LinkedIn API调用/me接口提示权限不足问题求助
Let’s break down why you’re hitting this 403 error and how to fix it—this is a common gotcha when working with LinkedIn’s v2 APIs.
The Core Issue: Mismatched Permissions for v2 API
Your current permissions (r_basicprofile, r_fullprofile) are legacy v1 API scopes, and they don’t work with LinkedIn’s v2 /me endpoint. For v2, you need v2-specific scopes:
r_liteprofile: Required to access basic profile data (name, profile photo, headline, etc.) via/mer_memberprofile: For more detailed profile data (work experience, education, etc.)—note this scope may require additional approval from LinkedIn- Keep
r_emailaddressif you need access to the user’s email, andw_shareif you need post permissions
Step-by-Step Fix
Update Your Authorization Scope
When initiating the OAuth2 flow, replace your old scopes with v2-compatible ones. For basic profile access, use:r_liteprofile r_emailaddress w_shareRe-Generate Your Access Token
Old access tokens retain the original permissions, so you’ll need to go through the full OAuth2 authorization flow again to get a new token with the updated scopes.Add the Required Request Header
LinkedIn’s v2 APIs require theX-Restli-Protocol-Versionheader to handle requests correctly. Many developers miss this, which can trigger misleading permission errors. Here’s your corrected curl command:curl -H "Authorization: Bearer YOUR_NEW_ACCESS_TOKEN" \ -H "Accept: application/json" \ -H "Content-Type: application/json" \ -H "X-Restli-Protocol-Version: 2.0.0" \ https://api.linkedin.com/v2/meVerify Your Token’s Scopes
Use LinkedIn’s official token inspection tool to confirm your new access token includes ther_liteprofile(orr_memberprofile) scope. This helps rule out any issues with the authorization flow.
Additional Notes
- If you’re requesting
r_memberprofile, you’ll need to submit access to LinkedIn for review—this scope isn’t available by default for most apps. Stick withr_liteprofileif you only need basic profile data. - Double-check that your app is configured correctly in the LinkedIn Developer Portal, ensuring the redirect URI and scopes match what you’re using in your authorization flow.
内容的提问来源于stack exchange,提问作者Krzysztof Makowski

