You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置LinkedIn为Google Cloud Identity Platform OIDC提供商时Issuer不匹配问题

问题:Google Cloud Identity Platform配置LinkedIn身份提供商的Issuer矛盾

我在使用Google Cloud Identity Platform配置LinkedIn作为身份提供商时遇到了Issuer相关的问题:

  1. 已完成LinkedIn应用注册,拿到Client ID、Secret,也配置了正确的Redirect URI
  2. 按OIDC配置要求,Issuer URL后需追加/.well-known/openid-configuration获取发现文档,但访问https://www.linkedin.com/.well-known/openid-configuration返回404
  3. 实际有效的发现文档地址是https://www.linkedin.com/oauth/.well-known/openid-configuration,其返回的配置中issuer字段值为https://www.linkedin.com
  4. 若将Issuer设为https://www.linkedin.com会报错(与发现配置中的Issuer不匹配),但设为https://www.linkedin.com/oauth却能正常工作

请问这是我遗漏了配置,还是LinkedIn不符合OIDC规范?


解答

  • LinkedIn的OIDC实现不符合标准规范
    OIDC核心规范明确要求:Issuer对应的URL必须可以通过追加/.well-known/openid-configuration路径访问到OIDC发现文档。但LinkedIn的发现文档并未放在根路径下,而是放在了/oauth/子路径中,同时发现文档里声明的issuer却是根域名https://www.linkedin.com,这完全违反了OIDC规范中关于发现端点位置的要求。

  • 为什么设置https://www.linkedin.com/oauth能正常工作
    当你将Issuer设为https://www.linkedin.com/oauth时,Google Cloud Identity Platform会自动向该URL追加/.well-known/openid-configuration,正好匹配LinkedIn实际的发现文档地址。尽管这个Issuer值和发现文档中声明的issuer字段不一致,但GCP在该场景下并未严格校验两者的一致性,而是优先使用发现文档返回的配置完成身份验证流程。

  • 当前可行的解决方案
    继续使用https://www.linkedin.com/oauth作为Issuer配置值即可,这是目前让GCP Identity Platform与LinkedIn OIDC集成正常运行的唯一可行方案。目前LinkedIn官方尚未修正这一规范不一致的问题,无需额外配置。

内容的提问来源于stack exchange,提问作者kevex91

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 18:05:25