GCP Gateway API无法通过OAuth访问令牌认证问题求助
问题:GCP Gateway API OAuth认证JWT格式错误排查与架构疑问
现象
用Postman发送GET请求到GCP Gateway的/hello接口时,返回JWT格式错误:Jwt is not in the form of Header.Payload.Signature with two dots and 3 sections。但使用相同访问令牌调用Firebase接口却能正常通过认证。
当前配置
GCP Gateway的OpenAPI配置文件
# openapi2-functions.yaml swagger: '2.0' info: title: my-api3 description: Sample API on API Gateway with a Google Cloud Functions backend version: 1.0.0 schemes: - https produces: - application/json paths: /hello: get: summary: Greet a user operationId: hello x-google-backend: address: #Function url here security: - google_id_token: [] responses: '200': description: A successful response schema: type: string securityDefinitions: # This section configures authentication with an Oauth google_id_token: authorizationUrl: "" flow: "implicit" type: "oauth2" x-google-issuer: "https://accounts.google.com" x-google-jwks_uri: "https://www.googleapis.com/oauth2/v3/certs" # Optional. Replace YOUR-CLIENT-ID with your client ID x-google-audiences: #client-id
其他环境信息
- 使用的权限范围:
https://www.googleapis.com/auth/cloud-platform、https://www.googleapis.com/auth/cloudfunctions - Cloud函数已测试两种模式:公开、IAM认证,结果一致
- OAuth ID处于测试模式未发布
核心疑问
- 为何相同令牌能通过Firebase接口认证,却无法通过GCP Gateway?
- 当前架构(API Gateway转发至Cloud函数)是否合适?若不合适,可行的安全替代架构是什么?
- 是否应该通过谷歌账号或服务账号登录获取ID令牌后再调用Gateway API?替代架构的流程及涉及服务有哪些?
解答
1. 令牌类型不匹配是核心原因
GCP Gateway配置的google_id_token认证方式,要求请求中携带的是ID令牌(ID Token),但你当前使用的是访问令牌(Access Token):
- 访问令牌用于授权访问Google Cloud服务(如Firebase、Cloud Functions),校验逻辑兼容非标准JWT格式;
- ID令牌是标准三段式JWT,专门用于身份认证,完全符合Gateway的
google_id_token校验规则。
Firebase接口支持访问令牌是因为它的认证逻辑兼容授权校验,而Gateway的google_id_token规则只接受标准ID令牌,因此出现格式错误。
2. 当前架构的调整与替代方案
当前API Gateway + Cloud Functions的架构本身可行,核心是修正令牌类型;若需调整,可参考以下安全架构:
方案1:终端用户认证(谷歌账号)
流程:
- 用户通过Google OAuth 2.0授权流程(隐式/授权码模式),请求
openidscope获取ID令牌; - 客户端携带ID令牌调用API Gateway;
- Gateway校验ID令牌后转发请求到Cloud Functions。
涉及服务:Google Identity Platform、API Gateway、Cloud Functions
方案2:服务间认证(服务账号)
流程:
- 调用方用服务账号生成ID令牌(目标受众设为Gateway的客户端ID或API域名);
- 携带ID令牌调用Gateway;
- Gateway校验后转发到Cloud Functions。
涉及服务:IAM服务账号、API Gateway、Cloud Functions
方案3:Cloud Functions直接IAM认证(跳过Gateway)
若不需要Gateway的流量控制、API管理能力,可直接让客户端通过IAM认证调用Cloud Functions:
- 终端用户:用ID令牌或OAuth访问令牌调用;
- 服务调用方:用服务账号的访问令牌或ID令牌调用。
涉及服务:IAM、Cloud Functions
3. 具体修正步骤
- 补全Gateway配置:将
x-google-audiences字段填写为你的OAuth客户端ID(必填,否则校验会失败); - 获取正确的ID令牌:
- 终端用户:在OAuth授权流程中添加
openidscope,确保返回ID令牌; - 服务账号:使用
gcloud命令生成ID令牌:gcloud auth print-identity-token --audiences=YOUR-GATEWAY-CLIENT-ID --impersonate-service-account=YOUR-SA@PROJECT.iam.gserviceaccount.com
- 终端用户:在OAuth授权流程中添加
内容的提问来源于stack exchange,提问作者Ankur Pawar
相关产品推荐
相关产品推荐

