Salesforce OAuth无法获取refresh token问题求助
Hey there! Let's troubleshoot why you're not getting the expected refresh token (or token data) even though Salesforce returns a 200 OK status. Here's a breakdown of the issues in your code and how to fix them:
1. You're Using the Wrong OAuth Endpoint
Your code targets https://login.salesforce.com, but Salesforce's official OAuth token endpoint is https://login.salesforce.com/services/oauth2/token. Missing that trailing path segment means you're hitting the Salesforce login page instead of the OAuth service—hence the 200 OK, but no token data.
2. Parameters Belong in the Request Body (Not the URL)
While POST requests can technically carry parameters in the URL, Salesforce expects OAuth grant parameters to be sent as form-urlencoded data in the request body. Putting sensitive values like client_secret in the URL is also a security risk, as they may get logged by servers or proxies.
3. You're Not Reading the Response Content
You're sending the request but never accessing the response body. Even if the endpoint was correct, you wouldn't see any token data unless you parse the content returned by Salesforce.
Fixed VB.NET Code Example
Imports System.Net.Http Imports System.Net.Http.Headers Imports System.Text.Json ' Define a class to map the Salesforce token response (adjust fields as needed) Public Class SalesforceTokenResponse Public Property access_token As String Public Property instance_url As String Public Property id As String Public Property token_type As String Public Property issued_at As String ' Note: A new refresh_token is only returned if your connected app is configured to rotate tokens Public Property refresh_token As String End Class ' Your updated token retrieval logic Dim createClient As New HttpClient() Dim tokenEndpoint As String = "https://login.salesforce.com/services/oauth2/token" ' Prepare form-urlencoded parameters Dim formData As New Dictionary(Of String, String)() formData.Add("grant_type", "refresh_token") formData.Add("client_id", strKey) formData.Add("client_secret", strSecret) formData.Add("refresh_token", refreshToken) ' Build the POST request Dim request = New HttpRequestMessage(HttpMethod.Post, tokenEndpoint) request.Content = New FormUrlEncodedContent(formData) ' Send request and process response Dim response = Await createClient.SendAsync(request) response.EnsureSuccessStatusCode() ' Throws an error if status code is not 2xx ' Read and parse the JSON response Dim responseContent = Await response.Content.ReadAsStringAsync() Dim tokenResponse = JsonSerializer.Deserialize(Of SalesforceTokenResponse)(responseContent) ' Access the token data Console.WriteLine($"New Access Token: {tokenResponse.access_token}") ' Check if a new refresh token was returned (depends on your connected app settings) If Not String.IsNullOrEmpty(tokenResponse.refresh_token) Then Console.WriteLine($"New Refresh Token: {tokenResponse.refresh_token}") End If
Critical Notes to Keep in Mind
- Refresh Token Rotation: Salesforce only returns a new
refresh_tokenif your connected app is configured to "Rotate Refresh Tokens" (found under Connected App > OAuth Policies). By default, using a refresh token will only issue a newaccess_token—this is expected behavior, not an error. - Validate Response Content: Even with a 200 OK, always read the response body. Sometimes Salesforce returns error messages in JSON format (e.g., invalid refresh token, expired credentials) that might look like a success at first glance.
- Security Best Practices: Never hardcode
client_id,client_secret, orrefresh_tokenin your code. Use secure configuration storage instead.
内容的提问来源于stack exchange,提问作者Imad

