AWS SNS对接APNS异常求助:推送失败且端点被禁用
Hey there, let's break down your Amazon SNS push notification issue step by step—this is a super common pain point, but totally solvable with targeted checks.
First, let's anchor on the core problem: your endpoints are getting disabled immediately after registration, which means SNS is hitting a hard validation error when trying to route notifications. Let's walk through the most likely fixes:
1. Fix Certificate/Environment Mismatches (The #1 Culprit)
This is the most frequent cause of disabled endpoints:
- For iOS (APNs):
- Double-check that your sandbox (development) certificate is linked exclusively to your SNS sandbox platform application, and your production certificate is paired with the production SNS app. Mixing these will fail every time.
- Ensure your certificates are valid (not expired) and you exported the
.p12file correctly—include the private key, and don't set a password when exporting (SNS can't handle password-protected certs).
- For Android (FCM):
- Confirm the server key in your SNS platform application matches exactly what's in the Firebase Console. Even a tiny typo here will block notifications.
2. Verify Device Token Integrity
- When your app registers with APNs/FCM, the token it receives must be sent to SNS exactly as-is. Even a single extra space or character mismatch will trigger an
InvalidTokenerror and disable the endpoint. - For iOS sandbox builds: Make sure your app is signed with a development provisioning profile (not ad-hoc or production). This ensures it's talking to the sandbox APNs environment, which aligns with your SNS sandbox endpoint.
3. Dig into CloudWatch Logs (Critical Details)
You mentioned CloudWatch has info—here's what to look for in the logs to pinpoint the issue:
Common error messages to flag:
InvalidToken: The device token is invalid for the environment (sandbox vs production) or stale (user uninstalled the app, device restored, etc.).InvalidCertificate: Your uploaded cert is corrupted, expired, or doesn't have push notification permissions enabled.PermissionError: SNS lacks the right to send to APNs/FCM. For APNs, confirm your cert allows push; for FCM, check your server key hascloudmessaging.messages.sendpermissions.
4. Validate Endpoint Creation Logic
- When calling
CreatePlatformEndpointvia the SNS API, ensure you're using the correctPlatformApplicationArnfor your environment. Accidentally using the production ARN in your debug build will instantly disable the endpoint. - Handle endpoint errors in your app: If SNS returns an
EndpointDisabledresponse, delete the old endpoint and register a new one—disabled endpoints can't be re-enabled automatically.
5. Test with a Direct SNS Publish
Isolate the issue by sending a test notification directly via the AWS CLI or Console:
aws sns publish --target-arn "arn:aws:sns:us-east-1:123456789012:endpoint/APNS_SANDBOX/MyApp/abc123" --message "Test push notification"
The CLI will return a specific error message (way more detailed than basic CloudWatch logs) that can cut straight to the problem.
6. App-Side Registration Checks
- For iOS: Confirm you're requesting push permissions correctly with
UNUserNotificationCenter.current().requestAuthorization, and only send the token to SNS after the user grants permission and the token is successfully retrieved. - For Android: Make sure your app refreshes the FCM token when the app updates or the device reboots—stale tokens are a frequent cause of disabled endpoints.
If you can share the exact CloudWatch error message, we can narrow this down even further, but these steps should cover 90% of cases where endpoints get disabled and notifications fail.
内容的提问来源于stack exchange,提问作者Ian Ferreira

