本地主机通过clasp运行GAS遇权限问题:已配置oauthScopes仍无法调用UrlFetchApp.fetch
UrlFetchApp.fetch Permission Error with clasp run Hey there, let's break down why you're still hitting that permission error even after adding the script.external_request scope to your manifest. Here are the most likely fixes to try:
1. Your Execution API access is too restrictive
Looking at your manifest, the executionApi.access is set to "DOMAIN". This restricts API execution exclusively to users within your Google Workspace domain. When you run clasp run, it uses your personal authenticated account—if that account isn't part of the specified domain (or if this is a standalone script not tied to a Workspace domain), this setting will block the execution entirely.
To fix this, update the executionApi.access value to match your use case:
- If you're the only one running the script, use
"ANYONE"(allows any authenticated user with access to the script to execute it) - For public access (not recommended for sensitive scripts), use
"ANYONE_ANONYMOUS"
Here's the adjusted manifest snippet:
{ "timeZone": "Asia/Tokyo", "dependencies": {}, "oauthScopes": [ "https://www.googleapis.com/auth/script.external_request" ], "exceptionLogging": "STACKDRIVER", "runtimeVersion": "V8", "executionApi": { "access": "ANYONE" } }
2. Sync your manifest changes and re-deploy
After updating the manifest, you need to ensure the changes are pushed to Google's servers and the script is re-deployed for the Execution API:
- Run
clasp pushto sync your local manifest with the cloud version - Then run
clasp deployto create a new deployment (or update an existing one) that includes the updated permissions
3. Refresh your OAuth credentials
Your existing clasp OAuth token might not have the new script.external_request scope attached. To refresh this:
- Run
clasp logoutto revoke the current token - Then run
clasp loginand follow the prompts to re-authenticate—this will generate a new token that includes all scopes declared in your manifest
4. Verify script ownership and access
Double-check that you're logged into clasp with the same Google account that owns the script. If the script was shared with you, make sure you have edit permissions (not just view) to modify and deploy it.
After trying these steps, run clasp run again—it should now have the necessary permissions to call UrlFetchApp.fetch.
内容的提问来源于stack exchange,提问作者Takehiko Esaka

