如何在同一Firebase项目中配置Web与iOS的Sign in with Apple不同标识?
Firebase Auth适配Web与iOS不同标识实现Sign in with Apple的解决方案
核心思路:利用Apple开发者后台的主App ID关联多标识特性,配合Firebase Auth的多受众验证支持,实现同一Firebase项目下Web(Services ID)和iOS(Bundle ID)的Apple登录共存。
1. 确认Apple开发者后台配置
- 主App ID(
com.example.app)已启用Sign in with Apple权限 - Services ID(
com.example.app.web)关联至该主App ID,且配置了Web端的重定向URL(需与Firebase Auth中设置一致) - iOS Bundle ID(
com.example.app)已启用Sign in with Apple,并归属同一主App ID
2. 修正Firebase Auth的Apple登录配置
- 确保Firebase中使用的Apple密钥是关联主App ID(
com.example.app)生成的,而非仅关联Services ID。该密钥需开启Sign in with Apple权限,且密钥ID、Team ID与Firebase配置完全匹配 - Firebase控制台中,Apple登录的
Services ID保持为com.example.app.web(保证Web端正常工作),无需修改——Firebase会自动验证同一主App ID下所有关联标识的ID Token
3. iOS/Expo端代码调整
Expo返回的ID Token受众为iOS Bundle ID,需正确转换为Firebase可识别的凭证:
import * as AppleAuthentication from 'expo-apple-authentication'; import { getAuth, signInWithCredential, OAuthProvider } from 'firebase/auth'; // 获取Apple登录凭证 const appleCredential = await AppleAuthentication.signInAsync({ requestedScopes: [ AppleAuthentication.AppleAuthenticationScope.FULL_NAME, AppleAuthentication.AppleAuthenticationScope.EMAIL, ], }); // 转换为Firebase OAuth凭证 const auth = getAuth(); const appleProvider = new OAuthProvider('apple.com'); const firebaseCredential = appleProvider.credential({ idToken: appleCredential.identityToken, rawNonce: appleCredential.nonce, // 确保nonce一致,防止重放攻击 }); // 完成登录 await signInWithCredential(auth, firebaseCredential);
4. 验证配置有效性
- Web端:保持原有代码不变,使用Services ID
com.example.app.web即可正常登录 - iOS端:运行上述代码,Firebase会验证ID Token的受众是否属于主App ID下的合法标识,验证通过后完成登录
失败原因复盘
- 修改iOS Bundle ID为
com.example.app.web失败:该标识已被Web端的Services ID占用,Apple开发者后台不允许重复注册 - 修改Firebase Services ID为iOS Bundle ID:Web端Apple登录要求使用Services ID作为client_id,因此请求被Apple拒绝,触发
invalid_request错误
额外检查项
- Expo的
app.json需正确配置iOS权限:{ "expo": { "ios": { "bundleIdentifier": "com.example.app", "usesAppleSignIn": true } } } - 确保Apple开发者后台中,Web端重定向URL已添加到Services ID的允许列表,且与Firebase Auth配置一致
内容的提问来源于stack exchange,提问作者Takaki
相关产品推荐
相关产品推荐

