启用Google Keep API是否需Google Workspace账号?遇invalid scope错误求助
问题解决:Google Keep API "invalid scope" 错误及权限说明
核心结论
Google Keep API仅对Google Workspace(原G Suite)账号开放,个人Google账号无法调用该API,这就是你遇到"invalid scope"错误的根本原因。其他如Drive API对个人账号开放,所以你的代码能正常运行。
代码相关说明
你的.NET Core 3.1 MVC代码本身没有问题,KeepService.ScopeConstants.Keep这个权限范围是正确的,但因为个人账号无权限使用Keep API,Google OAuth服务器会直接拒绝该范围的申请,返回无效范围错误。
你提供的代码如下:
using Microsoft.AspNetCore.Mvc; using Microsoft.Extensions.Logging; using System; using System.Collections.Generic; using System.Diagnostics; using System.Linq; using System.Threading.Tasks; using test_coremvc.Models; using Google.Apis.Auth.AspNetCore3; using Google.Apis.Auth.OAuth2; using Google.Apis.Drive.v3; using Google.Apis.Services; using Google.Apis.Keep.v1; namespace test_coremvc.Controllers { public class HomeController : Controller { private readonly ILogger<HomeController> _logger; public HomeController(ILogger<HomeController> logger) { _logger = logger; } public IActionResult Index() { return View(); } public IActionResult Privacy() { return View(); } [ResponseCache(Duration = 0, Location = ResponseCacheLocation.None, NoStore = true)] public IActionResult Error() { return View(new ErrorViewModel { RequestId = Activity.Current?.Id ?? HttpContext.TraceIdentifier }); } [GoogleScopedAuthorize(KeepService.ScopeConstants.Keep)] public async Task<IActionResult> KeepFileList([FromServices] IGoogleAuthProvider auth) { GoogleCredential cred = await auth.GetCredentialAsync(); var service = new KeepService(new BaseClientService.Initializer { HttpClientInitializer = cred }); //var files = await service.Files.List().ExecuteAsync(); //var fileNames = files.Files.Select(x => x.Name).ToList(); return View(); } } }
后续测试建议
如果要继续开发Keep相关功能,你需要:
- 使用Google Workspace账号
- 在Google Workspace管理员控制台中启用Keep API的访问权限
- 在Google Cloud控制台为你的项目启用Keep API,并完成OAuth同意屏幕的配置(Workspace账号的OAuth配置需确保权限范围被管理员允许)
内容的提问来源于stack exchange,提问作者Luca HO
相关产品推荐
相关产品推荐

