OAuth 2.0获取令牌时遇invalid grant type错误求助
Hey there, let's break down why you're hitting that frustrating "invalid grant type" error. This is one of the most common OAuth missteps, and your code has a few key issues that are causing it:
1. You're Missing the Required grant_type Parameter
OAuth 2.0 token requests must include a grant_type to tell the server which flow you're using. For the authorization code flow (which it looks like you're trying), this value needs to be authorization_code. Your current request doesn't include this at all—this is the biggest culprit here.
2. You're Sending JSON Instead of Form-Encoded Data
Most OAuth providers (including Shoeboxed) expect token requests to use application/x-www-form-urlencoded format, not JSON. Your code is passing a JSON string in CURLOPT_POSTFIELDS, which the server doesn't understand for this endpoint.
3. Your code Parameter is Formatted Wrong
The snippet shows you're using "[\"code\"]" as the code value—this is a placeholder wrapped in extra quotes and brackets, which isn't a valid authorization code. You need to replace that with the actual code string you received from the initial authorization step.
Here's a corrected version of your code that fixes all these issues:
<?php $curl = curl_init(); // Replace these with your actual values from Shoeboxed's dev portal $auth_code = "YOUR_REAL_AUTHORIZATION_CODE"; $client_id = "YOUR_CLIENT_ID"; $client_secret = "YOUR_CLIENT_SECRET"; $redirect_uri = "YOUR_REDIRECT_URI"; // Must match exactly what you used for authorization curl_setopt_array($curl, array( CURLOPT_URL => "https://id.shoeboxed.com/oauth/token", CURLOPT_RETURNTRANSFER => true, CURLOPT_SSL_VERIFYPEER => true, // Turn this back on for production—disabling it is insecure CURLOPT_POST => true, // Use http_build_query to create form-encoded data CURLOPT_POSTFIELDS => http_build_query(array( "grant_type" => "authorization_code", "code" => $auth_code, "client_id" => $client_id, "client_secret" => $client_secret, "redirect_uri" => $redirect_uri )), // Explicitly set the content type header CURLOPT_HTTPHEADER => array( "Content-Type: application/x-www-form-urlencoded" ) )); $response = curl_exec($curl); $curl_error = curl_error($curl); curl_close($curl); if ($curl_error) { echo "cURL Error: " . $curl_error; } else { // Decode and print the response to see if it works print_r(json_decode($response, true)); } ?>
Extra Checks to Make Sure It Works:
- If you're using a refresh token flow instead, swap
grant_typetorefresh_tokenand replace thecodeparameter with yourrefresh_token. - Double-check that your client ID, secret, and redirect URI match exactly what's registered in your Shoeboxed developer account—even a tiny typo can break this.
- Re-enable
CURLOPT_SSL_VERIFYPEERin production; disabling it leaves your request vulnerable to man-in-the-middle attacks.
内容的提问来源于stack exchange,提问作者Rick

