You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud Run托管外部身份登录重定向及Google登录报错问题

Troubleshooting: Google Authentication 403 Error with Cloud Run Hosted External Identity Login

Hey Jeff, let's break down how to fix that Google sign-in 403 error you're seeing, building on what you've already resolved:

Recap of Your Situation

Your App Engine app works fine with unauthenticated access or IAP-controlled access. When setting up Cloud Run-hosted external identity login, you first hit a metadata fetch error:

"Could not fetch URI /computeMetadata/v1/instance/service-accounts/default/token?scopes=https://www.googleapis.com/auth/cloud-platform,https://www.googleapis.com/auth/identitytoolkit"

You fixed that by re-enabling a disabled Compute Engine service account, but now you're stuck: email/password login works, but Google sign-in throws "The requested action is invalid." with a 403 on this API call:

GET https://www.googleapis.com/identitytoolkit/v3/relyingparty/getProjectConfig?key=*mykey*&cb=1599165379363 403

Top Troubleshooting Areas to Check

1. Double-Check Google Identity Provider is Properly Enabled

You mentioned enabling Google as a provider, but let's verify the details:

  • Head to your Google Cloud project's Identity Platform page, find the Google provider, and confirm it's marked as "Enabled". If you set it up manually, make sure the OAuth client ID and secret are correctly entered.
  • If you're using a linked Firebase project, hop over to the Firebase Console's Authentication > Sign-in method tab and ensure Google sign-in is enabled there too, with no incorrect authorized domains listed.

2. Verify API Key Permissions & Restrictions

The apiKey in your request needs the right setup:

  • Go to APIs & Services > Credentials in Cloud Console, locate this API key, and confirm the Identity Toolkit API is enabled for it (this is the API powering the getProjectConfig call).
  • Check if your API key has HTTP referrer restrictions. If yes, add both your Cloud Run service domain (iap-gcip-hosted-ui-app-engine-app-myserver-uc.a.run.app) and the Firebase hosted domain (*.firebaseapp.com) to the allowed list—missing these will trigger a 403.

3. Validate OAuth Client ID Redirect URIs

Google's OAuth flow requires exact matching redirect URIs:

  • Find the OAuth 2.0 Client ID linked to your Google identity provider (under APIs & Services > Credentials). Check that your Cloud Run callback URI (https://iap-gcip-hosted-ui-app-engine-app-myserver-uc.a.run.app/?apiKey=mykey) is listed in the "Authorized redirect URIs" section.
  • Don't forget to add the FirebaseUI temporary handler URI (https://*.firebaseapp.com/__/auth/handler) too—Google OAuth will reject requests without this.

4. Check Identity Platform Project Configuration

  • Confirm your Google Cloud project is properly linked to Identity Platform, with no misconfigured provider restrictions.
  • In Identity Platform, check the "Authorized domains" setting and ensure both your Cloud Run domain and Firebase domain are included here.

5. Recheck Service Account Permissions (Just to Be Safe)

Even though you re-enabled the Compute Engine service account, confirm it has the right permissions:

  • Assign at least the roles/identitytoolkit.client role (or roles/identitytoolkit.admin for full access) to the service account, so it can call the Identity Toolkit API without issues.

Bonus Debugging Steps

  • Try accessing the getProjectConfig API directly in your browser (replace *mykey* with your actual API key). The error response will give you specific details—like invalid API key, missing permissions, or blocked domain—that narrow down the issue.
  • Check your Cloud Run service logs for additional context; sometimes the service logs will show more details about why the authentication flow is failing.

内容的提问来源于stack exchange,提问作者Jeff

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 22:47:28