# rpc 错误：code = PermissionDenied desc = 缺少或无效的授权元数据

- **ID:** `go/grpc-permission-denied-metadata`
- **领域:** go
- **类别:** auth_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

服务器端认证拦截器拒绝了请求，因为授权元数据（bearer token、API key）缺失或验证失败。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| google.golang.org/grpc v1.55+ | active | — | — |

## 解决方案

1. **** (95% 成功率)
   ```
   md := metadata.Pairs("authorization", "Bearer "+token)
ctx = metadata.NewOutgoingContext(ctx, md)
resp, err := client.Get(ctx, req)
   ```
2. **** (93% 成功率)
   ```
   func authUnary(token string) grpc.UnaryClientInterceptor {
    return func(ctx context.Context, method string, req, reply any, cc *grpc.ClientConn, inv grpc.UnaryInvoker, opts ...grpc.CallOption) error {
        ctx = metadata.AppendToOutgoingContext(ctx, "authorization", "Bearer "+token)
        return inv(ctx, method, req, reply, cc, opts...)
    }
}
conn, _ := grpc.NewClient(addr, grpc.WithUnaryInterceptor(authUnary(token)))
   ```

## 无效尝试

- **** — gRPC method names are fixed; query strings are not transmitted. Token never reaches the server. (98% 失败率)
- **** — Leaks the token into logs and business payloads; bypasses standard interceptor checks. (85% 失败率)
