如何通过OAuth.tools获取Google Web应用的OAuth令牌并完成配置?
Got it, let's walk through this clearly—since you’ve already set up your Web app in Google Identity Platform, using OAuth.tools to fetch access tokens, refresh tokens, and ID tokens is totally doable once you pick the right OAuth flow and nail the configs.
Google recommends the Authorization Code Flow with PKCE for all web applications (both server-side web apps and single-page apps/SPAs). PKCE adds an extra layer of security to prevent authorization code interception, and it’s required for SPAs (since they can’t safely store a client secret). For server-side web apps, it’s still the best practice.
Before jumping into OAuth.tools, make sure you’ve configured these in your Google Cloud Console:
- Add
https://oauth.tools/callbackto your Web app’s Authorized Redirect URIs (under OAuth 2.0 Client IDs). If you skip this, you’ll get aredirect_uri_mismatcherror later. - Note down your Client ID (and Client Secret, if you’re using a server-side web app—skip this for SPAs).
- Decide on the scopes you need (e.g.,
openid,email,profilefor basic user data, or API-specific scopes likehttps://www.googleapis.com/auth/drive.readonly). Theopenidscope is mandatory if you want an ID token.
Once your Google setup is squared away, fill in these fields in OAuth.tools:
Basic Flow Settings
- OAuth Flow: Select
Authorization Code Flow (with PKCE) - Client Type: Choose
Public(even for server-side apps, PKCE works seamlessly here)
OAuth Endpoints (Google’s Fixed URIs)
- Authorization Endpoint:
https://accounts.google.com/o/oauth2/v2/auth - Token Endpoint:
https://oauth2.googleapis.com/token - Userinfo Endpoint (optional, for verifying token data):
https://openidconnect.googleapis.com/v1/userinfo - JWKS Endpoint (optional, for validating ID token signatures):
https://www.googleapis.com/oauth2/v3/certs
Client Details
- Client ID: Paste the Client ID from your Google Identity Platform Web app
- Client Secret: Paste this only if you’re using a server-side web app—leave it blank for SPAs (they can’t safely store secrets)
- Redirect URI: Enter
https://oauth.tools/callback(must match what you added in Google’s console)
Authorization Request Parameters
These are critical for getting all three tokens:
- Scopes: Enter your desired scopes separated by spaces (e.g.,
openid email profile). Rememberopenidis required for an ID token. - Response Type: Set to
code(standard for authorization code flow) - Code Challenge Method: Select
S256(the secure, recommended PKCE algorithm—OAuth.tools will auto-generate the challenge/verifier) - Access Type: Choose
offline—this is non-negotiable if you want a refresh token (without it, you’ll only get a short-lived access token) - Prompt: Optional, but set to
consenton your first run to force Google to issue a refresh token. After that, you can leave it blank or usenoneif you don’t need to re-authorize. - State: OAuth.tools will auto-generate a random value here (used to prevent CSRF attacks—no need to change it)
- After filling all the configs, click the
Authorizebutton in OAuth.tools - You’ll be redirected to Google’s login page—sign in with your account and approve the requested permissions
- Once you’re redirected back to OAuth.tools, you’ll see your access token, refresh token, and ID token displayed in the response section
- To test the refresh token, click the
Refresh Tokenbutton—you should get a new access token without re-authenticating
- Double-check the redirect URI in both Google’s console and OAuth.tools—mismatches are the most common error here
- For SPAs, never enter a client secret in OAuth.tools (or anywhere client-side)
- If you don’t get a refresh token, make sure you selected
offlineaccess type and usedconsentprompt on your first authorization - ID tokens will only be returned if you included the
openidscope
内容的提问来源于stack exchange,提问作者Travis Spencer

