You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ADC调用Google Admin Directory Group API时遇insufficient_scope错误

Google Workspace ADC调用Group API出现insufficient_scope错误排查

问题概述

作为Google Workspace超级管理员,使用应用默认凭据(ADC)调用Admin Directory Group API时触发insufficient_scope权限错误,但调用Admin Directory User API可正常执行。

调用Group API的代码

const {google} = require('googleapis');

async function main () {
    const auth = new google.auth.GoogleAuth({
        scopes: [
            'https://www.googleapis.com/auth/cloud-platform',
            'https://www.googleapis.com/auth/admin.directory.group',
            'https://www.googleapis.com/auth/admin.directory.user'
        ],
    });
    const service = await google.admin({version: 'directory_v1', auth});
    const res = await service.members.list({
        groupKey: 'my-group@my-domain'
    }).then(
        res => console.log(res.data)
    )
    console.log(res.data.members);
}

main().catch(console.error);

错误信息

GaxiosError: Insufficient Permission
    at Gaxios._request (/Users/kumar.gaurav/Documents/work/my-project/node_modules/gaxios/build/src/gaxios.js:130:23)
    at process.processTicksAndRejections (node:internal/process/task_queues:95:5)
    at async UserRefreshClient.requestAsync (/Users/kumar.gaurav/Documents/work/my-project/node_modules/google-auth-library/build/src/auth/oauth2client.js:382:18)
    at async main (/Users/kumar.gaurav/Documents/work/my-project/test-adc.js:28:17) {
  response: {
    config: {
      url: 'https://admin.googleapis.com/admin/directory/v1/groups/my-group%40my-domain/members',
      method: 'GET',
      userAgentDirectives: [Array],
      paramsSerializer: [Function (anonymous)],
      headers: [Object],
      params: {},
      validateStatus: [Function (anonymous)],
      retry: true,
      responseType: 'json',
      retryConfig: [Object]
    },
    data: { error: [Object] },
    headers: {
      'cache-control': 'private',
      connection: 'close',
      'content-encoding': 'gzip',
      'content-type': 'application/json; charset=UTF-8',
      date: 'Thu, 29 Dec 2022 12:35:44 GMT',
      server: 'ESF',
      'transfer-encoding': 'chunked',
      vary: 'Origin, X-Origin, Referer',
      'www-authenticate': 'Bearer realm="https://accounts.google.com/", error="insufficient_scope", scope="https://apps-apis.google.com/a/feeds/groups/ https://www.googleapis.com/auth/admin.directory.group https://www.googleapis.com/auth/directory.group https://www.googleapis.com/auth/admin.directory.group.member https://www.googleapis.com/auth/admin.directory.group.member.readonly https://www.googleapis.com/auth/apps.directory.group.member.readonly https://www.googleapis.com/auth/directory.group.member.readonly https://www.googleapis.com/auth/admin.directory.group.readonly https://www.googleapis.com/auth/apps.directory.group.readonly https://www.googleapis.com/auth/directory.group.readonly"',
      'x-content-type-options': 'nosniff',
      'x-frame-options': 'SAMEORIGIN',
      'x-xss-protection': '0'
    },
    status: 403,
    statusText: 'Forbidden',
    request: {
      responseURL: 'https://admin.googleapis.com/admin/directory/v1/groups/my-group%40my-domain/members'
    }
  },
  config: {
    url: 'https://admin.googleapis.com/admin/directory/v1/groups/my-group%40my-domain/members',
    method: 'GET',
    userAgentDirectives: [ [Object] ],
    paramsSerializer: [Function (anonymous)],
    headers: {
      'x-goog-api-client': 'gdcl/6.0.4 gl-node/18.4.0 auth/8.7.0',
      'Accept-Encoding': 'gzip',
      'User-Agent': 'google-api-nodejs-client/6.0.4 (gzip)',
      Authorization: 'Bearer ya29.someToken',
      Accept: 'application/json'
    },
    params: {},
    validateStatus: [Function (anonymous)],
    retry: true,
    responseType: 'json',
    retryConfig: {
      currentRetryAttempt: 0,
      retry: 3,
      httpMethodsToRetry: [Array],
      noResponseRetries: 2,
      statusCodesToRetry: [Array]
    }
  },
  code: 403,
  errors: [
    {
      message: 'Insufficient Permission',
      domain: 'global',
      reason: 'insufficientPermissions'
    }
  ]
}

ADC配置文件内容 (~/.config/gcloud/application_default_credentials.json)

{
  "client_id": "someClientId.apps.googleusercontent.com",
  "client_secret": "someClientSecret",
  "refresh_token": "someRefreshToken",
  "type": "authorized_user"
}

可正常运行的User API代码

// works
const res = await service.users.list({
    customer: 'my_customer',
    maxResults: 10,
    orderBy: 'email',
});

console.log(res.data.members);

问题原因及解决方案

核心原因

你的ADC类型是authorized_user(用户凭据),这类凭据的权限范围由首次生成凭据时授权请求的范围决定,而非直接继承Workspace管理员的所有权限。虽然你是管理员,但当初生成ADC时并未申请admin.directory.group相关的权限范围,导致调用Group API时令牌缺少必要权限;而User API能运行,说明授权时包含了admin.directory.user范围。

解决方案

  1. 删除现有ADC凭据:
    rm ~/.config/gcloud/application_default_credentials.json
    
  2. 重新生成带全量范围的ADC凭据:
    运行以下命令,明确指定所需的所有权限范围,确保Group相关权限被包含:
    gcloud auth application-default login --scopes=https://www.googleapis.com/auth/cloud-platform,https://www.googleapis.com/auth/admin.directory.group,https://www.googleapis.com/auth/admin.directory.user
    
  3. 验证权限范围:
    可以通过解码请求中的Bearer令牌(ya29.someToken),检查其中的scope字段是否包含https://www.googleapis.com/auth/admin.directory.group等Group相关权限,确认凭据已正确授权。

内容的提问来源于stack exchange,提问作者Kumar Gaurav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 20:45:29