【发布时间】:2017-07-27 20:28:28
【问题描述】:
我尝试对 Google Analytics 中的服务帐户进行授权 API 调用 (HTTP/REST)。 使用此文档:https://developers.google.com/identity/protocols/OAuth2ServiceAccount
我只是使用 HTTP/REST 请求来测试。
所以我有服务帐户的私钥文件:
{
"type": "service_account",
"project_id": "test-x",
"private_key_id": "some_private_key_id",
"private_key": "-----BEGIN PRIVATE KEY----- some_private_key -----END PRIVATE KEY-----",
"client_email": "test-01@test-x.iam.gserviceaccount.com",
"client_id": "some_client_id",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://accounts.google.com/o/oauth2/token",
"auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
"client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/test-01%40test-x.iam.gserviceaccount.com"
}
我创建 JWT 基于 客户电子邮件: test-01@test-x.iam.gserviceaccount.com
标题:
{"alg":"RS256","typ":"JWT"}
声明集:
{
"iss": "test-01@test-x.iam.gserviceaccount.com",
"scope": "https://www.googleapis.com/auth/analytics.readonly",
"aud": "https://www.googleapis.com/oauth2/v4/token",
"exp": 1488820112,
"iat": 1488816522
}
iat - 我只是设置当前
exp - 当前 + 1 小时,
我使用此服务创建签名:https://jwt.io/#debugger
它生成我尝试用于访问令牌请求的编码值
当我尝试使用“编码”字段生成的结果时:
curl -d 'grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer&assertion=JWT_that_has_been_signed' https://www.googleapis.com/oauth2/v4/token
结果:
{
"error": "invalid_grant",
"error_description": "Invalid JWT Signature."
}
但我没有使用我的私钥。 根据计算签名的文档,我必须使用我的私钥。 我不完全了解如何以正确的方式使用密钥来正确计算签名。
jwt.io 已经生成了 PUBLIC 和 PRIVATE 密钥...
可能我使用 jwt.io 不正确..
请告诉我创建 JWT 的正确方法,或者可能是创建它的另一个服务。
谢谢!
【问题讨论】:
-
你找到解决办法了吗
-
我没有找到如何以这种方式弄清楚。或者,我使用了 Google Analytics API 客户端。
-
我使用了这个库npmjs.com/package/google-oauth-jwt,并且我成功获得了令牌。希望它可以帮助其他面临类似问题的人
-
我收到此错误,client_email 错误
标签: rest google-analytics oauth-2.0 jwt