You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Google Identity REST API遇403错误:VPCSC_CHECK_FAILED权限排查

问题描述

我通过Firebase Admin SDK获取凭证后,调用Google Identity Toolkit的REST API(accounts:query接口)实现Firebase Authentication操作,代码如下:

const projectID = app.options.projectId;

const token = await app.options.credential?.getAccessToken();

if (!token) {
    throw 'No token!';
}

const url = `https://identitytoolkit.googleapis.com/v1/projects/${projectID}/accounts:query?alt=json`;
const options = {
    method: 'POST',
    headers: {
        'Content-Type': 'application/json',
        'Authorization': `Bearer ${token.access_token}`
    },
    body: JSON.stringify({
        "returnUserInfo": false,
        "expression": []
    })
};

return await fetch(url, options).then(response => response.json());

但收到403权限错误:

{
  "error": {
    "code": 403,
    "message": "VPCSC_CHECK_FAILED : Permission denied: Consumer 'project_number:{my-project-number}' has been suspended.",
    "errors": [
      {
        "message": "VPCSC_CHECK_FAILED : Permission denied: Consumer 'project_number:{my-project-number}' has been suspended.",
        "domain": "global",
        "reason": "forbidden"
      }
    ],
    "status": "PERMISSION_DENIED"
  }
}

已确认项目未被暂停、未使用VPCSC限制/边界,且Firebase Admin其他功能正常。想知道这是否是权限问题?该如何解决?是否需要配置特定IAM设置?


解决方案

这确实是权限配置问题,核心和IAM角色绑定、令牌权限范围相关,以下是具体排查和解决步骤:

  1. 检查服务账号的IAM角色

    • Firebase Admin SDK对应的服务账号,必须拥有Firebase Authentication Admin角色(roles/firebaseauth.admin)或Identity Toolkit Admin角色(roles/identitytoolkit.admin)。
    • 进入Google Cloud控制台IAM页面,找到该服务账号,确认是否已绑定上述角色之一;若未绑定,直接添加对应角色即可。
  2. 验证访问令牌的权限范围

    • Firebase Admin SDK默认获取的令牌可能缺少Identity Toolkit API的权限范围。可以用JWT解码工具查看令牌的scope字段,确认是否包含https://www.googleapis.com/auth/identitytoolkit或https://www.googleapis.com/auth/firebase。
    • 若缺少权限范围,初始化Admin SDK时可显式指定:
      const { initializeApp, getAuth, GoogleAuth } = require('firebase-admin/app');
      const serviceAccount = require('./service-account-key.json');
      
      const app = initializeApp({
        credential: GoogleAuth.fromJSON(serviceAccount).createScoped([
          'https://www.googleapis.com/auth/firebase',
          'https://www.googleapis.com/auth/identitytoolkit'
        ])
      });
      
  3. 排查VPCSC误报场景

    • 即便你确认未使用VPCSC,项目所属组织的全局策略可能隐含限制,或API调用路由触发了VPCSC检查:
      • 检查组织级VPC访问控制策略,确认没有针对Identity Toolkit API的限制规则;
      • 若在GCP内部环境运行,确保调用API的网络路由未经过VPCSC边界。
  4. 优先使用Firebase Admin SDK内置方法

    • 既然已在使用Admin SDK,完全可以用其内置的用户操作方法替代REST调用,避免权限配置麻烦。比如查询用户:
      // 示例:批量查询用户列表
      const userRecords = await getAuth(app).listUsers();
      userRecords.users.forEach(user => {
        console.log(`UID: ${user.uid}, 邮箱: ${user.email}`);
      });
      
    • 这种方式无需额外配置权限,SDK会自动处理凭证和权限校验。

内容的提问来源于stack exchange,提问作者Jonathan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 04:17:49