You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Gateway API无法通过OAuth访问令牌认证问题求助

问题:GCP Gateway API OAuth认证JWT格式错误排查与架构疑问

现象

用Postman发送GET请求到GCP Gateway的/hello接口时,返回JWT格式错误:Jwt is not in the form of Header.Payload.Signature with two dots and 3 sections。但使用相同访问令牌调用Firebase接口却能正常通过认证。

当前配置

GCP Gateway的OpenAPI配置文件

# openapi2-functions.yaml
swagger: '2.0'
info:
  title: my-api3
  description: Sample API on API Gateway with a Google Cloud Functions backend
  version: 1.0.0
schemes:
  - https
produces:
  - application/json
paths:
  /hello:
    get:
      summary: Greet a user
      operationId: hello
      x-google-backend:
        address: #Function url here
      security:
      - google_id_token: []
      responses:
        '200':
          description: A successful response
          schema:
            type: string
securityDefinitions:
  # This section configures authentication with an Oauth
  google_id_token:
      authorizationUrl: ""
      flow: "implicit"
      type: "oauth2"
      x-google-issuer: "https://accounts.google.com"
      x-google-jwks_uri: "https://www.googleapis.com/oauth2/v3/certs"
      # Optional. Replace YOUR-CLIENT-ID with your client ID
      x-google-audiences: #client-id

其他环境信息

  • 使用的权限范围:https://www.googleapis.com/auth/cloud-platform、https://www.googleapis.com/auth/cloudfunctions
  • Cloud函数已测试两种模式:公开、IAM认证,结果一致
  • OAuth ID处于测试模式未发布

核心疑问

  1. 为何相同令牌能通过Firebase接口认证,却无法通过GCP Gateway?
  2. 当前架构(API Gateway转发至Cloud函数)是否合适?若不合适,可行的安全替代架构是什么?
  3. 是否应该通过谷歌账号或服务账号登录获取ID令牌后再调用Gateway API?替代架构的流程及涉及服务有哪些?

解答

1. 令牌类型不匹配是核心原因

GCP Gateway配置的google_id_token认证方式,要求请求中携带的是ID令牌(ID Token),但你当前使用的是访问令牌(Access Token):

  • 访问令牌用于授权访问Google Cloud服务(如Firebase、Cloud Functions),校验逻辑兼容非标准JWT格式;
  • ID令牌是标准三段式JWT,专门用于身份认证,完全符合Gateway的google_id_token校验规则。

Firebase接口支持访问令牌是因为它的认证逻辑兼容授权校验,而Gateway的google_id_token规则只接受标准ID令牌,因此出现格式错误。

2. 当前架构的调整与替代方案

当前API Gateway + Cloud Functions的架构本身可行,核心是修正令牌类型;若需调整,可参考以下安全架构:

方案1:终端用户认证(谷歌账号)

流程:

  • 用户通过Google OAuth 2.0授权流程(隐式/授权码模式),请求openid scope获取ID令牌;
  • 客户端携带ID令牌调用API Gateway;
  • Gateway校验ID令牌后转发请求到Cloud Functions。
    涉及服务:Google Identity Platform、API Gateway、Cloud Functions

方案2:服务间认证(服务账号)

流程:

  • 调用方用服务账号生成ID令牌(目标受众设为Gateway的客户端ID或API域名);
  • 携带ID令牌调用Gateway;
  • Gateway校验后转发到Cloud Functions。
    涉及服务:IAM服务账号、API Gateway、Cloud Functions

方案3:Cloud Functions直接IAM认证(跳过Gateway)

若不需要Gateway的流量控制、API管理能力,可直接让客户端通过IAM认证调用Cloud Functions:

  • 终端用户:用ID令牌或OAuth访问令牌调用;
  • 服务调用方:用服务账号的访问令牌或ID令牌调用。
    涉及服务:IAM、Cloud Functions

3. 具体修正步骤

  • 补全Gateway配置:将x-google-audiences字段填写为你的OAuth客户端ID(必填,否则校验会失败);
  • 获取正确的ID令牌:
    • 终端用户:在OAuth授权流程中添加openid scope,确保返回ID令牌;
    • 服务账号:使用gcloud命令生成ID令牌:
      gcloud auth print-identity-token --audiences=YOUR-GATEWAY-CLIENT-ID --impersonate-service-account=YOUR-SA@PROJECT.iam.gserviceaccount.com
      

内容的提问来源于stack exchange,提问作者Ankur Pawar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 18:40:43