You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Heroku上安全使用Google服务账号调用Cloud Vision API?

Secure Google Cloud Vision Authentication on Heroku (Node.js)

Absolutely! You don’t need to upload your service account key file directly to Heroku or commit it to your repo—there are two secure, practical ways to handle authentication, both keeping your credentials safe.

This approach avoids file handling entirely and is the cleanest option:

  • First, open your Google Cloud service account JSON key file, select all the content, and copy it.
  • Go to your Heroku app’s dashboard, navigate to Settings > Config Vars, and add a new variable. Name it something like GOOGLE_APPLICATION_CREDENTIALS_JSON, then paste the full JSON content as its value.
  • In your Node.js code, instead of relying on a file path, parse the environment variable and pass the credentials directly to the Vision client:
const { ImageAnnotatorClient } = require('@google-cloud/vision');

// Parse the JSON from the environment variable
const googleCredentials = JSON.parse(process.env.GOOGLE_APPLICATION_CREDENTIALS_JSON);
const visionClient = new ImageAnnotatorClient({ credentials: googleCredentials });

The Google Cloud SDK will use these credentials directly, no file required.

Alternative: Generate a Temporary Key File at Startup

If your codebase relies on the GOOGLE_APPLICATION_CREDENTIALS environment variable pointing to a file, you can dynamically create a temporary file when your app starts (Heroku’s filesystem is ephemeral, but this works because the file is recreated on each dyno restart):

  • Add your full service account JSON content to a Heroku Config Var (e.g., GOOGLE_SERVICE_ACCOUNT_JSON).
  • In your app’s entry file, write the JSON content to a temporary file and set the required environment variable before initializing the Vision client:
const fs = require('fs');
const path = require('path');
const { ImageAnnotatorClient } = require('@google-cloud/vision');

// Create a temporary file path in your app directory
const tempKeyFilePath = path.join(__dirname, 'temp-gcp-key.json');

// Write the JSON content from the environment variable to the file
fs.writeFileSync(tempKeyFilePath, process.env.GOOGLE_SERVICE_ACCOUNT_JSON);

// Set the Google Cloud SDK's required environment variable
process.env.GOOGLE_APPLICATION_CREDENTIALS = tempKeyFilePath;

// Now initialize the client normally
const visionClient = new ImageAnnotatorClient();

Critical Notes

  • Never commit your service account JSON file to Git: Always use Heroku Config Vars for sensitive credentials.
  • The first method is preferred: It’s simpler, faster, and eliminates the need for file I/O operations.
  • Double-check your JSON content in Config Vars: Make sure there are no missing brackets or syntax errors when pasting.

内容的提问来源于stack exchange,提问作者tputkonen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 07:57:28