Google Business Communications:如何获取access_token而非id_token?
解决方案
一、手动生成JWT请求的正确参数
用Postman调用https://oauth2.googleapis.com/token获取access_token,得把以下参数配置完整:
- grant_type:固定填写
urn:ietf:params:oauth:grant-type:jwt-bearer - assertion:你生成的JWT令牌,且JWT的payload必须包含这些字段:
aud:固定为https://oauth2.googleapis.com/tokenscope:必须写完整的https://www.googleapis.com/auth/businesscommunications(别用oauth2l里的简写businesscommunications)exp:过期时间,设为当前时间加3600秒(不能超过1小时)iat:签发时间iss:服务账户的邮箱(从下载的JSON密钥文件的client_email字段获取)
之前只拿到id_token,大概率是JWT payload没加正确的scope,或者grant_type填错了。
二、Google API PHP Client的正确用法
别直接调用token接口,用客户端自带的服务账户授权流程,参考代码如下:
require __DIR__ . '/vendor/autoload.php'; $client = new Google\Client(); $client->setAuthConfig('./service_account_key.json'); // 必须添加完整的scope URL $client->addScope('https://www.googleapis.com/auth/businesscommunications'); // 开启服务账户模式 $client->useApplicationDefaultCredentials(); // 获取access token $accessToken = $client->fetchAccessTokenWithAssertion(); // 输出获取到的access_token print_r($accessToken['access_token']);
核心注意点:
- 必须使用完整的scope URL,不能用简写
- 要确保服务账户已在Google Cloud Console中被授予对应权限,比如添加Business Communications Editor角色
- 手动生成JWT时,签名算法必须为RS256,用服务账户的私钥签名
三、验证access_token有效性
拿到token后,可通过以下命令检查:
oauth2l info --token YOUR_ACCESS_TOKEN
查看返回结果的scope中是否包含https://www.googleapis.com/auth/businesscommunications,包含则说明token有效。
内容的提问来源于stack exchange,提问作者Paul Adrian Sevilla Ramirez
相关产品推荐
相关产品推荐

