You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Google PHP API库获取用户详情时遭遇403错误求助

Google_Client验证ID Token时出现403禁止访问/oauth2/v3/certs错误

我通过new Google_Client(['client_id' => $CLIENT_ID])创建Google_Client对象,尝试获取用户详情时出错。原本想获取指定Gmail账号的$googleUserid、$email、$picture等用户信息,结果收到无法获取验证证书的错误,访问/oauth2/v3/certs时遭403禁止。

使用的代码:

require '/home/nowvibac/vendor/autoload.php';

try{

$CLIENT_ID =  '204553466403-o75aj25ktmmjkk1g5a3set3losqvfeqe.apps.googleusercontent.com';

$client = new Google_Client(['client_id' => $CLIENT_ID]);  // Specify the CLIENT_ID of the app that accesses the backend

$payload = $client->verifyIdToken($id_token);

if ($payload) {
/*Own-- this id is the same as the one in js but its more authentic to avoid user manipulation */    
//verified variables from Google's API
  $googleUserid = $payload['sub'];
$email = $payload['email'];
$picture = $payload['picture'];
$name = $payload['name'];
}

}catch(Exception $e){
  echo $e;
}

错误信息:

Failed to retrieve verification certificates: "<!DOCTYPE html>
<html lang=en>
  <meta charset=utf-8>
  <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width">
  <title>Error 403 (Forbidden)!!1</title>
  <style>
    *{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}* > body{background:url(//www.google.com/images/errors/robot.png) 100% 5px no-repeat;padding-right:205px}p{margin:11px 0 22px;overflow:hidden}ins{color:#777;text-decoration:none}a img{border:0}@media screen and (max-width:772px){body{background:none;margin-top:0;max-width:none;padding-right:0}}#logo{background:url(//www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png) no-repeat;margin-left:-5px}@media only screen and (min-resolution:192dpi){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) 0}}@media only screen and (-webkit-min-device-pixel-ratio:2){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat;-webkit-background-size:100% 100%}}#logo{display:inline-block;height:54px;width:150px}
  </style>
  <a href=//www.google.com/><span id=logo aria-label=Google></span></a>
  <p><b>403.</b> <ins>That’s an error.</ins>
  <p>Your client does not have permission to get URL <code>/oauth2/v3/certs</code> from this server.  <ins>That’s all we know.</ins>

解决方法:

  • 排查服务器网络:403大概率是服务器无法正常访问Google认证端点,可能是IP被限制、防火墙拦截或代理配置问题。直接在服务器上执行curl https://www.googleapis.com/oauth2/v3/certs,看能否返回正常的证书内容。
  • 更新Google Client库:旧版本库可能存在端点URL配置错误,运行composer update google/apiclient升级到最新版,新版本会使用正确的证书获取地址。
  • 完善Client初始化配置:别只传client_id,建议完整配置客户端参数,比如:
$client = new Google_Client();
$client->setClientId($CLIENT_ID);
$client->setAccessType('offline');
  • 验证ID Token有效性:确保前端传过来的$id_token是合法有效的,没有过期或被篡改,可手动检查Token格式是否符合JWT标准。

内容的提问来源于stack exchange,提问作者Muhwezi Deus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 14:27:11