You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过OAuth.tools获取Google Web应用的OAuth令牌并完成配置?

Got it, let's walk through this clearly—since you’ve already set up your Web app in Google Identity Platform, using OAuth.tools to fetch access tokens, refresh tokens, and ID tokens is totally doable once you pick the right OAuth flow and nail the configs.

Step 1: Pick the Right OAuth Flow for Your Web App

Google recommends the Authorization Code Flow with PKCE for all web applications (both server-side web apps and single-page apps/SPAs). PKCE adds an extra layer of security to prevent authorization code interception, and it’s required for SPAs (since they can’t safely store a client secret). For server-side web apps, it’s still the best practice.

Step 2: Pre-Check Your Google Identity Platform Setup

Before jumping into OAuth.tools, make sure you’ve configured these in your Google Cloud Console:

  • Add https://oauth.tools/callback to your Web app’s Authorized Redirect URIs (under OAuth 2.0 Client IDs). If you skip this, you’ll get a redirect_uri_mismatch error later.
  • Note down your Client ID (and Client Secret, if you’re using a server-side web app—skip this for SPAs).
  • Decide on the scopes you need (e.g., openid, email, profile for basic user data, or API-specific scopes like https://www.googleapis.com/auth/drive.readonly). The openid scope is mandatory if you want an ID token.
Step 3: Configure OAuth.tools

Once your Google setup is squared away, fill in these fields in OAuth.tools:

Basic Flow Settings

  • OAuth Flow: Select Authorization Code Flow (with PKCE)
  • Client Type: Choose Public (even for server-side apps, PKCE works seamlessly here)

OAuth Endpoints (Google’s Fixed URIs)

  • Authorization Endpoint: https://accounts.google.com/o/oauth2/v2/auth
  • Token Endpoint: https://oauth2.googleapis.com/token
  • Userinfo Endpoint (optional, for verifying token data): https://openidconnect.googleapis.com/v1/userinfo
  • JWKS Endpoint (optional, for validating ID token signatures): https://www.googleapis.com/oauth2/v3/certs

Client Details

  • Client ID: Paste the Client ID from your Google Identity Platform Web app
  • Client Secret: Paste this only if you’re using a server-side web app—leave it blank for SPAs (they can’t safely store secrets)
  • Redirect URI: Enter https://oauth.tools/callback (must match what you added in Google’s console)

Authorization Request Parameters

These are critical for getting all three tokens:

  • Scopes: Enter your desired scopes separated by spaces (e.g., openid email profile). Remember openid is required for an ID token.
  • Response Type: Set to code (standard for authorization code flow)
  • Code Challenge Method: Select S256 (the secure, recommended PKCE algorithm—OAuth.tools will auto-generate the challenge/verifier)
  • Access Type: Choose offline—this is non-negotiable if you want a refresh token (without it, you’ll only get a short-lived access token)
  • Prompt: Optional, but set to consent on your first run to force Google to issue a refresh token. After that, you can leave it blank or use none if you don’t need to re-authorize.
  • State: OAuth.tools will auto-generate a random value here (used to prevent CSRF attacks—no need to change it)
Step 4: Fetch Your Tokens
  1. After filling all the configs, click the Authorize button in OAuth.tools
  2. You’ll be redirected to Google’s login page—sign in with your account and approve the requested permissions
  3. Once you’re redirected back to OAuth.tools, you’ll see your access token, refresh token, and ID token displayed in the response section
  4. To test the refresh token, click the Refresh Token button—you should get a new access token without re-authenticating
Key Notes to Avoid Headaches
  • Double-check the redirect URI in both Google’s console and OAuth.tools—mismatches are the most common error here
  • For SPAs, never enter a client secret in OAuth.tools (or anywhere client-side)
  • If you don’t get a refresh token, make sure you selected offline access type and used consent prompt on your first authorization
  • ID tokens will only be returned if you included the openid scope

内容的提问来源于stack exchange,提问作者Travis Spencer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 00:03:01