You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Google登录Bearer Token转换为访问令牌调用Sheets API

问题描述
  • 需调用Google Sheets API,但缺少可用于API授权的access_token
  • 已通过Google登录获取到包含用户信息的Bearer Token(ID Token),但无法直接用于API请求
  • 要求在纯Web环境(无需credentials.json文件)下,通过服务端生成有效access_token
核心概念澄清

你拿到的Bearer Token是ID Token,仅用于验证用户身份,不包含调用Sheets/Drive API的权限,必须换取专门的Access Token才能发起API请求。

解决方案:用ID Token换取Access Token

采用Google OAuth2的JWT Bearer断言授权流,将ID Token作为断言发送至Google令牌端点,换取带权限的Access Token。

操作步骤

  1. 确认权限配置:在Google Cloud Console中,你的应用已申请https://www.googleapis.com/auth/spreadsheets、https://www.googleapis.com/auth/drive等所需权限,且用户登录时已完成授权。
  2. 服务端发起令牌交换:敏感逻辑必须在服务端执行,禁止前端直接请求,示例如下:

服务端curl请求示例

curl -d 'grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer&assertion=YOUR_ID_TOKEN&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET' https://oauth2.googleapis.com/token

注:client_id和client_secret需从Google Cloud Console的OAuth 2.0客户端ID页面获取。

服务端Node.js/Express代码示例

const axios = require('axios');

// 新增接口用于换取Access Token
app.post('/get-access-token', async (req, res) => {
  const { idToken } = req.body;
  const clientId = '1097716786981-6gsahdt3b7tgq8ur229h21h1mgud9p7t.apps.googleusercontent.com';
  const clientSecret = 'YOUR_CLIENT_SECRET'; // 替换为你的客户端密钥

  try {
    const tokenRes = await axios.post('https://oauth2.googleapis.com/token', null, {
      params: {
        grant_type: 'urn:ietf:params:oauth:grant-type:jwt-bearer',
        assertion: idToken,
        client_id: clientId,
        client_secret: clientSecret
      }
    });

    res.json({
      access_token: tokenRes.data.access_token,
      expires_in: tokenRes.data.expires_in
    });
  } catch (err) {
    console.error('令牌交换失败:', err.response?.data || err.message);
    res.status(400).json({ error: '无法获取有效Access Token' });
  }
});

前端代码调整

修改登录回调逻辑,将ID Token发送至服务端换取Access Token,再用该令牌调用Sheets API:

function handleCredentialResponse(response) {
  console.log("Encoded JWT ID token: " + response.credential);
  axios.post('http://localhost:3000/get-access-token', {
      idToken: response.credential
    })
    .then(function (tokenRes) {
      console.log("获取到Access Token:", tokenRes.data.access_token);
      // 调用Google Sheets API
      fetchSheetData(tokenRes.data.access_token);
    })
    .catch(function (error) {
      console.error(error);
    });
}

// 调用Sheets API示例
function fetchSheetData(accessToken) {
  axios.get('https://sheets.googleapis.com/v4/spreadsheets/YOUR_SPREADSHEET_ID/values/A1:B2', {
    headers: {
      'Authorization': `Bearer ${accessToken}`
    }
  })
  .then(res => console.log('Sheets数据:', res.data))
  .catch(err => console.error('API调用失败:', err));
}

window.onload = function () {
  google.accounts.id.initialize({
    client_id: "1097716786981-6gsahdt3b7tgq8ur229h21h1mgud9p7t.apps.googleusercontent.com",
    callback: handleCredentialResponse
  });
  google.accounts.id.renderButton(
    document.getElementById("buttonDiv"),
    { theme: "outline", size: "large" }
  );
  google.accounts.id.prompt();
}
关键注意事项
  • 密钥保密:client_secret必须仅在服务端使用,禁止暴露在前端代码中,避免应用密钥泄露。
  • 权限匹配:确保用户授权的权限范围与API调用所需一致,否则换取的Access Token会因权限不足被拒绝。
  • 令牌有效期:Access Token有效期约1小时,过期后需重新换取;若需长期权限,建议改用完整的OAuth2授权码流程获取刷新令牌。

内容的提问来源于stack exchange,提问作者Emmanuel Viglioni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 03:12:27