You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何查看Google API凭据关联的权限范围?Earth Engine服务账号排查

问题描述

我正在使用Google Earth Engine(GEE)运行GIS计算,近期Google新增了项目管理已创建资产的功能,因此需要通过Google Cloud API找回项目名称。使用服务账号连接API时无法访问项目列表,但已确认给该账号添加了https://www.googleapis.com/auth/cloudplatformprojects.readonly权限范围。想了解是否可以通过API查看当前凭据的权限范围列表,测试代码如下:

import ee 

ee.Initialize() 

# 这是我想要测试的凭据
# 它是与其他Google API(我也用它连接Drive)类似的ServiceAccountCredential
cred = ee.Credentials()

# 类似这样的操作
for scope in cred.scopes(): 
    print(scope)
解决方案

查看当前凭据的权限范围

直接调用ee.Credentials()获取的对象没有scopes()方法,需要获取底层的OAuth2凭据实例才能查看权限范围,修改后的测试代码如下:

import ee
from google.auth.transport.requests import Request

ee.Initialize()

# 获取GEE当前使用的凭据
cred = ee.ServiceAccountCredentials._get_credentials()

# 刷新凭据以确保获取最新权限范围
if not cred.valid:
    cred.refresh(Request())

# 打印所有权限范围
if hasattr(cred, 'scopes'):
    for scope in cred.scopes:
        print(scope)
else:
    print("当前凭据未包含权限范围信息")

额外注意事项

  1. 若通过服务账号密钥文件初始化GEE,可在初始化时指定明确的权限范围,之后直接查看:
import ee

# 用服务账号密钥文件初始化并指定权限范围
credentials = ee.ServiceAccountCredentials(
    'your-service-account@project.iam.gserviceaccount.com',
    'path/to/key.json',
    scopes=['https://www.googleapis.com/auth/cloudplatformprojects.readonly', 'https://www.googleapis.com/auth/earthengine']
)
ee.Initialize(credentials)

# 查看已配置的权限范围
print(credentials.scopes)
  1. 若仍无法访问项目列表,除了确认权限范围,还要检查服务账号是否在Google Cloud项目中被授予Project Viewer(或更高等级)的IAM角色——仅配置权限范围不足以获取项目访问权限,必须同时配置对应的IAM角色。

内容的提问来源于stack exchange,提问作者Pierrick Rambaud

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.26 02:15:39