You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Business Communications:如何获取access_token而非id_token?

解决方案

一、手动生成JWT请求的正确参数

用Postman调用https://oauth2.googleapis.com/token获取access_token,得把以下参数配置完整:

  • grant_type:固定填写urn:ietf:params:oauth:grant-type:jwt-bearer
  • assertion:你生成的JWT令牌,且JWT的payload必须包含这些字段:
    • aud:固定为https://oauth2.googleapis.com/token
    • scope:必须写完整的https://www.googleapis.com/auth/businesscommunications(别用oauth2l里的简写businesscommunications)
    • exp:过期时间,设为当前时间加3600秒(不能超过1小时)
    • iat:签发时间
    • iss:服务账户的邮箱(从下载的JSON密钥文件的client_email字段获取)

之前只拿到id_token,大概率是JWT payload没加正确的scope,或者grant_type填错了。

二、Google API PHP Client的正确用法

别直接调用token接口,用客户端自带的服务账户授权流程,参考代码如下:

require __DIR__ . '/vendor/autoload.php';

$client = new Google\Client();
$client->setAuthConfig('./service_account_key.json');
// 必须添加完整的scope URL
$client->addScope('https://www.googleapis.com/auth/businesscommunications');
// 开启服务账户模式
$client->useApplicationDefaultCredentials();
// 获取access token
$accessToken = $client->fetchAccessTokenWithAssertion();

// 输出获取到的access_token
print_r($accessToken['access_token']);

核心注意点:

  • 必须使用完整的scope URL,不能用简写
  • 要确保服务账户已在Google Cloud Console中被授予对应权限,比如添加Business Communications Editor角色
  • 手动生成JWT时,签名算法必须为RS256,用服务账户的私钥签名

三、验证access_token有效性

拿到token后,可通过以下命令检查:

oauth2l info --token YOUR_ACCESS_TOKEN

查看返回结果的scope中是否包含https://www.googleapis.com/auth/businesscommunications,包含则说明token有效。

内容的提问来源于stack exchange,提问作者Paul Adrian Sevilla Ramirez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 21:54:24