() End Using End Using ' Now responseData should include full user details like name, email, address, etc. Console.WriteLine(responseData)
3. Verify the Response
After making these changes, your response should include fields like:
namegiven_name/family_nameemailaddress(if the user has provided it)- Additional profile metadata based on the scopes you requested
If you still don't see all the data, double-check that your access token was issued with the correct scopes. You can decode the JWT access token (using a free tool like jwt.io) to inspect the scope claim and confirm permissions.
内容的提问来源于stack exchange,提问作者ajoy

