You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Firebase REST API验证OAuth令牌时遇INVALID_IDP_RESPONSE错误求助

Fixing INVALID_IDP_RESPONSE Error When Using Google Apps Script OAuth Token with Firebase signInWithIdp

Let’s break down why you’re hitting that INVALID_IDP_RESPONSE error and how to fix it—this is a common gotcha when working with Google OAuth tokens and Firebase.

The Core Issue: Wrong Token Type

First off, ScriptApp.getOAuthToken() gives you a Google Apps Script-specific OAuth 2.0 access token, which is meant for accessing Google APIs (like Sheets or Drive). Firebase's signInWithIdp endpoint expects a Google ID Token instead—this is a JWT that proves the user's identity, not just a token for API access. That’s the biggest reason you’re seeing the error.

Step-by-Step Fixes

1. Get a Valid Google ID Token in Apps Script

To get an ID token, you’ll need to use the OAuth2 library for Apps Script (it simplifies handling the OAuth flow with the right scopes). Here’s how:

  • Add the OAuth2 Library: In your Apps Script project, go to Resources > Libraries, and add this library ID: 1B7FSrk5Zi6L1rSxxTDgDEUsPzlukDsi4KGuTMorsTQHhGBzBkMun4iDF. Use the latest version available.
  • Configure OAuth Credentials:
    • Head to the Google Cloud Console for your project, navigate to APIs & Services > Credentials.
    • Create a Web application OAuth client ID.
    • Add your Apps Script callback URI (get this via ScriptApp.getService().getUrl()) to the redirect URIs list.
  • Use this Code to Fetch the ID Token:
function getGoogleIdToken() {
  const clientId = "YOUR_WEB_CLIENT_ID";
  const clientSecret = "YOUR_WEB_CLIENT_SECRET";
  const scope = "openid email profile"; // Required to generate an ID token

  const service = OAuth2.createService("GoogleIDToken")
    .setAuthorizationBaseUrl("https://accounts.google.com/o/oauth2/auth")
    .setTokenUrl("https://oauth2.googleapis.com/token")
    .setClientId(clientId)
    .setClientSecret(clientSecret)
    .setCallbackFunction("authCallback")
    .setScope(scope)
    .setParam("access_type", "offline")
    .setParam("prompt", "consent");

  if (service.hasAccess()) {
    // Extract the ID token from the OAuth service's token data
    const tokenData = service.getToken();
    return tokenData.id_token;
  } else {
    // First run: prompt the user to authorize the app
    const authUrl = service.getAuthorizationUrl();
    Logger.log("Authorize your app here: " + authUrl);
    return null;
  }
}

function authCallback(request) {
  const service = OAuth2.createService("GoogleIDToken");
  const isAuthorized = service.handleCallback(request);
  return HtmlService.createHtmlOutput(isAuthorized ? "Authorization successful!" : "Authorization denied.");
}

2. Fix the Redirect URI Mismatch

Your requestUri must exactly match the redirect URI configured in your Google Cloud OAuth client. Double-check:

  • Use ScriptApp.getService().getUrl() to get the correct callback URI for your Apps Script project.
  • Update your OAuth client’s redirect URIs in the Google Cloud Console to include this exact URL.

3. Correct the postBody Format

In your credentials object, you used & (an HTML entity) instead of a plain &. Fix that line to:

postBody: `id_token=${googleIdToken}&providerId=google.com`,

Replace googleIdToken with the value you get from the getGoogleIdToken() function above.

4. Verify OAuth Scopes in Apps Script

Make sure your appsscript.json file includes the necessary scopes. You can edit it by going to View > Show manifest file:

{
  "oauthScopes": [
    "https://www.googleapis.com/auth/script.external_request",
    "openid",
    "email",
    "profile"
  ]
}

Test the Flow Again

Once you’ve made these changes, fetch the ID token using getGoogleIdToken(), pass it to the Firebase signInWithIdp endpoint, and you should no longer get the INVALID_IDP_RESPONSE error. You can then use the returned Firebase ID token to authenticate your cloud function requests and check the admin custom claim.

内容的提问来源于stack exchange,提问作者Chukwuma Nwaugha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:21:52