Google Meet API服务器到服务器调用失败,寻求技术解决方案
Google Meet API服务器到服务器调用获取录制文件报错问题
问题背景
- 尝试使用最新Google Meet API获取录制文件详情,采用服务器到服务器调用方式
- 已创建具备Google Meet API访问权限的服务账号,且在Google Cloud控制台中启用了Meet API
- 使用的scope
https://www.googleapis.com/auth/meet.recordings.readonly来自Meet API官方文档,但未出现在OAuth2 scopes总列表中
实现代码
from google.oauth2 import service_account credentials = service_account.Credentials.from_service_account_file( filename='ultra-might-424911-b1-9f5cf95d5846.json', scopes=["https://www.googleapis.com/auth/meet.recordings.readonly"] # Add the required scope ) client = meet_v2.ConferenceRecordsServiceClient(credentials=credentials) request = meet_v2.GetRecordingRequest(name="xxx-xxxx-xxx") response = client.get_recording(request=request) print(response)
遇到的错误
错误1:无效Scope
google.api_core.exceptions.RetryError: Timeout of 60.0s exceeded, last exception: 503 Getting metadata from plugin failed with error: ('invalid_scope: https://www.googleapis.com/auth/meet.recordings.readonly is not a valid audience string.', {'error': 'invalid_scope', 'error_description': 'https://www.googleapis.com/auth/meet.recordings.readonly is not a valid audience string.'})
错误2:认证凭证无效
尝试JWT认证方式后出现:
"Request had invalid authentication credentials. Expected OAuth 2 access token, login cookie or other valid authentication credential. See https://developers.google.com/identity/sign-in/web/devconsole-project."
解决方案
1. 配置服务账号的域范围委派
Google Meet API的服务器到服务器调用需要通过域范围委派让服务账号模拟域内用户访问资源:
- 登录Google Workspace Admin控制台,进入「安全」>「API控制」>「域范围委派」
- 添加服务账号的客户端ID,输入scope
https://www.googleapis.com/auth/meet.recordings.readonly - 保存配置,等待配置生效(可能需要几分钟)
2. 修改代码,模拟域内用户
服务账号本身无法直接访问Meet录制资源,必须模拟一个拥有该录制访问权限的域内用户:
from google.oauth2 import service_account SCOPES = ["https://www.googleapis.com/auth/meet.recordings.readonly"] SERVICE_ACCOUNT_FILE = 'ultra-might-424911-b1-9f5cf95d5846.json' # 替换为有权限访问目标录制文件的域内用户邮箱 USER_EMAIL = 'authorized-user@your-domain.com' # 创建基础凭证 credentials = service_account.Credentials.from_service_account_file( SERVICE_ACCOUNT_FILE, scopes=SCOPES) # 委派给指定用户 delegated_credentials = credentials.with_subject(USER_EMAIL) # 初始化客户端并发起请求 client = meet_v2.ConferenceRecordsServiceClient(credentials=delegated_credentials) # 注意资源名称格式必须为 meet-recordings/{录制ID} request = meet_v2.GetRecordingRequest(name="meet-recordings/xxx-xxxx-xxx") response = client.get_recording(request=request) print(response)
3. 验证资源名称格式
GetRecordingRequest的name参数必须是完整的资源路径,格式为meet-recordings/{your-recording-id},不能仅传入录制ID。
4. 确认Scope有效性
虽然该scope未出现在OAuth2总列表中,但作为新发布的Meet API专属scope,只要在Google Workspace Admin中完成域范围委派配置,即可正常使用。若仍提示无效,可检查Google Cloud控制台中服务账号是否已关联正确的API权限。
内容的提问来源于stack exchange,提问作者viv1
相关产品推荐
相关产品推荐

