You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Postman获取Firestore的Bearer Token?

通过Postman获取Firestore的Bearer Token步骤

1. 准备GCP服务账号密钥

  • 登录GCP控制台,进入「IAM与Admin > 服务账号」页面
  • 创建或选择一个已有服务账号,为其添加Firestore相关权限(例如「Cloud Datastore User」,Firestore底层依赖Datastore API权限)
  • 点击「添加密钥 > 创建新密钥」,选择JSON格式,将密钥文件下载到本地

2. 生成JWT断言(Assertion)

JWT是获取Token的核心凭证,由Header、Payload、Signature三部分组成:

  • Header:固定为{"alg":"RS256","typ":"JWT"},用Base64URL编码
  • Payload:需包含以下字段:
    • iss:服务账号密钥文件中的client_email值
    • scope:固定为https://www.googleapis.com/auth/datastore(Firestore API的权限范围)
    • aud:固定为https://oauth2.googleapis.com/token
    • iat:当前Unix时间戳(秒)
    • exp:过期时间戳,建议设为iat + 3600(1小时有效期)
  • Signature:用密钥文件中的private_key,以RS256算法对Base64URL编码后的Header+Payload进行签名

你可以用Postman的「预请求脚本」生成JWT,示例脚本如下(需先在Postman中引入jsrsasign库,可通过Postman的「设置 > 脚本」添加):

// 从服务账号密钥文件中提取信息
const clientEmail = "你的服务账号邮箱";
const privateKey = "你的服务账号私钥(注意保留换行符)";

const header = { alg: "RS256", typ: "JWT" };
const payload = {
  iss: clientEmail,
  scope: "https://www.googleapis.com/auth/datastore",
  aud: "https://oauth2.googleapis.com/token",
  iat: Math.floor(Date.now() / 1000),
  exp: Math.floor(Date.now() / 1000) + 3600
};

// 生成JWT
const jwt = KJUR.jws.JWS.sign("RS256", JSON.stringify(header), JSON.stringify(payload), privateKey);

// 将JWT存入环境变量,方便后续请求使用
pm.environment.set("jwt_assertion", jwt);

3. 发送Postman请求获取Token

  • 新建POST请求,URL填写https://oauth2.googleapis.com/token
  • 切换到「Body」标签,选择「x-www-form-urlencoded」格式
  • 添加以下两个参数:
    • grant_type:值为urn:ietf:params:oauth:grant-type:jwt-bearer
    • assertion:值为刚才生成的JWT(或直接引用环境变量{{jwt_assertion}})
  • 点击「发送」,响应中的access_token就是你需要的Firestore Bearer Token

4. 使用Token访问Firestore API

在Firestore的API请求中,将Authorization请求头设置为Bearer {{access_token}}即可正常调用接口。

内容的提问来源于stack exchange,提问作者user2965514

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 10:33:26