You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OAuth 2.0获取令牌时遇invalid grant type错误求助

Fixing the "invalid grant type" Error in Your Shoeboxed OAuth Token Request

Hey there, let's break down why you're hitting that frustrating "invalid grant type" error. This is one of the most common OAuth missteps, and your code has a few key issues that are causing it:

1. You're Missing the Required grant_type Parameter

OAuth 2.0 token requests must include a grant_type to tell the server which flow you're using. For the authorization code flow (which it looks like you're trying), this value needs to be authorization_code. Your current request doesn't include this at all—this is the biggest culprit here.

2. You're Sending JSON Instead of Form-Encoded Data

Most OAuth providers (including Shoeboxed) expect token requests to use application/x-www-form-urlencoded format, not JSON. Your code is passing a JSON string in CURLOPT_POSTFIELDS, which the server doesn't understand for this endpoint.

3. Your code Parameter is Formatted Wrong

The snippet shows you're using "[\"code\"]" as the code value—this is a placeholder wrapped in extra quotes and brackets, which isn't a valid authorization code. You need to replace that with the actual code string you received from the initial authorization step.

Here's a corrected version of your code that fixes all these issues:

<?php
$curl = curl_init();

// Replace these with your actual values from Shoeboxed's dev portal
$auth_code = "YOUR_REAL_AUTHORIZATION_CODE";
$client_id = "YOUR_CLIENT_ID";
$client_secret = "YOUR_CLIENT_SECRET";
$redirect_uri = "YOUR_REDIRECT_URI"; // Must match exactly what you used for authorization

curl_setopt_array($curl, array(
    CURLOPT_URL => "https://id.shoeboxed.com/oauth/token",
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_SSL_VERIFYPEER => true, // Turn this back on for production—disabling it is insecure
    CURLOPT_POST => true,
    // Use http_build_query to create form-encoded data
    CURLOPT_POSTFIELDS => http_build_query(array(
        "grant_type" => "authorization_code",
        "code" => $auth_code,
        "client_id" => $client_id,
        "client_secret" => $client_secret,
        "redirect_uri" => $redirect_uri
    )),
    // Explicitly set the content type header
    CURLOPT_HTTPHEADER => array(
        "Content-Type: application/x-www-form-urlencoded"
    )
));

$response = curl_exec($curl);
$curl_error = curl_error($curl);

curl_close($curl);

if ($curl_error) {
    echo "cURL Error: " . $curl_error;
} else {
    // Decode and print the response to see if it works
    print_r(json_decode($response, true));
}
?>

Extra Checks to Make Sure It Works:

  • If you're using a refresh token flow instead, swap grant_type to refresh_token and replace the code parameter with your refresh_token.
  • Double-check that your client ID, secret, and redirect URI match exactly what's registered in your Shoeboxed developer account—even a tiny typo can break this.
  • Re-enable CURLOPT_SSL_VERIFYPEER in production; disabling it leaves your request vulnerable to man-in-the-middle attacks.

内容的提问来源于stack exchange,提问作者Rick

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:28:58