You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Google访问令牌获取Azure B2C JWT令牌?(Flutter场景)

How to Exchange Google Access Token (ya29.Glss...) for Azure B2C JWT (eyJhbGciO...)

Great question—this is a super common scenario when you want to ditch B2C's hosted browser flow and use native social login SDKs instead. The core solution is leveraging Azure B2C's token exchange flow to trade your Google access token for a B2C-signed JWT. Here's a straightforward breakdown:

Prerequisites First

Before diving in, make sure you’ve got these bases covered:

  • Google is configured as an identity provider in your Azure B2C tenant (you’ll need your Google Cloud client ID/secret linked in B2C’s identity provider settings).
  • You’ve set up a custom policy in Azure B2C (default user flows don’t support direct token exchange with third-party tokens—custom policies are mandatory here).

Step 1: Configure Your Custom Policy for Token Exchange

You’ll need to tweak your custom policy to enable token exchange:

  • Ensure Google is added as a claims provider (if it isn’t already).
  • Add a technical profile that supports the urn:ietf:params:oauth:grant-type:jwt-bearer grant type—this is what triggers the token exchange logic.

Key policy updates to make:

  1. In the <ClaimsProviders> section, confirm your Google claims provider has a technical profile that accepts external tokens.
  2. Update your relying party technical profile to allow token exchange requests (set GrantType to urn:ietf:params:oauth:grant-type:jwt-bearer).

Step 2: Send the Token Exchange Request to Azure B2C

Once your policy is set up, send a POST request to B2C’s token endpoint with these parameters:

Example Request (curl)

POST https://your-b2c-tenant.b2clogin.com/your-b2c-tenant.onmicrosoft.com/your-custom-policy-id/oauth2/v2.0/token
Content-Type: application/x-www-form-urlencoded

grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer
&client_id=your-b2c-app-client-id
&client_secret=your-b2c-app-client-secret  # Only required if your B2C app is a confidential client (e.g., backend services)
&assertion=ya29.Glss...  # Your native Google login access token
&assertion_type=urn:ietf:params:oauth:token-type:access_token
&scope=openid offline_access https://your-b2c-tenant.onmicrosoft.com/your-api-name/api.read
&requested_token_use=id_token  # Use "access_token" if you need an API access token instead

Key Parameters Explained

  • grant_type: Must be urn:ietf:params:oauth:grant-type:jwt-bearer to tell B2C you’re doing a token exchange.
  • assertion: The Google access token you grabbed from the native login plugin.
  • assertion_type: Explicitly tells B2C this is a Google access token (use the value above).
  • scope: Define the permissions you want in the B2C token—openid for an ID token, offline_access for a refresh token, plus any API-specific scopes you need.

Critical Notes

  • Google Token Validity: Double-check that your Google access token isn’t expired, and its aud (audience) claim matches the Google client ID you linked in Azure B2C. B2C will reject tokens with mismatched audiences immediately.
  • No Extra Google Params: You don’t need to add special parameters when requesting the Google token—just a valid access token from the native SDK is all you need.
  • Troubleshooting: Common issues include invalid tokens, misconfigured custom policies, or missing scopes. B2C’s error responses usually have detailed messages to help you debug.

内容的提问来源于stack exchange,提问作者Chief Wiggum

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:32:22