You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flutter Google SignIn生成的TokenId无法在Okto API中使用

问题

在我的Flutter应用中,我尝试通过Google登录获取用户凭证(TokenId),用于Okto钱包的API认证。应用虽能生成TokenId,但无法在该API中生效;而通过OAuth2.0 playground生成的TokenId却能正常调用API并返回预期响应。我已添加所有SHA证书但问题仍存在,是否需要在Google Cloud中验证应用?

附上登录方法代码片段:

Future<void> _handleGoogleSignIn() async {
    if (_nameController.text.isEmpty || _numberController.text.isEmpty) {
      _showSnackBar('Please enter your name and number.');
      return;
    }

    setState(() {
      _isLoading = true;
    });

    try {
      final User? currentUser = _auth.currentUser;

      if (currentUser != null) {
        // User is already signed in, navigate to RewardSplash directly
        _navigateToRewardSplash();
        return;
      }

      final GoogleSignIn googleSignIn = GoogleSignIn(scopes: ['email']);
      final GoogleSignInAccount? googleSignInAccount =
          await googleSignIn.signIn();

      if (googleSignInAccount != null) {
        final GoogleSignInAuthentication googleAuth =
            await googleSignInAccount.authentication;
        final AuthCredential credential = GoogleAuthProvider.credential(
          accessToken: googleAuth.accessToken,
          idToken: googleAuth.idToken,
        );
        final UserCredential userCredential =
            await _auth.signInWithCredential(credential);

        final String? idToken = await userCredential.user!.getIdToken();

        if (idToken != null) {
          //pass the generated idtoken to API
          await ApiHandler.authenticateWithToken(idToken);

          // Store the text from the controllers in local variables
          final String name = _nameController.text;
          final String number = _numberController.text;

          // Write data to Firestore
          await FirebaseFirestore.instance.collection('Contacts').add({
            'name': name,
            'number': number,
          });

          _navigateToRewardSplash();
        } else {
          print("ID Token is null");
        }
      }
    } catch (error) {
      print("Something went wrong. Please try again");
      print(error);
      _showSnackBar('Something went wrong. Please try again');
    } finally {
      setState(() {
        _isLoading = false;
      });
    }
  }
可能的原因与解决方案
  • Google Cloud应用验证是核心问题
    是的,你需要在Google Cloud中完成应用验证。未验证的应用生成的ID Token会被标记为"未验证",很多第三方API(包括Okto钱包)会拒绝这类Token;而OAuth2.0 playground是Google官方验证过的服务,生成的Token能被正常识别。

  • 检查ID Token的受众(Audience)是否匹配
    你当前通过userCredential.user!.getIdToken()获取的是Firebase自定义ID Token,其aud(受众)字段是你的Firebase项目ID,而非Okto钱包API要求的OAuth客户端ID。可以用本地JWT解码工具查看Token的aud字段,确保和Okto要求的一致。

  • 补充必要的OAuth Scopes
    代码中仅请求了email scope,OpenID Connect标准要求必须包含openid scope才能生成有效的ID Token。修改GoogleSignIn的scopes配置:

    final GoogleSignIn googleSignIn = GoogleSignIn(scopes: ['email', 'openid']);
    
  • 使用Google登录直接返回的ID Token
    不要使用Firebase生成的Token,直接用GoogleSignIn返回的googleAuth.idToken传递给Okto API,这个Token是标准的OpenID Connect ID Token,符合第三方API的验证要求。修改代码中的Token获取逻辑:

    // 替换原来的getIdToken调用
    final String? idToken = googleAuth.idToken;
    
    if (idToken != null) {
      await ApiHandler.authenticateWithToken(idToken);
      // 后续存储数据、跳转逻辑不变
    }
    

内容的提问来源于stack exchange,提问作者Ronak Raj Rauniyar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 01:15:35