You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Vertex AI RAG上传文件时OAuth Scope无效问题求助

排查Vertex AI RAG upload_file接口"Invalid OAuth scope or ID token audience provided"错误

核心排查方向

1. 验证OAuth Scope配置

  • 确认使用的是Vertex AI官方指定的Scope:https://www.googleapis.com/auth/cloud-platform 或 https://www.googleapis.com/auth/vertexai,不要叠加无关Scope。
  • 检查代码中是否在客户端初始化阶段明确传递了Scope,避免依赖默认的不完整Scope集合。

2. 确认服务账号权限与认证上下文

  • 验证服务账号已被授予Vertex AI User或Vertex AI Administrator角色,同时需具备Cloud Storage Object Creator/Editor权限(文件上传会关联GCS存储)。
  • 确保代码通过环境变量GOOGLE_APPLICATION_CREDENTIALS明确指定服务账号密钥文件路径,避免本地多账号认证上下文冲突。
  • 检查密钥文件是否未过期、未被吊销,且所属项目与代码中指定的GCP项目ID一致。

3. 排查ID Token受众匹配问题

  • 部分场景下,认证生成的ID Token受众(aud字段)与Vertex AI服务预期不符。可通过以下代码解码验证:
    from google.auth import default
    import jwt
    
    credentials, _ = default()
    decoded = jwt.decode(credentials.token, options={"verify_signature": False})
    print("Token audience:", decoded.get("aud"))
    
    正常情况下aud字段应为https://vertexai.googleapis.com/,若不符,可在认证时手动指定受众:
    from google.oauth2 import service_account
    
    credentials = service_account.Credentials.from_service_account_file(
        "your-service-account-key.json",
        scopes=["https://www.googleapis.com/auth/cloud-platform"],
        target_audience="https://vertexai.googleapis.com/"
    )
    

4. 检查客户端库版本

  • 升级google-cloud-vertexai和google-auth到最新稳定版本,旧版本可能存在认证逻辑bug:
    pip install --upgrade google-cloud-vertexai google-auth
    

5. 确认项目与区域一致性

  • 确保代码中指定的Vertex AI区域、GCP项目ID,与服务账号所属项目完全匹配,跨项目调用会触发权限验证失败。

补充信息请求

请提供以下内容以便进一步定位:

  • 代码中认证初始化和rag.upload_file调用的完整片段
  • 完整的错误堆栈日志(包含所有上下文信息)

内容的提问来源于stack exchange,提问作者Shivam Sahil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 21:17:34