You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase技术问题:为何会获取到两个Firebase ID Token?

Firebase ID Token 不包含用户Profile信息 & 重登Token变长问题解析

Hey Jeff, let's walk through what's going on here and how to get your ID Token showing the correct user profile data, plus clear up why that re-login token is longer.

1. Why displayName/photoURL aren't showing up in your ID Token

Firebase ID Tokens are cached by default—when you update a user's profile, the existing token doesn't automatically sync those changes. Here's what you need to fix this:

  • Always force a token refresh after updating profile: Instead of just calling getIdToken(), use getIdToken(true) (the true parameter tells Firebase to skip the cache and fetch a fresh token that includes your updated profile fields).
  • Double-check how you're updating the profile: Make sure you're using Firebase Auth's official updateProfile() method, not directly modifying a database record. Only changes made via the Auth API get embedded into the ID Token.

Example code to update profile and get fresh token

// Update user profile first
await firebase.auth().currentUser.updateProfile({
  displayName: "Jeff Minsung Kim",
  photoURL: "https://your-photo-url.com/avatar.jpg"
});

// Force refresh to get a token with updated profile data
const updatedIdToken = await firebase.auth().currentUser.getIdToken(true);

// Now decode this token to verify the fields are present
import jwtDecode from 'jwt-decode';
const decodedToken = jwtDecode(updatedIdToken);
console.log(decodedToken.name); // Should display your displayName
console.log(decodedToken.picture); // Should display your photoURL

2. Why the re-login token is longer

This is totally normal! Here's why:

  • The initial post-registration token likely only contains basic auth claims (like uid, email, exp). When you log back in after a full logout, Firebase might be including additional claims in the token—this could be custom claims you've set for the user, or extra data from your authentication provider (if you're using Google/Facebook login, for example).
  • To see exactly what's adding to the length, decode both tokens using a JWT decoder (like the jwt-decode library I mentioned earlier) and compare their payloads side by side. You'll spot the extra fields right away.

Quick recap

  • Fix missing profile data: Force a token refresh with getIdToken(true) after updating the user's profile.
  • Longer re-login token: It's just carrying more auth-related data—decode it to confirm the extra claims.

内容的提问来源于stack exchange,提问作者JeffMinsungKim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:37:00