You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel中Apple Sign-In验证失败,报invalid_client错误求助

Laravel中Apple Sign-In验证失败,报invalid_client错误求助

我正在Laravel项目里做Apple Sign-In的验证,但一直卡着报错,有没有大佬能帮忙排查下问题?我还准备了打码后的Key ID和Service ID截图。

返回的错误信息如下:

{success: false, message: Failed to verify with Apple, error: {error: invalid_client}}

我的.env配置内容:

APPLE_CLIENT_ID=com.example.apple
APPLE_TEAM_ID=NR88888888
APPLE_KEY_ID=RJ85222222

下面是我处理Apple登录的函数(因为StackOverflow的内容限制,只能贴出部分代码):

function loginWithApple(Request $request) 
{
    try 
    {
        $authCode = $request->input('apple_authorization_code');
        if (empty($authCode)) 
        {
            return response()->json([
                'success' => false,
                'message' => 'Authorization code is required'
            ], 400);
        }

        // Load and validate private key file
        $path = storage_path('appleKeys/applePrivateKey/AuthKey_RJ85222222.p8');
        if (!file_exists($path)) 
        {
            Log::error('Apple Login: Private key file not found', ['path' => $path]);
            throw new \Exception('Apple private key file not found at: ' . $path);
        }

        $privateKeyContent = file_get_contents($path);
        if (!$privateKeyContent) 
        {
            Log::error('Apple Login: Failed to read private key file');
            throw new \Exception('Failed to read private key file');
        }

        // Ensure private key format
        $privateKey = openssl_pkey_get_private($privateKeyContent);
        if (!$privateKey) 
        {
            Log::error('Apple Login: Invalid private key format', [
                'openssl_error' => openssl_error_string()
            ]);
            throw new \Exception('Invalid private key format: ' . openssl_error_string());
        }

        // Generate client secret (JWT)
        $timestamp = time();
        $header = [
            'alg' => 'ES256',
            'kid' => env('APPLE_KEY_ID')
        ];
        
        $payload = [
            'iss' => env('APPLE_TEAM_ID'),
            'iat' => $timestamp,
            'exp' => $timestamp + 86400 * 180, // 180 days
            'aud' => 'https://appleid.apple.com',
            'sub' => env('APPLE_CLIENT_ID'),
        ];

        // Base64Url encode header and payload
        $base64Header = rtrim(strtr(base64_encode(json_encode($header)), '+/', '-_'), '=');
        $base64Payload = rtrim(strtr(base64_encode(json_encode($payload)), '+/', '-_'), '=');

        // Create signature
        $signature = '';
        if (!openssl_sign(
            $base64Header . '.' . $base64Payload,
            $signature,
            $privateKey,
            OPENSSL_ALGO_SHA256
        )) {
            Log::error('Apple Login: Failed to create signature', [
                'openssl_error' => openssl_error_string()
            ]);
            throw new \Exception('Failed to create signature: ' . openssl_error_string());
        }

        $base64Signature = rtrim(strtr(base64_encode($signature), '+/', '-_'), '=');
        $clientSecret = $base64Header . '.' . $base64Payload . '.' . $base64Signature;

        // Send request to Apple for token
        $requestData = [
            'client_id' => env('APPLE_CLIENT_ID'),
            'client_secret' => $clientSecret,
            'code' => $authCode,
            'grant_type' => 'authorization_code'
        ];

        Log::debug('Apple Login: Sending request to Apple', [
            'url' => 'https://appleid.apple.com/auth/token',
            'client_id' => env('APPLE_CLIENT_ID'),
            'code' => $authCode,
            'code_length' => strlen($authCode),
        ]);

        // $response = Http::asForm()->post('https://appleid.apple.com/auth/token', $requestData);
        $response = Http::withHeaders([
            'Content-Type' => 'application/x-www-form-urlencoded'
        ])->post('https://appleid.apple.com/auth/token', $requestData);

        if (!$response->successful()) 
        {
            Log::error('Apple Login: Failed response from Apple', [
                'status' => $response->status(),
                'error' => $response->json(),
            ]);
            return response()->json([
                'success' => false,
                'message' => 'Failed to verify with Apple',
                'error' => $response->json()
            ], 400);
        }

        $data = $response->json();
        $idToken = $data['id_token'];
        $tokenParts = explode('.', $idToken);
        
        if (count($tokenParts) != 3) {
            return response()->json([
                'success' => false,
                'message' => 'Invalid token format'
            ], 400);
        }
    } 
    catch (\Exception $e) 
    {
        Log::error('Apple Sign In Error', [
            'error' => $e->getMessage(),
            'trace' => $e->getTraceAsString()
        ]);       
    }
}

Key ID截图:
Key ID

Service ID截图:
Service ID

备注:内容来源于stack exchange,提问作者Zeone line

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.15 08:53:02