Firebase技术问题:为何会获取到两个Firebase ID Token?
Firebase ID Token 不包含用户Profile信息 & 重登Token变长问题解析
Hey Jeff, let's walk through what's going on here and how to get your ID Token showing the correct user profile data, plus clear up why that re-login token is longer.
1. Why displayName/photoURL aren't showing up in your ID Token
Firebase ID Tokens are cached by default—when you update a user's profile, the existing token doesn't automatically sync those changes. Here's what you need to fix this:
- Always force a token refresh after updating profile: Instead of just calling
getIdToken(), usegetIdToken(true)(thetrueparameter tells Firebase to skip the cache and fetch a fresh token that includes your updated profile fields). - Double-check how you're updating the profile: Make sure you're using Firebase Auth's official
updateProfile()method, not directly modifying a database record. Only changes made via the Auth API get embedded into the ID Token.
Example code to update profile and get fresh token
// Update user profile first await firebase.auth().currentUser.updateProfile({ displayName: "Jeff Minsung Kim", photoURL: "https://your-photo-url.com/avatar.jpg" }); // Force refresh to get a token with updated profile data const updatedIdToken = await firebase.auth().currentUser.getIdToken(true); // Now decode this token to verify the fields are present import jwtDecode from 'jwt-decode'; const decodedToken = jwtDecode(updatedIdToken); console.log(decodedToken.name); // Should display your displayName console.log(decodedToken.picture); // Should display your photoURL
2. Why the re-login token is longer
This is totally normal! Here's why:
- The initial post-registration token likely only contains basic auth claims (like
uid,email,exp). When you log back in after a full logout, Firebase might be including additional claims in the token—this could be custom claims you've set for the user, or extra data from your authentication provider (if you're using Google/Facebook login, for example). - To see exactly what's adding to the length, decode both tokens using a JWT decoder (like the
jwt-decodelibrary I mentioned earlier) and compare their payloads side by side. You'll spot the extra fields right away.
Quick recap
- Fix missing profile data: Force a token refresh with
getIdToken(true)after updating the user's profile. - Longer re-login token: It's just carrying more auth-related data—decode it to confirm the extra claims.
内容的提问来源于stack exchange,提问作者JeffMinsungKim
相关产品推荐
相关产品推荐

