Google令牌过期/撤销问题求助:指定Client_id与Client_Secret后Refresh Token仍约1小时失效
invalid_grant with Short-Lived Refresh Tokens Hey there, sorry to hear you're stuck with this frustrating invalid_grant error and refresh tokens expiring after just an hour—let's break down where you can find logs to diagnose the root cause, plus a few extra checks to rule out common issues.
Log Sources to Dig Into
1. Google Cloud Console Logs
Head over to the Logging section in your Google Cloud Console and filter for these specific log types:
- OAuth2 Token Endpoint Logs: Search for
protoPayload.methodName:"google.identity.oauth2.v2.TokenEndpoint"—this log tracks every refresh token request, including detailed error codes and explanations (liketoken_revokedor permissions-related issues) that might tell you why the token is getting invalidated. - API Audit Logs: Make sure audit logs are enabled for Admin SDK and Group Settings API. These logs will show you what happens when your token is used to call APIs—if there's a permission mismatch or a revocation event, it'll be logged here.
- Credential Audit Logs: Check the Credentials logs under
IAM > Audit Logs. This tracks usage of your OAuth client credentials, so if there's any unusual activity (like a credential reset) that's causing tokens to get revoked, you'll see it here.
2. OAuth Playground's Detailed Request/Response
In the OAuth Playground, go to Step 2 where you exchange the authorization code for tokens. Click "Show headers/body" to see the full response from Google's token endpoint. Sometimes, even if you get a refresh token initially, there might be warnings in the response that hint at why it's short-lived.
3. Token Debugging with Google's Token Info Endpoint
You can directly check the status of your refresh token using Google's token info endpoint. Send a GET request like this:
GET https://oauth2.googleapis.com/tokeninfo?refresh_token=YOUR_REFRESH_TOKEN
If the token is valid, you'll get details like its expiration time, linked client ID, and authorized scopes. If it's already expired or revoked, you'll get the invalid_grant error with a more specific reason (e.g., "Token has been revoked").
Quick Checks to Rule Out Simple Fixes
Before diving deep into logs, double-check these common pitfalls:
- Consent Screen Compatibility: Since you set the consent screen to "internal", make sure the account you're using to generate tokens is part of the same Google Workspace domain. External accounts can't use internal consent screens, which might restrict token validity.
- Offline Access Confirmation: Double-check that you really set
Access Type=Offlinein the OAuth Playground. If this parameter is missing, Google will only issue short-lived refresh tokens (around 1 hour) instead of permanent ones. This is super easy to miss! - Client Credentials Match: Ensure the Client ID and Secret you entered in OAuth Playground are exactly the same as the ones in your Google API Console's Web app credential—even a single extra space can break things.
- Revocation Triggers: Check if any of these actions happened:
- Did the user revoke app access in their Google account's "Security > Third-party apps with account access"?
- Did a Workspace admin reset the user's password or revoke the app's domain-wide permissions?
- Was the OAuth client credential regenerated or deleted recently?
内容的提问来源于stack exchange,提问作者KhalilG

