如何用Google访问令牌获取Azure B2C JWT令牌?(Flutter场景)
How to Exchange Google Access Token (
ya29.Glss...) for Azure B2C JWT (eyJhbGciO...) Great question—this is a super common scenario when you want to ditch B2C's hosted browser flow and use native social login SDKs instead. The core solution is leveraging Azure B2C's token exchange flow to trade your Google access token for a B2C-signed JWT. Here's a straightforward breakdown:
Prerequisites First
Before diving in, make sure you’ve got these bases covered:
- Google is configured as an identity provider in your Azure B2C tenant (you’ll need your Google Cloud client ID/secret linked in B2C’s identity provider settings).
- You’ve set up a custom policy in Azure B2C (default user flows don’t support direct token exchange with third-party tokens—custom policies are mandatory here).
Step 1: Configure Your Custom Policy for Token Exchange
You’ll need to tweak your custom policy to enable token exchange:
- Ensure Google is added as a claims provider (if it isn’t already).
- Add a technical profile that supports the
urn:ietf:params:oauth:grant-type:jwt-bearergrant type—this is what triggers the token exchange logic.
Key policy updates to make:
- In the
<ClaimsProviders>section, confirm your Google claims provider has a technical profile that accepts external tokens. - Update your relying party technical profile to allow token exchange requests (set
GrantTypetourn:ietf:params:oauth:grant-type:jwt-bearer).
Step 2: Send the Token Exchange Request to Azure B2C
Once your policy is set up, send a POST request to B2C’s token endpoint with these parameters:
Example Request (curl)
POST https://your-b2c-tenant.b2clogin.com/your-b2c-tenant.onmicrosoft.com/your-custom-policy-id/oauth2/v2.0/token Content-Type: application/x-www-form-urlencoded grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer &client_id=your-b2c-app-client-id &client_secret=your-b2c-app-client-secret # Only required if your B2C app is a confidential client (e.g., backend services) &assertion=ya29.Glss... # Your native Google login access token &assertion_type=urn:ietf:params:oauth:token-type:access_token &scope=openid offline_access https://your-b2c-tenant.onmicrosoft.com/your-api-name/api.read &requested_token_use=id_token # Use "access_token" if you need an API access token instead
Key Parameters Explained
grant_type: Must beurn:ietf:params:oauth:grant-type:jwt-bearerto tell B2C you’re doing a token exchange.assertion: The Google access token you grabbed from the native login plugin.assertion_type: Explicitly tells B2C this is a Google access token (use the value above).scope: Define the permissions you want in the B2C token—openidfor an ID token,offline_accessfor a refresh token, plus any API-specific scopes you need.
Critical Notes
- Google Token Validity: Double-check that your Google access token isn’t expired, and its
aud(audience) claim matches the Google client ID you linked in Azure B2C. B2C will reject tokens with mismatched audiences immediately. - No Extra Google Params: You don’t need to add special parameters when requesting the Google token—just a valid access token from the native SDK is all you need.
- Troubleshooting: Common issues include invalid tokens, misconfigured custom policies, or missing scopes. B2C’s error responses usually have detailed messages to help you debug.
内容的提问来源于stack exchange,提问作者Chief Wiggum
相关产品推荐
相关产品推荐

