You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android设备Apple ID登录Firebase时ID Token受众不匹配问题排查

问题解决思路

1. Android设备上的Apple ID登录是否属于Web方式?

是。Android系统无原生Apple登录SDK支持,sign_in_with_apple包在Android端会通过**Web Authentication Flow(网页视图)**完成登录,本质属于Web端OAuth流程。

2. 是否需要使用FirebaseAuth.instance.signInWithPopup()?

不需要。sign_in_with_apple包已封装Android端网页登录流程,无需替换API,当前问题核心是配置错误而非API使用不当。

3. 「ID Token受众不匹配」错误的解决方案

你代码的核心问题是WebAuthenticationOptions中的clientId配置错误:

  • 你填写的FIREBASE_BUNDLE_ID不符合要求,Android网页流必须使用Apple开发者后台创建的「Service ID」作为clientId,而非应用bundle id或Firebase包名。
  • Apple返回的ID Token受众(aud字段)为配置的Service ID,Firebase验证时会对比自身OAuth客户端信息,两者不匹配就会抛出该错误。

修改后的代码示例

static Future<UserCredential> signInWithApple() async {
    final appleCredential = await SignInWithApple.getAppleIDCredential(
      scopes: [
        AppleIDAuthorizationScopes.email,
        AppleIDAuthorizationScopes.fullName,
      ],
      webAuthenticationOptions: WebAuthenticationOptions(
          // 替换为你在Apple开发者后台创建的Service ID
          clientId: "你的Apple Service ID", 
          redirectUri: Uri.parse(
              'https://MI_PROJECT_ID.cloudfunctions.net/handleAppleSignIn')),
    );

    final oauthCredential = OAuthProvider('apple.com').credential(
      idToken: appleCredential.identityToken,
      accessToken: appleCredential.authorizationCode,
    );

    final UserCredential appleUser =
        await FirebaseAuth.instance.signInWithCredential(oauthCredential);

    return appleUser;
  }

额外验证点

  • 确认Apple开发者后台的Service ID已配置正确的重定向URI(即代码中的redirectUri),且已启用「Sign In with Apple」功能。
  • 确认Firebase控制台中Apple登录提供商的配置,已正确填入对应Service ID和密钥,且重定向URI与Apple后台一致。

内容的提问来源于stack exchange,提问作者guerrero

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 10:12:41