You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Assistant与自建Web服务账号链接遇“Accounts failed to link”错误求助

Let’s break down why you’re hitting the "Accounts failed to link" error when redirecting to Google’s OAuth redirect URL, and fix it step by step:

1. Verify the state Parameter Matches Exactly

Google Assistant generates a unique state value when initiating the account linking flow—you can’t manually set this value yourself. When you redirect back to oauth-redirect.googleusercontent.com, the state parameter must be the exact one that Google sent to your google-oauth2 endpoint initially.

Fix:

  • When your https://webserver.herokuapp.com/google-oauth2 endpoint receives the request from Google Assistant, capture the state parameter from that request (don’t hardcode manually_set_state_value).
  • Pass this captured state through every step of your OAuth flow: include it in the redirect to Google’s login page, carry it through to your complete/google-oauth2 endpoint, and finally include it in the final redirect to Google’s OAuth URL.

2. Ensure All URLs Use HTTPS

Google requires all endpoints involved in account linking to use HTTPS. Looking at your flow, you’re using http://webserver.herokuapp.com/complete/google-oauth2/ as a redirect URI—this HTTP URL will cause validation failures.

Fix:

  • Update all redirect URIs in your Google Cloud Console (for both the Assistant app and your webserver’s OAuth setup) to use https:// instead of http://.
  • Confirm your Heroku server is configured to serve over HTTPS (Heroku provides free SSL for apps, so this should just be a matter of updating your URLs).

3. Check Implicit Flow Parameter Requirements

For Google Assistant’s implicit flow, the final redirect must include all required parameters correctly:

  • access_token: A valid token issued by your webserver
  • token_type: Must be exactly bearer (double-check it’s lowercase, no typos)
  • state: Matches the original value from Google Assistant
  • Optional but recommended: expires_in (numeric value for token expiration in seconds)

Fix:

  • Validate that your webserver is generating a valid, non-expired access_token before redirecting.
  • Double-check parameter names and values for typos (e.g., no missing underscores in access_token).

4. Confirm Client ID Consistency

Ensure the Client ID used in your webserver’s OAuth setup is exactly the same as the one configured in your Google Assistant account linking settings. A mismatch here will cause Google to reject the token exchange.

Fix:

  • Cross-verify the Client ID in your https://webserver.herokuapp.com/google-oauth2 endpoint (the one passed to Google’s auth URL) with the Client ID listed in your Actions on Google Console under Account Linking > Client ID.

5. Validate OpenID Scope Inclusion

Google’s account linking requires the openid scope to be included in the OAuth request. While you mentioned using openid+email+profile, confirm this is being passed correctly to Google’s auth endpoint.

Fix:

  • Inspect the actual URL your webserver redirects to for Google login—ensure the scope parameter is present and includes openid. If it’s missing or malformed, Google won’t issue a valid identity token that Assistant can use.

If you’re still stuck after these fixes, check the Google Assistant Developer Console’s logs (under Activity > Logs) for more specific error details—they often include hints about what’s failing during the linking process.

内容的提问来源于stack exchange,提问作者Eugene Kovalev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:29:01