You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Expo SDK刷新Google API访问令牌时遭遇未授权错误

Fixing "unauthorized_client" When Refreshing Google Access Tokens in Expo

I’ve run into this exact frustrating issue before with Expo and Google OAuth, so let’s break down the most likely fixes to get your token refresh working again:

  • Double-check your client ID and platform configuration

    • Make sure you’re using the correct client ID tied to your Expo project in the Google Cloud Console. Google assigns unique IDs for iOS, Android, and web platforms—mixing these up is a common cause of the unauthorized error.
    • Verify that your Expo app’s bundle ID (iOS) and package name (Android) match exactly what’s registered in the OAuth 2.0 Client IDs section of the console. Even a tiny typo here will block token refreshes.
  • Skip the client secret for mobile apps

    • Expo’s managed workflow uses the PKCE (Proof Key for Code Exchange) flow, which doesn’t require a client_secret in refresh requests. Including it anyway will trigger the "unauthorized_client" error. Your valid refresh request should look like this:
      POST /oauth2/v4/token HTTP/1.1
      Host: www.googleapis.com
      Content-Type: application/x-www-form-urlencoded
      
      client_id=<YOUR_CLIENT_ID>&
      refresh_token=<YOUR_REFRESH_TOKEN>&
      grant_type=refresh_token
      
  • Ensure you requested the right scope initially

    • Without including the offline_access scope when you first obtained the access token, Google won’t issue a valid refresh token. If you missed this, have users re-authenticate to get a new refresh token with the correct scope.
    • Also, check if the refresh token was revoked: Google can invalidate refresh tokens if the user revoked app access or changed their account password. Re-authenticating will generate a fresh token to test with.
  • Validate your OAuth consent and redirect settings

    • In the Google Cloud Console, go to APIs & Services > OAuth consent screen. If your app is still in testing mode, make sure the user’s email is listed in the Test users section—non-test users can’t use refresh tokens for unverified apps.
    • Confirm your Authorized redirect URIs match what Expo uses. For most Expo projects, this is something like exp://<your-expo-ngrok-url>/--/expo-auth-session or the default Expo redirect URI tied to your project ID.

If none of these work, enable debug logging in your Expo auth session to inspect the exact parameters being sent in the refresh request—sometimes a hidden extra space or misformatted value is the root cause.

内容的提问来源于stack exchange,提问作者ljmocic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:44:21