You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android应用集成FCM通知遇cloudmessaging.messages.create权限拒绝问题

问题描述

我正在给Android应用添加通知功能,使用Postman测试推送。通过控制台程序获取Authorization Bearer Token后在Postman中使用,获取Token的代码如下:

public static async Task<string> getToken()
{
    try
    {
        // 创建明确的ServiceAccountCredential凭证
        var credential = await GoogleCredential.FromFile({pathToJsonFile})                                            
                     .CreateScoped("https://www.googleapis.com/auth/firebase.messaging")
                     .UnderlyingCredential
                     .GetAccessTokenForRequestAsync();

        return credential;
    }
    catch (Exception ex)
    {
        return "";
    }
}

{pathToJsonFile}是我在console.cloud.google.com为创建的服务账号获取的密钥文件,已为该服务账号分配Owner和Service Account Admin角色。

我通过Postman发送请求,URL中的项目名称取自console.firebase.google.com/project/.../,请求体为:

{
  "message": {
    "token": "{tokenIGotFromAndroidDevice}",
    "notification": {
      "title": "body",
      "body": "Title"
    },
    "data": {
      "type": "1",
      "message": "message"
    }
  }
}

但收到如下403响应:

{
  "error": {
    "code": 403,
    "message": "Permission 'cloudmessaging.messages.create' denied on resource '//cloudresourcemanager.googleapis.com/projects/...' (or it may not exist).",
    "status": "PERMISSION_DENIED",
    "details": [
      {
        "@type": "type.googleapis.com/google.rpc.ErrorInfo",
        "reason": "IAM_PERMISSION_DENIED",
        "domain": "cloudresourcemanager.googleapis.com",
        "metadata": {
          "resource": "projects/...",
          "permission": "cloudmessaging.messages.create"
        }
      }
    ]
  }
}
解决步骤
  • 给服务账号添加Firebase Cloud Messaging Admin角色:Owner和Service Account Admin角色未必包含cloudmessaging.messages.create权限,需明确添加该角色。
  • 核对项目ID一致性:确保Postman请求URL中的项目ID与密钥文件里的项目ID完全匹配,避免拼写错误。
  • 等待权限生效:IAM角色变更通常需要几分钟才能生效,添加角色后稍作等待再测试。
  • 验证Token权限范围:确认生成的Token包含https://www.googleapis.com/auth/firebase.messaging权限范围,可通过解码Token查看。
  • 检查请求URL格式:FCM v1接口的正确URL应为https://fcm.googleapis.com/v1/projects/{你的项目ID}/messages:send,确认URL格式无误。

内容的提问来源于stack exchange,提问作者PhpLou

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 17:57:37