iOS11 DeviceCheck免费试用机制实现遇授权令牌格式错误
Hey there, let's work through this DeviceCheck JWT issue you're hitting. That error usually points to a problem with how your JWT is structured, signed, or the parameters you're passing. Let's break down the possible fixes based on your code:
1. Fix the JWT.encode parameter syntax
Looking at your fetch_auth_token method, you've got a small syntax quirk in the JWT.encode call that could be causing unexpected behavior:
authentication_token = JWT.encode(body, auth_key, 'ES256', header_files = header)
The fourth parameter doesn't need the header_files = assignment — it's redundant and might confuse the method's argument handling. Change it to:
authentication_token = JWT.encode(body, auth_key, 'ES256', header)
2. Validate your p8 key file handling
Your auth_key method is on the right track, but let's add safeguards to rule out file-related issues:
- Double-check that
developer_token_filepoints to the correct absolute path of your AuthKey_#####.p8 file. Relative paths can break depending on where your Rails app is running. - Ensure the p8 file has no extra whitespace, missing lines, or formatting errors. It must start with
-----BEGIN PRIVATE KEY-----and end with-----END PRIVATE KEY-----. - Add error checking to catch invalid keys early:
def auth_key file_path = developer_token_file raise "Auth key file not found at #{file_path}" unless File.exist?(file_path) file_content = File.read(file_path) key = OpenSSL::PKey::EC.new(file_content) unless key.check_key raise "Invalid EC private key in #{file_path} — double-check file formatting" end key end
3. Verify JWT header & payload values
Small typos here will break authentication every time:
kid: Must match the exact Key ID from Apple Developer Portal when you created the AuthKey. No extra spaces, no missing characters.iss: Must be your Apple Developer Team ID (found in the Membership section of the portal).- Timestamps: Use
Time.current.to_iinstead ofDateTime.now().to_time.to_i— it's cleaner and respects your Rails app's timezone settings. Your 12-hour expiration window is correct (Apple's max allowed for DeviceCheck tokens).
4. Debug the generated JWT
Once you've made these changes, print out the generated auth_token and decode it using a client-side JWT debugging tool to verify:
- The header shows
alg: "ES256"and the correctkid. - The payload has the right
iss, validiat/exptimestamps. - The signature is valid (you can cross-check this using your p8 key in the tool).
Here's the revised fetch_auth_token method with these fixes:
def fetch_auth_token header = { alg: "ES256", kid: key_id, typ: "JWT" } body = { iss: team_id, iat: Time.current.to_i, exp: Time.current.to_i + 43_200 # 12-hour expiration (Apple's max) } JWT.encode(body, auth_key, 'ES256', header) end
Start with the syntax fix for JWT.encode — that's a common gotcha. Then work through the key validation and parameter checks, and you should be able to resolve that authentication token error.
内容的提问来源于stack exchange,提问作者Jmf

