You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flutter调用Gmail API遭遇insufficient scope权限不足错误求助

解决Flutter访问Gmail API时的insufficient scope错误

问题核心:你初始化GoogleSignIn时没有请求gmail.readonly权限,导致用户登录时授予的权限不包含该scope——权限是在用户授权阶段确定的,后续在AccessCredentials里手动添加scope不会生效,因为返回的access token根本没有这个权限。

具体修复步骤

1. 初始化GoogleSignIn时指定所需scope

把原来的GoogleSignIn初始化代码改成带scopes的版本:

final GoogleSignIn _googleSignIn = GoogleSignIn(
  scopes: [
    'https://www.googleapis.com/auth/gmail.readonly',
  ],
);

这样用户登录时,Google会明确向用户请求Gmail只读权限,返回的access token才会包含该权限。

2. 清除旧的授权缓存

因为你之前已经登录过,设备上会保留旧的授权信息(没有包含gmail.readonly),需要让用户重新授权:

  • 调用await _googleSignIn.signOut()退出当前登录
  • 或者卸载重装app,清除本地缓存
  • 之后重新登录,此时会弹出包含Gmail权限的授权弹窗

3. 再次验证Google Cloud控制台配置

虽然你已经做过这些,但再确认一遍:

  • 确保Gmail API已在Google Cloud控制台中启用
  • OAuth同意屏幕的“已授权的范围”里添加了https://www.googleapis.com/auth/gmail.readonly
  • 测试用户列表里包含你用来测试的邮箱账号
  • 客户端ID的类型与你的Flutter项目平台(Android/iOS/Web)匹配

修改后的完整代码示例

final GoogleSignIn _googleSignIn = GoogleSignIn(
  scopes: [
    'https://www.googleapis.com/auth/gmail.readonly',
  ],
);

Future<void> authenticateAndFetchEmails() async {
  try {
    // 先退出旧登录(测试阶段可选,确保重新授权)
    await _googleSignIn.signOut();
    
    // Sign in the user
    final GoogleSignInAccount? googleUser = await _googleSignIn.signIn();

    // Retrieve authentication credentials
    final GoogleSignInAuthentication googleAuth = await googleUser!.authentication;

    // Use the access token for authorization
    final accessToken = googleAuth.accessToken!;
    print(accessToken);
    // Create authenticated client
    final client = authenticatedClient(
      http.Client(),
      AccessCredentials(
        AccessToken(
          'Bearer',
          accessToken,
          DateTime.now().toUtc().add(Duration(hours: 1)), // Example expiry
        ),
        googleAuth.refreshToken, // 传入refresh token,用于过期后自动刷新
        ['https://www.googleapis.com/auth/gmail.readonly'],
      ),
    );

    final gmailApi = gmail.GmailApi(client);
    final response = await gmailApi.users.messages.list('me');
    final messages = response.messages ?? [];

    for (var message in messages) {
      final msg = await gmailApi.users.messages.get('me', message.id!);
      final snippet = msg.snippet!;

      if (snippet.contains('Debit') ||
          snippet.contains('Account Name') ||
          snippet.contains('Description')) {
        print('Found email: ${msg.payload!.headers!.firstWhere((header) => header.name == 'Subject').value}');
      }
    }
  } catch (e) {
    print('Failed to authenticate or fetch emails: $e');
  }
}

内容的提问来源于stack exchange,提问作者Alexander Osuya Sty

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 18:50:14