You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP集成Facebook Account Kit登录异常求助:短信验证后无响应

Hey there! Let's figure out why your Facebook Account Kit SMS login isn't saving user data to your database after OTP verification. You mentioned you're getting through the OTP check just fine, but you end up redirected to index.php with no further action—so the issue is almost certainly missing or misconfigured post-verification logic. Here's how to fix it step by step:

1. Add Post-Verification Logic to index.php

When Account Kit finishes verifying the OTP, it redirects to your configured callback URL (which sounds like index.php) with a code parameter. You need to catch this code, exchange it for user details via Account Kit's API, then handle the database insert/login. Here's a complete code snippet to add to the top of your index.php:

<?php
session_start();

// Replace these with your actual Account Kit credentials
$APP_ID = 'YOUR_APP_ID';
$APP_SECRET = 'YOUR_APP_SECRET';
$API_VERSION = 'v1.1'; // Use the version you're working with

// Handle Account Kit callback after OTP verification
if (isset($_GET['code'])) {
    $auth_code = $_GET['code'];

    // Step 1: Exchange authorization code for access token
    $token_endpoint = "https://graph.accountkit.com/{$API_VERSION}/access_token";
    $token_params = [
        'grant_type' => 'authorization_code',
        'code' => $auth_code,
        'access_token' => "AA|{$APP_ID}|{$APP_SECRET}"
    ];

    // Use cURL if file_get_contents is disabled on your server
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_URL, $token_endpoint . '?' . http_build_query($token_params));
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
    curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true); // Keep this enabled in production
    $token_response = curl_exec($ch);
    curl_close($ch);

    $token_data = json_decode($token_response, true);

    if (isset($token_data['access_token'])) {
        $access_token = $token_data['access_token'];

        // Step 2: Fetch user's phone number using the access token
        $user_endpoint = "https://graph.accountkit.com/{$API_VERSION}/me";
        $user_params = ['access_token' => $access_token];
        
        $ch = curl_init();
        curl_setopt($ch, CURLOPT_URL, $user_endpoint . '?' . http_build_query($user_params));
        curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
        curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true);
        $user_response = curl_exec($ch);
        curl_close($ch);

        $user_data = json_decode($user_response, true);
        $user_phone = $user_data['phone']['number']; // This is the user's verified phone number

        // Step 3: Insert/Update database & set session
        try {
            // Replace with your database credentials
            $pdo = new PDO('mysql:host=localhost;dbname=YOUR_DB_NAME', 'DB_USER', 'DB_PASSWORD');
            $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);

            // Check if user already exists
            $check_user = $pdo->prepare("SELECT id FROM users WHERE phone = :phone");
            $check_user->bindParam(':phone', $user_phone);
            $check_user->execute();
            $existing_user = $check_user->fetch(PDO::FETCH_ASSOC);

            if ($existing_user) {
                // User exists: log them in
                $_SESSION['user_id'] = $existing_user['id'];
                $_SESSION['user_phone'] = $user_phone;
                // Redirect to dashboard instead of staying on index
                header("Location: dashboard.php");
                exit;
            } else {
                // New user: register them
                $insert_user = $pdo->prepare("INSERT INTO users (phone, created_at) VALUES (:phone, NOW())");
                $insert_user->bindParam(':phone', $user_phone);
                $insert_user->execute();

                $_SESSION['user_id'] = $pdo->lastInsertId();
                $_SESSION['user_phone'] = $user_phone;
                header("Location: dashboard.php");
                exit;
            }
        } catch(PDOException $e) {
            echo "Database error: " . $e->getMessage();
        }
    } else {
        // Handle token fetch failure
        echo "Verification failed: " . $token_data['error']['message'] ?? "Unknown error";
    }
}

// Rest of your index.php content goes here
?>
2. Verify Callback URL Configuration

Head to your Facebook Developer Dashboard, navigate to your app > Account Kit > Settings. Make sure the Redirect URL matches your index.php exactly (including http:///https:// and full path). If this doesn't match, Account Kit won't send the code parameter, and your logic won't trigger.

3. Debugging Tips
  • Add var_dump($_GET); at the top of index.php to check if the code parameter is being passed after verification. If it's missing, double-check your callback URL.
  • Check your PHP error logs for issues like cURL being disabled, database connection failures, or SQL syntax errors.
  • Test the API requests manually (using Postman or curl) to ensure you're getting valid token and user data from Account Kit.
4. Ensure Database Setup is Correct

Make sure your users table has a phone field (or whatever you're using to store the verified number) and that your database user has permission to read/write to the table.

内容的提问来源于stack exchange,提问作者Patrick Jane

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:40:10