Gmail API REST请求跳过浏览器授权及PHP调用发信相关问题
企业Gmail API自动授权及发信实现方案
一、跳过手动授权的实现方法
你当前使用的是普通OAuth2授权码流程,本身规则就要求用户手动确认授权,针对企业Gmail场景,直接使用带全域委派权限的服务账号即可完全跳过手动操作步骤,实现全自动授权:
- 操作前置配置:
- 在Google Cloud控制台创建服务账号,生成JSON格式的密钥文件
- 为该服务账号启用Gmail API调用权限
- 在企业Google Admin控制台,为该服务账号授予
https://www.googleapis.com/auth/gmail.send的全域委派权限,允许它模拟域内任意邮箱身份发信
- 服务账号换access token示例(PHP过程式):
// 加载服务账号密钥内容,替换为你自己的密钥参数 $service_account_key = json_decode(file_get_contents('your-service-account-key.json'), true); $iss = $service_account_key['client_email']; $scope = 'https://www.googleapis.com/auth/gmail.send'; // 要模拟发信的企业邮箱账号 $sub = 'sender@your-company-domain.com'; $iat = time(); $exp = $iat + 3600; // base64url编码处理 function base64url_encode($data) { return rtrim(strtr(base64_encode($data), '+/', '-_'), '='); } // 构造JWT头 $header = json_encode(['alg' => 'RS256', 'typ' => 'JWT']); // 构造JWT载荷 $payload = json_encode([ 'iss' => $iss, 'scope' => $scope, 'aud' => 'https://oauth2.googleapis.com/token', 'exp' => $exp, 'iat' => $iat, 'sub' => $sub ]); $jwt_header_enc = base64url_encode($header); $jwt_payload_enc = base64url_encode($payload); // 用服务账号私钥签名 openssl_sign("$jwt_header_enc.$jwt_payload_enc", $signature, $service_account_key['private_key'], 'SHA256'); $jwt_signature_enc = base64url_encode($signature); $jwt = "$jwt_header_enc.$jwt_payload_enc.$jwt_signature_enc"; // POST请求换access token $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, 'https://oauth2.googleapis.com/token'); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query([ 'grant_type' => 'urn:ietf:params:oauth:grant-type:jwt-bearer', 'assertion' => $jwt ])); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $response = curl_exec($ch); curl_close($ch); $token_data = json_decode($response, true); $access_token = $token_data['access_token'];
用这个方式拿到的access_token不需要任何手动授权操作,直接可以调用Gmail API。
二、Gmail发邮件REST调用示例
Gmail API发信要求邮件内容为base64url编码的标准MIME格式字符串,发送接口为POST https://gmail.googleapis.com/gmail/v1/users/me/messages/send
1. CURL命令示例
首先构造标准MIME邮件内容:
From: 技术部 <tech@your-domain.com> To: 客户 <customer@example.com> Subject: 合作对接确认 Content-Type: text/plain; charset=utf-8 您好,附件是本次合作的对接文档,请查收。
将上述内容做base64url编码(替换+为-、/为_、删除末尾的=),假设编码后字符串为ENCODED_MAIL_CONTENT,调用命令如下:
curl --request POST \ "https://gmail.googleapis.com/gmail/v1/users/me/messages/send" \ --header "Authorization: Bearer 替换为你拿到的access_token" \ --header "Content-Type: application/json" \ --data '{"raw": "ENCODED_MAIL_CONTENT"}'
2. PHP过程式调用示例
// 构造MIME邮件 $to = 'recipient@example.com'; $from = 'sender@your-domain.com'; $subject = '测试API发信'; $message_text = '这是通过Gmail API发送的测试邮件内容'; $mime_mail = "From: $from\r\n" . "To: $to\r\n" . "Subject: $subject\r\n" . "Content-Type: text/plain; charset=utf-8\r\n\r\n" . $message_text; // 转base64url编码 $raw_mail = rtrim(strtr(base64_encode($mime_mail), '+/', '-_'), '='); // 调用发信接口 $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, 'https://gmail.googleapis.com/gmail/v1/users/me/messages/send'); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode(['raw' => $raw_mail])); curl_setopt($ch, CURLOPT_HTTPHEADER, [ 'Authorization: Bearer ' . $access_token, 'Content-Type: application/json' ]); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $send_response = curl_exec($ch); curl_close($ch); print_r(json_decode($send_response, true));
内容的提问来源于stack exchange,提问作者fxguillois
相关产品推荐
相关产品推荐

