You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Google服务账号调用Drive API时出现Invalid JWT错误求助

解决Google服务账号Invalid JWT令牌错误(invalid_grant)

错误核心原因

这个invalid_grant错误本质是JWT令牌的时间验证未通过——要么服务器本地时间与Google服务器时间偏差过大,要么令牌有效期不符合要求,或是服务账号配置存在疏漏。

具体解决步骤

  • 强制同步服务器时间
    Google对令牌时间精度要求极高,服务器时间与标准时间偏差超过5分钟就会触发该错误:

    • Linux系统:执行timedatectl status查看时间状态,若未同步,运行timedatectl set-ntp on开启自动时间同步;
    • Windows系统:打开「日期和时间设置」,勾选「自动设置时间」和「自动设置时区」。
  • 核对服务账号配置

    1. 确认serviceAccount.json中的private_key和client_email完整无误,private_key必须保留原始换行格式(不能被压缩或转义);
    2. 若需访问Google Workspace域内用户的Drive(而非服务账号自身存储空间),必须在Workspace管理员后台为该服务账号开启域范围委派,并授权https://www.googleapis.com/auth/drive权限。
  • 显式获取客户端令牌(修复自动授权逻辑)
    部分场景下自动授权的令牌生成逻辑可能异常,手动显式获取客户端令牌可解决问题,修改后的代码示例:

const serviceAccountKey = require('../../../serviceAccount.json');
const { google } = require('googleapis');

async function initDriveService() {
  const auth = new google.auth.GoogleAuth({
    credentials: serviceAccountKey,
    scopes: ['https://www.googleapis.com/auth/drive'],
  });
  // 显式获取授权客户端
  const authClient = await auth.getClient();
  return google.drive({
    version: 'v3',
    auth: authClient,
  });
}

// 调用示例
async function listDriveFolders() {
  try {
    const driveService = await initDriveService();
    const response = await driveService.files.list({
      q: 'mimeType = "application/vnd.google-apps.folder"'
    });
    return response.data;
  } catch (error) {
    console.error('操作失败:', error);
  }
}

listDriveFolders();
  • 验证JWT令牌有效期
    Google要求服务账号的JWT令牌有效期必须在1小时以内(exp - iat ≤ 3600秒)。使用官方库时该逻辑由库自动处理,但服务器时间异常仍会触发错误,需确保时间同步正常。

内容的提问来源于stack exchange,提问作者John Albuquerque

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 22:42:53