使用CURL调用PayPal Payout API遇REQUIRED_SCOPE_MISSING错误求助
Hey there, let's break down why you're hitting this scope error with PayPal Payouts—even if you've checked the app permissions, there's usually a small oversight in how you're requesting your access token or setting up the app. Here's what to check step by step:
1. Make sure you request the correct scope when fetching your access token
PayPal's client credentials grant doesn't automatically include Payouts permissions by default. You need to explicitly specify the Payouts-related scope in your token request.
For sending payouts, you need the scope: https://api.paypal.com/v1/payments/payouts (add https://api.paypal.com/v1/payments/payouts.read if you also need to query payout statuses).
Update your token request in the get_access_token function to include this scope. Here's how the POST data should look in PHP:
$postdata = 'grant_type=client_credentials&scope=https://api.paypal.com/v1/payments/payouts';
If you're using raw cURL, it'd look like this:
curl -X POST https://api.sandbox.paypal.com/v1/oauth2/token \ -u "YOUR_CLIENT_ID:YOUR_SECRET" \ -d "grant_type=client_credentials&scope=https://api.paypal.com/v1/payments/payouts"
2. Verify your app's Payouts permissions are enabled and active
Head back to the PayPal Developer Console:
- Go to your app's details page, switch to the Permissions tab
- Ensure the
Payoutspermission is marked as Enabled - Important note: Payouts only work with Business-type PayPal accounts. If your app is linked to a Personal account, even with permissions enabled, you'll hit this error—double-check your account type.
- Also, if you just enabled the permission, wait a minute or two; sometimes permissions take a short time to propagate to the sandbox API.
3. Check what scopes your access token actually has
To confirm your token includes the right permissions, call PayPal's token info endpoint with your access token:
curl -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \ https://api.sandbox.paypal.com/v1/oauth2/tokeninfo?access_token=YOUR_ACCESS_TOKEN
Look for the scope field in the JSON response—if it doesn't include the Payouts scope string, your token request was missing the parameter, so go back to step 1.
4. Confirm you're using the correct environment
You're targeting the sandbox (api.sandbox.paypal.com), so make sure your app is a Sandbox app (not a Live app) and that you enabled permissions in the Sandbox section of the console. Mixing live/sandbox credentials or settings will cause scope issues too.
A quick code quality tip: Avoid using global variables in your get_access_token function—pass $clientId and $secret as function parameters instead. It makes the code cleaner and avoids unexpected variable scoping issues.
内容的提问来源于stack exchange,提问作者Sunny Kasera

