使用Auth0认证调用EVE Online API的控制台应用登录遇JsonReaderException错误
That Unexpected character encountered while parsing value: < error is a dead giveaway—your code is trying to parse HTML as JSON. Chances are, the EVE authorization endpoint is returning an error page (like a 400 Bad Request) instead of the JSON response you expected, because your login flow is missing critical parameters or using incorrect ones.
Let’s break down what’s going wrong and how to fix it:
Why You’re Seeing This Error
When you get a < as the first character in a response, it’s almost always an HTML document (think: a login page, error message, or redirect). Your JSON parser chokes on this because it’s not valid JSON. This happens when your authorization request doesn’t meet EVE’s OAuth 2.0 requirements.
Correct EVE OAuth 2.0 Flow for Console Apps
EVE’s API uses the Authorization Code Flow (best for confidential clients like console apps) which requires specific parameters at every step. Here’s what you need to do:
1. Build a Valid Authorization Request URL
You can’t just pass default parameters—these are non-negotiable:
response_type: Must becode(this tells EVE to return an authorization code instead of a token directly)client_id: Your unique app ID from the EVE Developer Portalredirect_uri: Exact match of the callback URL you registered in the EVE Developer Portal (for console apps, use something likehttp://localhost:5000/callbackorurn:ietf:wg:oauth:2.0:oobfor out-of-band auth)scope: Space-separated list of EVE API permissions your app needs (e.g.,esi-characters.read_blueprints.v1)state: A random string to prevent CSRF attacks (generate a GUID or similar)
Example query string for the authorization URL:
response_type=code&client_id=YOUR_APP_ID&redirect_uri=http%3A%2F%2Flocalhost%3A5000%2Fcallback&scope=esi-characters.read_blueprints.v1&state=YOUR_RANDOM_GUID
2. Handle the Authorization Response
- Open the constructed URL in the user’s browser (your console app can launch the default browser programmatically)
- After the user logs in and authorizes your app, EVE will redirect to your
redirect_uriwith acodeandstateparameter - First, verify the
statematches the one you generated earlier (critical for security) - Use the
codeto request an access token from EVE’s token endpoint:https://login.eveonline.com/oauth/token
3. Request the Access Token Correctly
This is a POST request with form-encoded parameters (not JSON):
grant_type:authorization_codecode: The authorization code you received from the redirectclient_id: Your app ID againclient_secret: Your app’s secret from the EVE Developer Portal (keep this secure!)redirect_uri: Same as used in the authorization request
This request will return a valid JSON response with your access token, refresh token, etc.—no more HTML parsing errors.
Common Mistakes to Fix
- Mismatched redirect URI: Even a tiny difference (like
httpvshttps, or a missing trailing slash) will trigger an error page - Wrong response_type: Using
token(Implicit Flow) isn’t recommended for console apps and will return a different response format - Missing scope: Some EVE API endpoints require specific scopes—omitting them can lead to errors that return HTML instead of JSON
- Invalid client ID/secret: Double-check these values from the EVE Developer Portal
Quick Code Example (.NET Console App)
Here’s a simplified snippet to illustrate the flow:
using System; using System.Diagnostics; using System.Net.Http; using System.Collections.Generic; using System.Threading.Tasks; class EveAuthFlow { static async Task Main(string[] args) { // Replace these with your app's details var clientId = "YOUR_EVE_APP_ID"; var clientSecret = "YOUR_EVE_APP_SECRET"; var redirectUri = "http://localhost:5000/callback"; var scope = "esi-characters.read_blueprints.v1"; var state = Guid.NewGuid().ToString(); // Build authorization URL var authUrl = $"https://login.eveonline.com/oauth/authorize?response_type=code&client_id={clientId}&redirect_uri={Uri.EscapeDataString(redirectUri)}&scope={Uri.EscapeDataString(scope)}&state={state}"; // Open browser for user to authorize Process.Start(new ProcessStartInfo(authUrl) { UseShellExecute = true }); // Note: You'll need a simple HTTP server here to listen for the redirect and capture the 'code' // For this example, assume you've manually entered the code after authorization Console.Write("Enter authorization code: "); var authCode = Console.ReadLine(); // Request access token using var httpClient = new HttpClient(); var tokenRequest = new FormUrlEncodedContent(new Dictionary<string, string> { {"grant_type", "authorization_code"}, {"code", authCode}, {"client_id", clientId}, {"client_secret", clientSecret}, {"redirect_uri", redirectUri} }); var tokenResponse = await httpClient.PostAsync("https://login.eveonline.com/oauth/token", tokenRequest); tokenResponse.EnsureSuccessStatusCode(); // Will throw if request fails var tokenJson = await tokenResponse.Content.ReadAsStringAsync(); Console.WriteLine("Token response (JSON):"); Console.WriteLine(tokenJson); // Now parse tokenJson with your JSON serializer } }
Once you fix the parameters and follow the proper flow, that JsonReaderException should disappear—you’ll be getting valid JSON responses from EVE’s API endpoints.
内容的提问来源于stack exchange,提问作者Zarwalski

