使用服务账号调用Google Reseller API遇权限不足问题求助
Google Reseller API 服务账号权限不足问题排查
问题详情
尝试通过服务账号密钥访问Google Reseller API获取客户和订阅信息,调用失败。代码片段:
async function runSample() { const auth = new google.auth.GoogleAuth({ keyFile: "../server/credentials/serviceAccountKey.json", scopes: ["https://www.googleapis.com/auth/apps.order", "https://www.googleapis.com/auth/apps.order.readonly" ], }); // Acquire an auth client, and bind it to all future calls const authClient = await auth.getClient(); google.options({ auth: authClient }); // Do the magic const res = await reseller.subscriptions.list(); console.log(res.data); } runSample().catch(console.error);
调用返回权限不足错误:
errors: [ { message: 'Authenticated user is not authorized to perform this action.', domain: 'global', reason: 'insufficientPermissions' } ]
补充信息:同一服务账号可正常访问Cloud Channel Service API,已为该账号分配所有者、Cloud Workstation Admin、ServiceAccount Admin角色,且已在域范围委派(DWD)中添加所需范围。
解决方案
将服务账号添加为经销商控制台管理员
Reseller API的权限不依赖GCP IAM角色,必须在Google经销商控制台中授权服务账号为经销商管理员:- 登录经销商控制台,进入「设置」>「用户和权限」
- 添加服务账号的邮箱地址,分配「经销商管理员」角色
在代码中模拟经销商管理员用户
服务账号调用Reseller API时需模拟拥有经销商权限的域用户,而非使用自身身份。修改GoogleAuth配置,添加subject参数:const auth = new google.auth.GoogleAuth({ keyFile: "../server/credentials/serviceAccountKey.json", scopes: ["https://www.googleapis.com/auth/apps.order", "https://www.googleapis.com/auth/apps.order.readonly" ], subject: "dealer-admin@your-domain.com" // 替换为实际经销商管理员邮箱 });注意:该邮箱用户必须已在经销商控制台中获得管理员权限。
确认Reseller API已启用
在GCP项目中搜索并启用「Google Workspace Reseller API」,确保不是仅启用了Cloud Channel API。核对域范围委派的范围配置
确认DWD中添加的范围与代码中使用的完全一致,无拼写或格式错误。
内容的提问来源于stack exchange,提问作者Kishan Prajapati
相关产品推荐
相关产品推荐

