You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP API Gateway配置OpenAPI安全定义校验Identity Platform指定租户用户身份

GCP Identity Platform 指定租户的 OpenAPI 安全定义配置方案

你需要替换安全定义中签发方(issuer)字段为租户专属值即可实现指定租户用户的身份校验,其余基础配置逻辑和默认Firebase校验规则一致。

配置模板

先确认两个必填参数:

  • 你的GCP项目ID:{project_id}
  • 你创建的Identity Platform租户ID:{tenant_id}(可在Identity Platform租户管理页面查询获取)

完整的安全定义配置如下:

securityDefinitions:
  identity_platform_tenant:
    authorizationUrl: ""
    flow: "implicit"
    type: "oauth2"
    x-google-issuer: "https://securetoken.google.com/{project_id}/tenants/{tenant_id}"
    x-google-jwks_uri: "https://www.googleapis.com/service_accounts/v1/metadata/x509/securetoken@system.gserviceaccount.com"
    x-google-audiences: "{project_id}"

字段说明

  • x-google-issuer:这是实现租户校验的核心字段,相比普通Firebase校验的issuer地址,额外增加了/tenants/{tenant_id}后缀,API Gateway会自动校验请求携带的JWT令牌的iss字段是否完全匹配该值,非该租户的用户请求会直接被拦截。
  • x-google-jwks_uri:租户身份令牌的公钥校验地址和默认Firebase一致,无需修改。
  • x-google-audiences:填写你的GCP项目ID即可,用于校验JWT的受众字段,避免跨项目滥用令牌。

绑定到API路径

配置完安全定义后,需要在对应API路径下指定使用该安全规则进行校验,示例如下:

paths:
  /your-business-api:
    get:
      security:
        - identity_platform_tenant: []
      # 其余API配置项

注意:需要确保客户端请求携带的ID令牌是通过该租户的身份认证流程获取的,否则签发方不匹配会直接返回401未授权错误。

内容的提问来源于stack exchange,提问作者Oscar Ojeda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.23 17:45:02