将R Studio连接至Exact Online API时的授权码使用问题
Hey there, let's break down the most common issues that trip people up when exchanging an authorization code for tokens in Step 3 of the Exact Online OAuth2 flow—since you've already got Steps 1 and 2 sorted, we can zero in on this specific request.
First, let's make sure we're aligned on what a valid token exchange request requires (small mistakes here cause most failures):
Important: The token endpoint is region-specific (e.g., for the Netherlands it's
https://start.exactonline.nl/api/oauth2/token—confirm you're using the correct one for your Exact Online environment).
Here are the critical checks to run through:
- Confirm your request method and content type: You must send a
POSTrequest with aContent-Typeheader set toapplication/x-www-form-urlencoded. GET requests will fail outright, and JSON payloads aren't supported here. - Validate all required parameters (no typos!): Your request body must include these exact fields:
grant_type: Must be set toauthorization_code(this is non-negotiable—any other value will throw an error)code: The full authorization code from your redirect URL (make sure you're only using the string aftercode=—no extra characters or URL prefixes)redirect_uri: This must match exactly the one you registered in your Exact Online app settings. Even a tiny difference (like a missing trailing slash) will cause the request to be rejected.client_id: Your app's unique client ID from the Exact Online developer portalclient_secret: Your app's client secret (keep this secure—never expose it in frontend code!)
- Check code expiration: Exact Online's authorization codes expire after 10 minutes. If you waited too long to exchange it, you'll need to redo Steps 1 and 2 to get a fresh code.
- Analyze the error response: Don't overlook the error message you're getting—it's your best clue. Common issues include:
invalid_grant: Typically means the code is expired, invalid, or your redirect URI doesn't match the registered oneinvalid_client: Double-check that your client ID and secret are correct and properly URL-encodedunsupported_grant_type: You either forgot to setgrant_type=authorization_codeor used an incorrect value
If you're testing with a tool like Postman, here's a quick setup checklist:
- Set the request method to
POST - Input the correct region-specific token endpoint
- Navigate to the "Body" tab, select
x-www-form-urlencoded(this is the required format) - Add all the parameters listed above with their accurate values
One last gotcha: don't URL-decode the authorization code before sending it. Use the raw string you pulled from the redirect URL (just make sure you strip off the code= prefix).
内容的提问来源于stack exchange,提问作者Stan

