使用Expo SDK刷新Google API访问令牌时遭遇未授权错误
I’ve run into this exact frustrating issue before with Expo and Google OAuth, so let’s break down the most likely fixes to get your token refresh working again:
Double-check your client ID and platform configuration
- Make sure you’re using the correct client ID tied to your Expo project in the Google Cloud Console. Google assigns unique IDs for iOS, Android, and web platforms—mixing these up is a common cause of the unauthorized error.
- Verify that your Expo app’s bundle ID (iOS) and package name (Android) match exactly what’s registered in the OAuth 2.0 Client IDs section of the console. Even a tiny typo here will block token refreshes.
Skip the client secret for mobile apps
- Expo’s managed workflow uses the PKCE (Proof Key for Code Exchange) flow, which doesn’t require a
client_secretin refresh requests. Including it anyway will trigger the "unauthorized_client" error. Your valid refresh request should look like this:POST /oauth2/v4/token HTTP/1.1 Host: www.googleapis.com Content-Type: application/x-www-form-urlencoded client_id=<YOUR_CLIENT_ID>& refresh_token=<YOUR_REFRESH_TOKEN>& grant_type=refresh_token
- Expo’s managed workflow uses the PKCE (Proof Key for Code Exchange) flow, which doesn’t require a
Ensure you requested the right scope initially
- Without including the
offline_accessscope when you first obtained the access token, Google won’t issue a valid refresh token. If you missed this, have users re-authenticate to get a new refresh token with the correct scope. - Also, check if the refresh token was revoked: Google can invalidate refresh tokens if the user revoked app access or changed their account password. Re-authenticating will generate a fresh token to test with.
- Without including the
Validate your OAuth consent and redirect settings
- In the Google Cloud Console, go to APIs & Services > OAuth consent screen. If your app is still in testing mode, make sure the user’s email is listed in the Test users section—non-test users can’t use refresh tokens for unverified apps.
- Confirm your Authorized redirect URIs match what Expo uses. For most Expo projects, this is something like
exp://<your-expo-ngrok-url>/--/expo-auth-sessionor the default Expo redirect URI tied to your project ID.
If none of these work, enable debug logging in your Expo auth session to inspect the exact parameters being sent in the refresh request—sometimes a hidden extra space or misformatted value is the root cause.
内容的提问来源于stack exchange,提问作者ljmocic
相关产品推荐
相关产品推荐

