You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

集成Pusher Beam时调用beamsClient.setUserId遇401(无效JWT签名)问题

Pusher Beams setUserId 401(Invalid JWT signature)问题排查

问题描述

在集成Pusher Beam Notification功能时,调用beamsClient.setUserId持续收到401错误,响应信息如下:

{"error":"Unauthorized","description":"Invalid JWT signature"}

已确认生成的JWT令牌正确,求排查可能的原因。

相关代码

const token = "****";
const instanceId = "****";
const currentUserId = "****";

const beamsTokenProvider = new PusherPushNotifications.TokenProvider({
    url: "https://our-domain/pusher-beam-auth/",
    headers: {
        "Authorization": "Token " + token,
        "Content-Type": "application/json"
    }
});

const beamsClient = new PusherPushNotifications.Client({
    instanceId: instanceId,
});

beamsClient
.start()
.then(() => beamsClient.setUserId(currentUserId, beamsTokenProvider)) // 此处始终返回401错误
.catch(console.error);

可能的原因及排查方向

  • JWT签名算法不匹配:Pusher Beams要求使用HS256算法签名JWT,若后端使用RS256或其他算法,会导致签名验证失败。需确认后端生成JWT的算法与Pusher控制台配置一致。
  • 签名密钥错误:后端必须使用Pusher Beams控制台中的Instance Secret(而非Instance ID或其他密钥)签名JWT,密钥不匹配会直接导致签名无效。
  • JWT Payload字段问题:Pusher要求JWT必须包含sub字段(值为待绑定的用户ID)和exp过期时间(有效期不超过24小时)。若字段缺失、格式错误,或sub值与前端传入的currentUserId不一致,会触发验证失败。
  • 后端认证接口响应格式错误:后端接口https://our-domain/pusher-beam-auth/需直接返回纯JWT字符串,不能返回包含额外字段的JSON对象。同时要确认前端传入的currentUserId与后端生成JWT时的sub值完全匹配(含大小写、特殊字符)。
  • 服务器时间不同步:JWT的exp校验依赖服务器时间,若后端服务器与Pusher服务器时间差过大(如超过5分钟),会被判定为无效签名。检查后端服务器系统时间是否准确。
  • 前端Instance ID错误:确认前端初始化beamsClient时的instanceId与Pusher控制台中的Instance ID完全一致,注意大小写是否匹配。

内容的提问来源于stack exchange,提问作者michael ababao

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 06:01:00