You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何查询Identity Platform关联服务账号并授权调用Cloud Function

解决Identity Platform触发器调用Cloud Function 403错误

一、查询Identity Platform关联的服务账号

控制台操作步骤

  • 打开Cloud Console,进入Identity Platform页面
  • 切换到设置标签页
  • 在服务账号板块,即可看到关联的服务账号,格式为:service-<项目编号>@gcp-sa-identitytoolkit.iam.gserviceaccount.com

命令行查询

执行以下命令(替换<你的项目ID>):

gcloud iam service-accounts list --filter="email:gcp-sa-identitytoolkit" --project=<你的项目ID>

结果中含gcp-sa-identitytoolkit的邮箱即为目标服务账号。

二、给服务账号授予Cloud Function调用权限

控制台授权步骤

  • 进入Cloud Functions页面,找到before-signup函数
  • 进入函数详情页,切换到权限标签
  • 点击添加,在新成员栏填入查到的服务账号邮箱
  • 角色选择Cloud Functions > Cloud Functions Invoker
  • 点击保存完成配置

命令行授权

执行以下命令(替换占位符为实际信息):

gcloud functions add-iam-policy-binding <函数名称> \
  --member="serviceAccount:<服务账号邮箱>" \
  --role="roles/cloudfunctions.invoker" \
  --project=<项目ID>

注意事项

  • 权限生效可能需要1-2分钟,之后再测试账号创建流程
  • 确认before-signup函数为HTTP类型(Identity Platform仅支持调用HTTP触发器的Cloud Function)

内容的提问来源于stack exchange,提问作者anonymous-dev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 01:35:45