You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

作为Google Workspace管理员获取用户邮件时遇403错误求助

解决Gmail API服务账号域级授权的403错误

问题背景

作为Google Workspace管理员,已完成以下操作但调用Gmail API时出现403错误:

  • 在GCP控制台创建项目并启用Gmail API
  • 创建服务账号并下载密钥JSON文件
  • 在Google Workspace Admin控制台配置域级授权,添加服务账号Client ID及https://www.googleapis.com/auth/gmail.readonly权限

执行Python代码时,凭证正常输出,但调用users().messages().list(userId='me')返回403错误:

return (<HttpError 403 when requesting https://gmail.googleapis.com/gmail/v1/users/me/profile?alt=json
)

错误原因

服务账号本身不具备Gmail邮箱身份,无法直接用userId='me'访问资源。必须通过域级授权模拟域内具体用户,才能以该用户身份访问其邮箱数据。

解决方案

1. 修改凭证创建逻辑,添加用户模拟

在创建服务账号凭证后,调用with_subject()方法指定要访问的域内用户邮箱(需为Workspace域下的有效账号)。

2. 修正API调用的userId参数

可直接使用目标用户邮箱,或在模拟用户后使用'me'(此时me指代被模拟的用户)。

修改后的完整代码示例

from googleapiclient.discovery import build
from google.oauth2 import service_account
import json

# 授权范围保持不变
SCOPES = ['https://www.googleapis.com/auth/gmail.readonly']
# 指定要模拟的域内用户邮箱
TARGET_USER_EMAIL = 'user@your-domain.com'

# 加载服务账号密钥
with open("C:/Python310/mailchecking01-d253ce85770d.json") as f:
    service_account_info = json.load(f)

# 创建凭证并模拟目标用户
creds = service_account.Credentials.from_service_account_file(
    "C:/Python310/mailchecking01-d253ce85770d.json", 
    scopes=SCOPES
).with_subject(TARGET_USER_EMAIL)

# 构建Gmail服务
service = build('gmail', 'v1', credentials=creds)

try:
    # 使用目标用户邮箱或'me'作为userId
    results = service.users().messages().list(userId=TARGET_USER_EMAIL).execute()
    print('成功获取邮件列表:')
    print(results)
except Exception as e:
    print('获取邮件列表失败,错误信息:')
    print(e)

额外检查项

  • 确认Google Workspace Admin控制台的域级授权中,服务账号的Client ID已正确添加,且授权范围包含https://www.googleapis.com/auth/gmail.readonly
  • 确保被模拟的用户账号状态正常,无权限限制
  • 移除代码中未使用的导入(如gmail_connector相关模块),避免不必要的依赖问题

内容的提问来源于stack exchange,提问作者Ramzi Missaoui

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 00:55:06