You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用oauth2l获取Google Ads刷新令牌时遇凭证及密钥解析错误

问题分析与解决方法

问题根源

你混淆了OAuth客户端凭据和服务账号凭据的用途:

  • 你要获取刷新令牌,属于OAuth 2.0授权码流程,需要用Web/桌面应用的OAuth客户端ID凭据,而非服务账号凭据。
  • 错误添加"type": "service_account"后,oauth2l会将其当作服务账号凭据处理,但你的凭据里缺少服务账号必需的private_key、client_email等字段,因此触发私钥解析错误。

解决步骤

  1. 修正credentials.json的type字段
    把错误添加的"type": "service_account"替换为"type": "client_secret",因为你的凭据是Web应用的OAuth客户端ID:

    {
      "type": "client_secret",
      "web": {
        "client_id": "XXXXXXXXXX.apps.googleusercontent.com",
        "project_id": "XXXXXXXXXX",
        "auth_uri": "https://accounts.google.com/o/oauth2/auth",
        "token_uri": "https://oauth2.googleapis.com/token",
        "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
        "client_secret": "XXXXXXXXXX",
        "javascript_origins": [
          "https://XXXXXXXXXX.co.uk"
        ]
      }
    }
    
  2. 重新执行oauth2l命令
    再次运行原命令:

    oauth2l fetch --credentials credentials.json --scope adwords \
        --output_format refresh_token
    

    执行后会弹出授权页面,完成登录授权后就能获取到刷新令牌。

  3. 可选:改用参数直接传递客户端信息
    如果还是有问题,可以跳过credentials文件,直接用参数传递客户端ID和密钥:

    oauth2l fetch --client_id "XXXXXXXXXX.apps.googleusercontent.com" \
        --client_secret "XXXXXXXXXX" --scope adwords \
        --output_format refresh_token
    

内容的提问来源于stack exchange,提问作者AndyW

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 13:54:53