如何排查Vertex AI HTTP连接12小时后认证失败问题
Google Vertex AI 12小时后出现401认证及invalid_grant错误排查
初始通过HTTP请求连接Google Vertex AI正常,但运行12小时以上后出现401认证错误,错误信息如下:
{ "error": { "code": 401, "message": "Request is missing required authentication credential. Expected OAuth 2 access token, login cookie or other valid authentication credential. See https://developers.google.com/identity/sign-in/web/devconsole-project.", "status": "UNAUTHENTICATED", "details": [{ "@type": "type.googleapis.com/google.rpc.ErrorInfo", "reason": "CREDENTIALS_MISSING", "domain": "googleapis.com", "metadata": { "method": "google.cloud.aiplatform.v1.PredictionService.GenerateContent", "service": "aiplatform.googleapis.com" } }] } }
同时刷新token时出现invalid_grant错误:
{ "error": "invalid_grant", "error_description": "reauth related error (invalid_rapt)", "error_uri": "https://support.google.com/a/answer/9368756", "error_subtype": "invalid_rapt" }
操作流程
- 在控制台创建WEB APPLICATION类型凭证(名称CRIAS),授权重定向URI为
https://console.developers.google.com和https://developers.google.com/oauthplayground - 进入OAuth Playground,勾选Vertex AI API相关权限(含
https://www.googleapis.com/auth/cloud-platform等) - 配置OAuth 2.0为Server-side流程,使用自有凭证,获取Refresh Token和Access Token
- 在请求平台中,先通过refresh_token获取access_token,再携带该token向Vertex AI的
streamGenerateContent接口发起请求
问题排查与解决方法
1. 失效核心原因
- OAuth Playground生成的刷新令牌默认有效期仅7天,且关联的Google账号若开启二次验证或触发安全策略变更,会直接触发
invalid_rapt错误,强制要求重新认证。 - Server-side流程下,通过OAuth Playground获取的令牌并非为生产环境长期运行设计,无法保证持续可用性。
2. 生产环境最优方案:改用服务账号认证
- 在Google Cloud控制台创建服务账号,下载JSON格式密钥文件。
- 基于服务账号密钥自动生成access_token,令牌最长有效期1小时,到期可无缝重新生成,适配长期运行的服务场景。
- 为服务账号分配对应IAM权限,如
Vertex AI User或Cloud AI Platform Developer,确保具备调用streamGenerateContent接口的权限。
3. 临时测试方案
- 若仅用于短期测试,可重新在OAuth Playground完成授权流程,获取新的refresh_token,但此方法无法解决长期运行问题,账号安全策略变更后仍会失效。
内容的提问来源于stack exchange,提问作者dérick Fernandes
相关产品推荐
相关产品推荐

