You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否无需OAuth 2使用Dribbble API v2展示个人作品?

Can I use Dribbble API v2 without OAuth 2.0?

Unfortunately, you can’t use Dribbble API v2 without OAuth 2.0 authentication—the team completely removed the simple Client Access Token flow that existed in v1. The v2 API is built around secure user-specific authorization, so every request requires a valid OAuth 2.0 access token tied to a user account.

I get why this is frustrating—v1 made it super easy to pull your own shots for a portfolio with just a single token. But the good news is there are still straightforward ways to display your Dribbble work without overcomplicating things, especially since you’re only showcasing your own shots.

1. Minimal OAuth 2.0 flow (for dynamic updates)

Since you’re accessing your own content, you can set up a one-time authorization to get a token and use it securely:

  • Head to the Dribbble Developer Portal, create a new application, and grab your client_id and client_secret.
  • Use the Authorization Code Flow to generate an access token:
    1. Visit the authorization URL (replace placeholders with your app details):
      https://dribbble.com/oauth/authorize?client_id=YOUR_CLIENT_ID&redirect_uri=YOUR_REDIRECT_URI&response_type=code
      
    2. Log in with your Dribbble account and authorize the app. You’ll get an authorization code in the redirect URL.
    3. Exchange this code for an access token using a server-side script or tool like Postman—never do this in frontend code, as it would expose your client_secret.
  • Create a simple server-side proxy endpoint that calls the Dribbble API (GET /v2/user/shots) with your token, then returns the data to your portfolio frontend. This keeps your token secure and avoids CORS issues.

2. Static generation (simplest for portfolios)

If your shots don’t update constantly, static generation is a low-fuss alternative:

  • Write a quick script (e.g., Node.js, Python) that uses your access token to fetch your shots from the API.
  • Save the response as a static shots.json file in your project.
  • Load this JSON file directly in your portfolio frontend to render your shots.
  • Set up a cron job or manual trigger to run the script whenever you upload a new shot, so your static data stays up to date.

3. Official embed widgets (no API required)

If you want to skip API calls entirely, use Dribbble’s official embed widgets:

  • For each shot, grab the embed code from the shot’s page (click the "Embed" button).
  • Add these embeds directly to your portfolio page. While it’s less flexible than pulling data via API, it’s a zero-code way to display your work.

Important Notes:

  • Never hardcode your access token or client_secret in frontend code—this exposes them to anyone inspecting your page.
  • Access tokens have expiration dates, so use the refresh_token provided with your token to get a new one without re-authorizing.
  • Static generation works best if you don’t update your shots daily, as you’ll need to regenerate the JSON file manually or via automation when adding new work.

内容的提问来源于stack exchange,提问作者Kirill Poddubnyi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:40:03