使用Fastlane上传TestFlight时遭遇认证凭证无效问题
排查Fastlane上传TestFlight的认证失败问题
错误信息
执行Fastlane的pilot(或upload_to_testflight)动作时,持续出现认证错误:
[08:17:35]: Called from Fastfile at line 30 [08:17:35]: ``` [08:17:35]: 28: [08:17:35]: 29: # Upload the build to TestFlight [08:17:35]: => 30: pilot( api_key_path: "fastlane/api.json" ) [08:17:35]: 31: end [08:17:35]: 32: end [08:17:35]: ``` [08:17:35]: Authentication credentials are missing or invalid. - Provide a properly configured and signed bearer token, and make sure that it has not expired. Learn more about Generating Tokens for API Requests
相关配置
api.json格式(已确认密钥内容无误)
{ "key_id": "my_key_id", "issuer_id": "my_issuer_id", "key": "-----BEGIN PRIVATE KEY-----\nMIGTAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBHknlhdlYdLu\nAgEGCCqGSM49AwEHBHknlhdlYdLu\nAgEGCCqGSM49AwEHBHknlhdlYdLu\n-----END PRIVATE KEY-----", "duration": 1200, "in_house": false }
Fastfile中引用方式
pilot( api_key_path: "fastlane/api.json" ) # 或实际使用的: upload_to_testflight( api_key_path: "fastlane/api.json" )
完整Fastfile配置
default_platform(:ios) platform :ios do desc "Push a new beta build to TestFlight" lane :beta do # Increment build number automatically increment_build_number( xcodeproj: "someapp.xcodeproj" ) # Build the app using your specific workspace and scheme build_app( workspace: "someapp.xcworkspace", scheme: "someappQA", export_method: "app-store", export_options: { provisioningProfiles: { "com.someapp.app.qa" => "com.someapp.app.qa" } } ) # Upload the build to TestFlight upload_to_testflight( api_key_path: "fastlane/api.json" ) end end
GitHub Workflow配置
name: iOS Build and Upload to TestFlight on: workflow_dispatch: jobs: build-ios: runs-on: macos-latest steps: - name: Checkout code uses: actions/checkout@v4 - name: Set up Ruby uses: ruby/setup-ruby@v1 with: ruby-version: '3.3' # Install Bundler and CocoaPods - name: Install Bundler and CocoaPods run: | gem install bundler sudo gem install cocoapods - name: Install Node.js dependencies run: npm install - name: Navigate to iOS directory, clean Pods, and remove Podfile.lock run: | cd ios pod deintegrate rm -rf Podfile.lock npx pod-install - name: Install Fastlane dependencies run: | cd ios bundle install - name: Decode and set up iOS certificate run: | echo "${{ secrets.IOS_DISTRIBUTION_CREDENTIALS }}" | base64 --decode > ios_distribution.p12 echo "${{ secrets.PROVISIONING_PROFILE }}" | base64 --decode > provisioning.mobileprovision shell: bash - name: Import certificate to keychain run: | security create-keychain -p "" build.keychain security import ios_distribution.p12 -k build.keychain -P "${{ secrets.P12_PASSWORD }}" -T /usr/bin/codesign security set-keychain-settings build.keychain security unlock-keychain -p "" build.keychain security set-key-partition-list -S apple-tool:,apple: -s -k "" build.keychain security list-keychains -d user -s build.keychain $(security list-keychains -d user | tr -d '"') security list-keychains -s build.keychain shell: bash - name: Set provisioning profile run: | mkdir -p ~/Library/MobileDevice/Provisioning\ Profiles cp provisioning.mobileprovision ~/Library/MobileDevice/Provisioning\ Profiles/ shell: bash - name: Build and upload to TestFlight run: | cd ios bundle exec fastlane beta
排查方向与解决办法
- 检查api.json路径正确性:确认
fastlane/api.json存在于iOS目录下(Workflow中执行cd ios后运行fastlane),如果文件在项目根目录的fastlane文件夹,需调整路径为../fastlane/api.json。 - 验证私钥格式:将私钥保存为单独的
.p8文件,在api.json中用key_path替代key字段,避免JSON转义错误;确保.p8文件无多余空行,首尾标识完整。 - 确认API密钥权限:登录Apple开发者后台,检查该API密钥已启用
App Store Connect API权限,权限等级至少为Developer;确认密钥未被吊销,issuer_id和key_id完全匹配。 - 延长token有效期:将
duration从1200秒调整为最大值3600秒,避免构建过程中token过期。 - 更新Fastlane版本:执行
bundle update fastlane升级到最新稳定版,修复旧版本可能存在的认证bug。 - Workflow中显式生成api.json:将api.json内容存入GitHub Secrets,在Workflow中生成文件,避免路径问题:
- name: Create api.json run: | echo '${{ secrets.APP_STORE_API_JSON }}' > ios/fastlane/api.json shell: bash
内容的提问来源于stack exchange,提问作者root69
相关产品推荐
相关产品推荐

