You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google OAuth2客户端密钥JSON文件无效问题排查求助

OAuth 2.0配置报错:Invalid client secret JSON file

问题详情

我创建了OAuth 2.0 Client IDs,下载的JSON配置如下:

{
  "web": {
    "client_id": "topsecretstuff.apps.googleusercontent.com",
    "project_id": "health-42",
    "auth_uri": "https://accounts.google.com/o/oauth2/auth",
    "token_uri": "https://oauth2.googleapis.com/token",
    "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
    "client_secret": "GOCSPX-topsecretstuff",
    "redirect_uris": [
      "https://topsecret.domain.tld/oauth2callback.php",
      "https://topsecret.domain.tld/googlelogin.php"
    ]
  }
}

使用以下PHP代码配置OAuth认证:

$client = new Google\Client();

$authfile = 'somepath/client_secret.json';
$client->setAuthConfig($authfile);
$client->setRedirectUri('https://topsecret.domain.tld/oauth2callback.php');
$client->setAccessType('offline');        // offline access
$client->setIncludeGrantedScopes(true);   // incremental auth
$client->addScope(Google\Service\Fitness::FITNESS_ACTIVITY_READ);
$auth_url = $client->createAuthUrl();
header('Location: ' . filter_var($auth_url, FILTER_SANITIZE_URL));
if (isset($_SESSION['access_token']) && $_SESSION['access_token'])
{
    $client->setAccessToken($_SESSION['access_token']);
    echo "已登录,访问令牌:" . $_SESSION['access_token'];
}
else
{
    $redirect_uri = 'https://topsecret.domain.tld/oauth2callback.php';
    header('Location: ' . filter_var($redirect_uri, FILTER_SANITIZE_URL));
}

运行时触发错误:

Fatal error:  Uncaught Google_Exception: Invalid client secret JSON file. in somepath/lib/vendor/google/apiclient/src/Google/Client.php:171
Stack trace:
#0 somepath/client.php(10): Google_Client->setAuthConfig('/somepath...')
#1 somepath/googlelogin.php(32): include_once('/somepath...')
#2 {main}
  thrown in somepath/lib/vendor/google/apiclient/src/Google/Client.php on line 171

我查过相关问题,有人建议下载其他类型的JSON文件,但在Google OAuth2配置界面只能看到下载JSON的选项,配置界面显示的是Web类型客户端凭证,下载按钮仅提供JSON格式选项。

排查与解决方案

  • 检查文件路径正确性
    确保$authfile的路径无误:

    • 相对路径要以当前执行的PHP脚本(如googlelogin.php)为基准,而非被引入的client.php;
    • 优先使用绝对路径,比如$authfile = __DIR__ . '/client_secret.json';,避免路径解析偏差。
  • 验证JSON文件完整性
    重新下载JSON凭证文件,确保下载过程未中断,文件内容与你提供的一致;也可通过JSON校验工具确认文件格式无语法错误。

  • 调整文件权限
    确保Web服务器进程(如www-data、apache)拥有读取该JSON文件的权限,可执行chmod 644 somepath/client_secret.json调整权限。

  • 手动配置凭证替代文件读取
    如果文件读取始终报错,可跳过setAuthConfig,直接手动设置客户端信息:

    $client->setClientId('topsecretstuff.apps.googleusercontent.com');
    $client->setClientSecret('GOCSPX-topsecretstuff');
    $client->setAuthUri('https://accounts.google.com/o/oauth2/auth');
    $client->setTokenUri('https://oauth2.googleapis.com/token');
    
  • 更新Google API客户端版本
    确保使用的google/apiclient是最新版本,执行composer update google/apiclient更新,旧版本可能存在Web类型凭证的兼容问题。

内容的提问来源于stack exchange,提问作者Bas van den Dikkenberg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 09:55:38