You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让IdentityServer-A信任IdentityServer-B生成的引用令牌?

嘿,这个问题我之前帮团队处理过——核心原因是引用令牌的设计本质:它只是签发它的IdentityServer(也就是B)内部的一个“引用ID”,实际的令牌数据存在B的存储里,IdentityServer-A根本拿不到这些数据,自然会判定为Invalid reference token。

要解决这个跨实例信任的问题,有两种主流方案,看你的场景需求来选:

方案一:换成JWT自包含令牌(推荐)

JWT是自包含的令牌,里面自带了所有验证所需的信息(签名、Claims、有效期等),只要IdentityServer-A信任IdentityServer-B的签名密钥,就能直接验证令牌有效性,不需要依赖B的存储。具体步骤:

  • 在IdentityServer-B的客户端配置(对应Website-B的Client)里,把AccessTokenType设置为AccessTokenType.Jwt:
    new Client
    {
        ClientId = "website-b",
        // 其他配置...
        AccessTokenType = AccessTokenType.Jwt
    }
    
  • 在IdentityServer-A的配置中,添加IdentityServer-B作为受信任的身份提供者:
    1. 注册B的元数据地址,让A自动获取B的公钥和配置:
      services.AddAuthentication()
          .AddJwtBearer("B", options =>
          {
              options.Authority = "https://identityserver-b.example.com";
              options.Audience = "api-a"; // API-A的资源名称
              options.TokenValidationParameters = new TokenValidationParameters
              {
                  ValidateIssuer = true,
                  ValidIssuers = new[] { "https://identityserver-b.example.com" }
              };
          });
      
    2. 在API-A的授权配置中,允许接受来自B的令牌:
      services.AddAuthorization(options =>
      {
          options.DefaultPolicy = new AuthorizationPolicyBuilder()
              .RequireAuthenticatedUser()
              .AddAuthenticationSchemes("Bearer", "B") // 同时支持A和B的令牌
              .Build();
      });
      
  • 测试流程:Website-B从B获取JWT令牌后,直接携带它访问API-A,IdentityServer-A会验证JWT的签名和内容,验证通过就允许访问。

方案二:实现令牌转换(保留引用令牌场景)

如果因为合规或其他原因必须用引用令牌,那得让Website-B先把B的引用令牌转换成A的引用令牌,再访问API-A。原理是IdentityServer-A会调用IdentityServer-B的令牌 introspect 端点验证原令牌的有效性,然后签发自己的引用令牌。具体步骤:

  • 在IdentityServer-A中配置一个专门用于令牌转换的客户端(给Website-B用):
    new Client
    {
        ClientId = "website-b-token-exchange",
        ClientSecrets = { new Secret("your-secret".Sha256()) },
        AllowedGrantTypes = GrantTypes.TokenExchange,
        AllowOfflineAccess = true,
        AllowedScopes = { "api-a" } // 要访问的API-A资源
    }
    
  • 在IdentityServer-B中,确保Website-B的客户端有权限访问introspect端点,并且配置A为允许的调用方(如果B开启了introspect的权限控制)。
  • 修改Website-B的请求流程:
    1. 先从IdentityServer-B获取引用令牌。
    2. 向IdentityServer-A的/connect/token端点发送令牌交换请求,参数如下:
      POST /connect/token
      Content-Type: application/x-www-form-urlencoded
      
      grant_type=urn:ietf:params:oauth:grant-type:token-exchange
      client_id=website-b-token-exchange
      client_secret=your-secret
      subject_token=【从B获取的引用令牌】
      subject_token_type=urn:ietf:params:oauth:token-type:access_token
      audience=api-a
      
    3. 拿到A签发的引用令牌后,再用这个令牌访问API-A,此时A就能正常验证自己签发的引用令牌了。

注意事项

  • 不管用哪种方案,都要确保IdentityServer-A和B之间的网络是互通的(尤其是方案二中A调用B的introspect端点时)。
  • 要严格配置Issuer、Audience和签名密钥,避免出现令牌验证不通过的情况。
  • 如果用方案二,记得给IdentityServer-B的introspect端点配置正确的权限,确保A可以合法调用它验证令牌。

内容的提问来源于stack exchange,提问作者Abdullah Hashim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 17:47:57