使用Firebase REST API验证OAuth令牌时遇INVALID_IDP_RESPONSE错误求助
Let’s break down why you’re hitting that INVALID_IDP_RESPONSE error and how to fix it—this is a common gotcha when working with Google OAuth tokens and Firebase.
The Core Issue: Wrong Token Type
First off, ScriptApp.getOAuthToken() gives you a Google Apps Script-specific OAuth 2.0 access token, which is meant for accessing Google APIs (like Sheets or Drive). Firebase's signInWithIdp endpoint expects a Google ID Token instead—this is a JWT that proves the user's identity, not just a token for API access. That’s the biggest reason you’re seeing the error.
Step-by-Step Fixes
1. Get a Valid Google ID Token in Apps Script
To get an ID token, you’ll need to use the OAuth2 library for Apps Script (it simplifies handling the OAuth flow with the right scopes). Here’s how:
- Add the OAuth2 Library: In your Apps Script project, go to Resources > Libraries, and add this library ID:
1B7FSrk5Zi6L1rSxxTDgDEUsPzlukDsi4KGuTMorsTQHhGBzBkMun4iDF. Use the latest version available. - Configure OAuth Credentials:
- Head to the Google Cloud Console for your project, navigate to APIs & Services > Credentials.
- Create a Web application OAuth client ID.
- Add your Apps Script callback URI (get this via
ScriptApp.getService().getUrl()) to the redirect URIs list.
- Use this Code to Fetch the ID Token:
function getGoogleIdToken() { const clientId = "YOUR_WEB_CLIENT_ID"; const clientSecret = "YOUR_WEB_CLIENT_SECRET"; const scope = "openid email profile"; // Required to generate an ID token const service = OAuth2.createService("GoogleIDToken") .setAuthorizationBaseUrl("https://accounts.google.com/o/oauth2/auth") .setTokenUrl("https://oauth2.googleapis.com/token") .setClientId(clientId) .setClientSecret(clientSecret) .setCallbackFunction("authCallback") .setScope(scope) .setParam("access_type", "offline") .setParam("prompt", "consent"); if (service.hasAccess()) { // Extract the ID token from the OAuth service's token data const tokenData = service.getToken(); return tokenData.id_token; } else { // First run: prompt the user to authorize the app const authUrl = service.getAuthorizationUrl(); Logger.log("Authorize your app here: " + authUrl); return null; } } function authCallback(request) { const service = OAuth2.createService("GoogleIDToken"); const isAuthorized = service.handleCallback(request); return HtmlService.createHtmlOutput(isAuthorized ? "Authorization successful!" : "Authorization denied."); }
2. Fix the Redirect URI Mismatch
Your requestUri must exactly match the redirect URI configured in your Google Cloud OAuth client. Double-check:
- Use
ScriptApp.getService().getUrl()to get the correct callback URI for your Apps Script project. - Update your OAuth client’s redirect URIs in the Google Cloud Console to include this exact URL.
3. Correct the postBody Format
In your credentials object, you used & (an HTML entity) instead of a plain &. Fix that line to:
postBody: `id_token=${googleIdToken}&providerId=google.com`,
Replace googleIdToken with the value you get from the getGoogleIdToken() function above.
4. Verify OAuth Scopes in Apps Script
Make sure your appsscript.json file includes the necessary scopes. You can edit it by going to View > Show manifest file:
{ "oauthScopes": [ "https://www.googleapis.com/auth/script.external_request", "openid", "email", "profile" ] }
Test the Flow Again
Once you’ve made these changes, fetch the ID token using getGoogleIdToken(), pass it to the Firebase signInWithIdp endpoint, and you should no longer get the INVALID_IDP_RESPONSE error. You can then use the returned Firebase ID token to authenticate your cloud function requests and check the admin custom claim.
内容的提问来源于stack exchange,提问作者Chukwuma Nwaugha

