无法通过C# .NET的Google Admin SDK获取API客户端及OAuth scopes
关于获取Google Admin Console域范围委托客户端及OAuth Scopes的方案
Google Admin SDK没有直接提供专门的API端点来获取Admin Console中Security > API Controls > Domain-wide Delegation页面下的API客户端列表及关联的OAuth scopes。不过有两个可行的替代方案:
方案1:使用Google Cloud Identity API的oauth2Clients.list端点
这个端点可以列出域内所有已配置的OAuth客户端,包括拥有域范围权限的那些。你需要先为服务账号授予identity.oauth2Clients.list权限,然后通过C#的Google.Apis.Identity.v1 NuGet包调用。
示例代码片段:
using Google.Apis.Identity.v1; using Google.Apis.Auth.OAuth2; using System; var credential = GoogleCredential.FromFile("service-account-key.json") .CreateScoped(IdentityService.Scopes.IdentityOauth2clientsList); var service = new IdentityService(new BaseClientService.Initializer() { HttpClientInitializer = credential, ApplicationName = "Your Domain Management App" }); var request = service.Oauth2Clients.List("your-domain.com"); var response = request.Execute(); foreach (var client in response.Oauth2Clients) { Console.WriteLine($"客户端ID: {client.ClientId}"); Console.WriteLine($"关联Scopes: {string.Join(", ", client.Scopes)}"); Console.WriteLine("---"); }
方案2:使用Admin SDK Directory API的serviceAccounts.list(仅服务账号客户端)
如果你的需求只覆盖服务账号类型的客户端,可以用这个端点列出域内所有服务账号,通过返回的ServiceAccount对象获取客户端ID及关联的权限信息。但这个方法无法获取非服务账号类型的OAuth客户端。
注意事项
- 无论使用哪个方案,你的服务账号必须拥有Google Workspace超级管理员权限,或者被单独授予对应API的访问权限。
- 确保服务账号已完成域范围委托的配置,拥有调用对应API的权限。
内容的提问来源于stack exchange,提问作者Parth Jani
相关产品推荐
相关产品推荐

