You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Service Account认证Google API时遭遇invalid_scope错误求助

问题原因及解决方案

错误根源

你的代码在生成JWT时存在关键问题:将jwtClaim对象嵌套在另一个对象中传给jwt.sign方法。Google OAuth 2.0服务账户认证要求JWT payload里的scope必须是顶层属性,但当前代码生成的JWT中,scope被包裹在jwtClaim子对象内,导致认证服务器无法识别请求的权限范围,进而返回invalid_scope错误。

修复步骤

1. 修正JWT生成逻辑

修改jwt.sign的调用参数,直接传入jwtClaim作为payload,而非嵌套对象:

// 原错误代码
const token = jwt.sign({ jwtClaim }, keys.private_key, { algorithm: 'RS256' });

// 修改后的正确代码
const token = jwt.sign(jwtClaim, keys.private_key, { algorithm: 'RS256' });

2. 修正时间戳格式

exp和iat字段需要使用Unix时间戳(秒),而Date.now()返回的是毫秒,需转换为秒:

var jwtClaim = {
    "iss":   "cv-thing-sacc@cv-thing.iam.gserviceaccount.com",
    "scope": "https://www.googleapis.com/auth/spreadsheets.readonly",
    "aud":   "https://oauth2.googleapis.com/token",
    "exp":    Math.floor(Date.now() / 1000) + 3600, // 有效期1小时
    "iat":    Math.floor(Date.now() / 1000)
};

若使用毫秒时间戳,会导致JWT时间无效,可能引发额外认证错误。

额外说明

  • 你使用的https://www.googleapis.com/auth/spreadsheets.readonly是合法的只读权限范围,无需添加其他范围。
  • 目标文档公开状态不影响服务账户认证流程,只要权限范围正确、JWT格式合规即可正常获取令牌。

内容的提问来源于stack exchange,提问作者Corvus Corax

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 14:05:14