Flutter Web集成Firebase Phone Auth时reCAPTCHA Enterprise验证失败并回退v2仍报invalid-app-credential错误
Let's break down why you're hitting the invalid-app-credential error even when the reCAPTCHA Enterprise token generates successfully, and how to fix it:
1. Mismatched reCAPTCHA Key Type or Configuration
First, double-check that you're using a reCAPTCHA Enterprise key (not a standard v2/v3 key) and that it's properly linked to your Firebase project.
- Go to the Google Cloud Console (linked to your Firebase project), navigate to reCAPTCHA Enterprise > Keys, and confirm your key is marked as "Enterprise" (not v2/v3).
- Ensure this key is exactly the one you've added in your
index.html(render=MY_KEY) and Firebase Console's phone auth settings.
2. Incorrect RecaptchaVerifier Initialization
Even with reCAPTCHA Enterprise enabled, Flutter Web's firebase_auth requires explicit configuration of the RecaptchaVerifier to use Enterprise mode. If you skip this, it defaults to v2, causing a mismatch between the Enterprise token and the v2 validator.
Update your Dart code to explicitly initialize the verifier with Enterprise parameters:
final verifier = RecaptchaVerifier( container: null, // Leave as null for auto-rendered widget parameters: { 'sitekey': 'YOUR_ENTERPRISE_KEY', 'enterprise': 'true', // Critical flag to enable Enterprise mode }, ); final confirmationResult = await FirebaseAuth.instance.signInWithPhoneNumber( phoneNumber, verifier, );
3. Version Mismatch Between Flutter firebase_auth and Web JS SDKs
Your firebase_auth version (^6.1.3) must be compatible with the Firebase JS SDK versions you've manually added to index.html (10.12.0). Mismatches can cause silent failures in credential validation.
Instead of manually adding JS scripts, use the flutterfire_cli to auto-generate a compatible index.html:
- Run
flutterfire configurein your project root - This will overwrite your
index.htmlwith the correct JS SDK versions matched to your Flutter Firebase dependencies.
4. Missing API Enablement in Google Cloud Console
Even if you enabled reCAPTCHA Enterprise in Firebase Console, you need to ensure the reCAPTCHA Enterprise API is enabled in the Google Cloud Console:
- Go to Cloud Console > APIs & Services > Library
- Search for "reCAPTCHA Enterprise API" and confirm it's marked as "Enabled".
5. Domain Configuration Issues
Double-check domain permissions for both your reCAPTCHA Enterprise key and Firebase project:
- In reCAPTCHA Enterprise key settings: Add all test domains (including port numbers if you use them, e.g.,
localhost:5000) to the "Allowed domains" list. - In Firebase Console > Authentication > Settings > Authorized domains: Ensure the same domains are listed here too.
- Wait 5-10 minutes for domain changes to propagate (cloud configurations can take time to sync).
6. Test with Enforce Mode (Temporarily)
While your current setting is AUDIT (monitor-only), switching to ENFORCE mode temporarily in Firebase Console's phone auth settings can help surface configuration issues that might be hidden in audit mode. Remember to switch back if you don't want strict enforcement long-term.
内容的提问来源于stack exchange,提问作者Ruth Hari

