Firebase云函数FCM推送报错:凭证与注册令牌归属不一致
Let's break down why you're hitting this messaging/mismatched-credential error and how to fix it—since manual pushes work, we know your device tokens are valid, so the issue is almost certainly with how your Cloud Function is authenticating to FCM.
Key Observations & Fixes
The error tells us the credential your Cloud Function is using doesn't have permission to send to those tokens, even though you only have one Firebase project. Here are the most likely solutions:
1. Simplify Firebase Admin Initialization
Your current initialization uses functions.config().firebase, an older pattern. Newer versions of the Firebase Admin SDK automatically pick up the correct project credentials when running in Cloud Functions. Update your initialization line to:
admin.initializeApp();
If you manually specified a service account key before, double-check that key was downloaded from your exact Firebase project (not a forgotten staging/test project).
2. Verify Tokens Belong to Your Project
Even though manual pushes work, confirm the tokens your Cloud Function fetches from the tokens collection are linked to your project:
- Grab one token from your Cloud Function logs
- Go to your Firebase Console > Cloud Messaging > Send your first message
- Paste that token into the "Test on device" field and send a test
- If it fails, that token belongs to another project—check your client app's
google-services.json/GoogleService-Info.plistto ensure it uses the correct project config.
3. Clarify the Server Key's Role
The Firebase Server Key is used to authenticate requests to the FCM HTTP REST API. When using the Firebase Admin SDK in Cloud Functions, you don't need to use it directly—the SDK handles authentication via the project's service account automatically. Your manual push works because the console uses the Server Key under the hood, confirming your tokens and project are aligned.
4. Confirm Cloud Function Deployment Target
It's easy to accidentally deploy to the wrong project if you have multiple Firebase projects configured in your CLI:
- Run
firebase usein your terminal to check which project your CLI targets - If it's incorrect, switch with
firebase use <your-project-id>and redeploy the function
5. Fix Token Cleanup Logic
Your cleanupTokens function wasn't actually adding tokens to delete—here's the corrected version to remove invalid tokens from Firestore:
function cleanupTokens(response, tokens) { const tokensDelete = []; response.results.forEach((result, index) => { const error = result.error; if (error) { console.error("Failure sending notification to", tokens[index], error); if ( error.code === "messaging/invalid-registration-token" || error.code === "messaging/registration-token-not-registered" ) { // Add delete promise to the cleanup array tokensDelete.push(admin.firestore().collection("tokens").doc(tokens[index]).delete()); } } }); return Promise.all(tokensDelete); }
Final Troubleshooting Step
If none of the above works:
- Delete the existing Cloud Function and redeploy it fresh
- In the GCP Console, check that the service account assigned to your Cloud Function has the
Cloud Messaging Adminrole (under IAM & Admin > IAM)
内容的提问来源于stack exchange,提问作者Neat

