You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS Amplify Auth.federatedSignIn()实现社交登录遇权限错误求助

解决Cognito联邦登录报错:Token is not from a supported provider of this identity pool

问题详情

尝试通过Google社交登录完成Cognito身份认证时,触发400错误:

POST https://cognito-identity.us-east-1.amazonaws.com/ 400
ERROR NotAuthorizedException: Token is not from a supported provider of this identity pool.

已在Cognito身份池中添加Google作为身份提供商,使用的代码如下:

import { GoogleAuth } from '@codetrix-studio/capacitor-google-auth';

async googleAuth() {
      let googleUser = await GoogleAuth.signIn();
      const token = googleUser.authentication.idToken;
      let user = {
        email: googleUser.email,
        name: googleUser.name,
      };
      const expiresIn = 3600;
      const providerName = 'google';

      try {
        await Auth.federatedSignIn(
          providerName,
          {
            token,
            expires_at: expiresIn * 1000 + new Date().getTime(),
          },
          user,
        );
      } catch (err) {
        console.log('ERROR', err);
      }
    }

修复方案

1. 修正提供商名称

Cognito要求Google的提供商名称为accounts.google.com,而非代码中的google,修改后代码如下:

const providerName = 'accounts.google.com';

2. 验证Google ID Token有效性

解码ID Token查看payload,确认:

  • iss字段值为https://accounts.google.com
  • aud字段值与你在Google Cloud Console创建的OAuth客户端ID完全匹配
    确保Token是Google合法签发且未过期。

3. 检查Cognito身份池配置

  • 进入AWS控制台的Cognito身份池,确认Google提供商的客户端ID与Google Cloud中的一致
  • 检查身份池的信任关系策略,确保包含Google的授权声明:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "Federated": "accounts.google.com"
          },
          "Action": "sts:AssumeRoleWithWebIdentity",
          "Condition": {
            "StringEquals": {
              "accounts.google.com:aud": "你的Google客户端ID"
            }
          }
        }
      ]
    }
    
  • 确认身份池的“未验证/已验证身份”权限中已启用Google登录。

4. 修正Token过期时间计算

避免手动计算过期时间,直接使用插件返回的expiresAt值:

const { idToken, expiresAt } = googleUser.authentication;
// ...
await Auth.federatedSignIn(
  providerName,
  {
    token: idToken,
    expires_at: expiresAt,
  },
  user,
);

内容的提问来源于stack exchange,提问作者jewells joshi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 18:20:35