Magento 1 REST API 报错:本地返回403、线上返回404
Troubleshooting Magento REST API: Valid Token but 403 (Local) / 404 (Production)
Let’s break down this frustrating dual-environment issue you’re facing—getting a valid token but hitting 403 locally and 404 in production. I’ve tangled with Magento’s REST API quirks enough times to know exactly where to look, so let’s walk through fixes step by step:
Local Environment: 403 Forbidden Error
- Double-Check API Resource Permissions: A valid token doesn’t mean your user role has access to product/customer endpoints. Head to Magento Admin → System → User Roles → [Your Integration Role] → Role Resources. Make sure either ALL resources are allowed, or specifically check boxes for
Magento_Catalog::productsandMagento_Customer::customers. This is the #1 overlooked cause for 403s. - Verify Token Scope: When you requested the token, did you specify the correct scope? If you used
adminscope but your integration is meant for storefront access, you’ll hit permission blocks. Confirm your token request body looks like this (adjust scope as needed):{ "username": "your_admin_user", "password": "your_admin_pass", "scope": "admin" } - Test Server-Side with Curl: Local dev servers (like XAMPP/WAMP) sometimes have wonky CORS or .htaccess rules blocking client-side requests. Rule out client issues by running this directly from your local server terminal:
If this works, the problem is with your test client’s CORS setup, not Magento.curl -H "Authorization: Bearer YOUR_VALID_TOKEN" http://local-magento-url/rest/V1/products
Production Environment: 404 Not Found Error
- Don’t Skip the Store Code: Magento’s production REST URLs require a store code unless you’ve configured a default. For example, if your production store uses code
default, your URL should behttps://prod-magento-url/rest/default/V1/products—missing the/default/segment is the most common 404 trigger here. - Validate Rewrite Rules & HTTPS: Production servers often have stricter URL rewriting. Go to Admin → Stores → Configuration → General → Web and confirm
Use Web Server Rewritesis enabled. Also, ensure you’re using HTTPS for API requests—Magento may redirect or block HTTP calls in production. - Confirm Integration is Active: It’s easy to forget, but sometimes integrations get disabled during production deployments. Check Admin → System → Integrations and make sure your API integration is set to "Active".
- Flush Caches & Reindex: Stored cache can corrupt API route mappings. Run these commands via SSH on your production server:
bin/magento cache:flush bin/magento indexer:reindex
Quick Cross-Environment Check
Before diving deeper, validate your token is actually valid (even if you got it successfully). Use this endpoint:
curl -H "Authorization: Bearer YOUR_TOKEN" https://your-magento-url/rest/V1/token/validate
If it returns true, your token is good—so the issue is definitely with permissions, URL structure, or server config, not the token itself.
内容的提问来源于stack exchange,提问作者Divyarajsinh
相关产品推荐
相关产品推荐

