You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud API 403权限不足 Play Console报表拉取报错

Google Play Console 报表自动下载报错修复方案

问题背景

需要从Google Play Console提取自有移动应用的报表数据。根据官方文档说明,原本需使用SignedJwtAssertionCredentials完成身份认证,但实测文档提供的代码片段已过时,SignedJWTAssertionCredentials当前已不可用,最初实现代码如下:

from oauth2client.service_account import  ServiceAccountCredentials
from apiclient.discovery import build

scopes = ['https://www.googleapis.com/auth/analytics.readonly']
key_file_location = 'files/access_token/mykeyfile.json'

credentials = ServiceAccountCredentials.from_json_keyfile_name(key_file_location, scopes)

cloud_storage_bucket = 'pubsite_prod_rev_123456789'
report_to_download = 'installs/installs_com.someapp.etc.etc_2021*'

storage = build('storage', 'v1', credentials=credentials)

print( storage.objects().get(bucket = cloud_storage_bucket,object = report_to_download).execute())

运行代码后首先抛出403权限不足报错:

googleapiclient.errors.HttpError: <HttpError 403 when requesting https://storage.googleapis.com/storage/v1/b/pubsite_prod_rev_123456789/o/installs%2Finstalls_com.someapp.etc.etc_2021%2A?alt=json returned "Insufficient Permission". Details: "[{'message': 'Insufficient Permission', 'domain': 'global', 'reason': 'insufficientPermissions'}]">

此时服务账号已在Play Console中被授予管理员权限,仍报权限错误。后续补充scope配置时,因代码书写问题和依赖问题,又抛出KeyError: 'access_token'报错。

错误根因

  • 403权限不足:初始配置的scope完全错误,仅配置了Google Analytics只读权限,没有配置访问Google Cloud Storage的权限——Play Console的所有报表实际都存储在GCS专属桶中,API鉴权时scope不匹配,哪怕服务账号在Play Console有管理员权限也会被拦截。
  • access_token缺失报错:一是使用的oauth2client库已废弃多年,和当前Google OAuth2接口的返回格式不兼容,无法正确解析令牌;二是补充scope时代码语法错误,scope列表被拆到代码块外,配置未生效。
  • 隐藏逻辑错误:代码中用通配符*拼接对象路径直接调用objects().get(),GCS对象接口是精确匹配,不支持通配符匹配,就算权限校验通过也会报资源不存在错误。

修复步骤

  1. 替换废弃依赖
    卸载已停止维护的旧依赖,安装Google官方当前维护的SDK包:
    pip uninstall oauth2client
    pip install google-auth google-auth-httplib2 google-api-python-client
    
  2. 修正权限scope配置
    访问Play Console报表不需要Analytics、云平台全量只读权限,仅需GCS只读权限即可:
    SCOPES = ['https://www.googleapis.com/auth/devstorage.read_only']
    
  3. 修正文件匹配逻辑
    先调用GCS列表接口按前缀筛选匹配的报表文件,再执行下载操作,不要直接用通配符调用get接口。

可运行参考代码

from google.oauth2 import service_account
from googleapiclient.discovery import build

# 配置项
KEY_FILE_LOCATION = 'files/access_token/mykeyfile.json'
CLOUD_STORAGE_BUCKET = 'pubsite_prod_rev_123456789'
# 要匹配的报表路径前缀,不需要加通配符
REPORT_PREFIX = 'installs/installs_com.someapp.etc.etc_2021'

# 初始化认证与客户端
credentials = service_account.Credentials.from_service_account_file(
    KEY_FILE_LOCATION, scopes=SCOPES
)
storage = build('storage', 'v1', credentials=credentials)

# 拉取匹配前缀的所有报表文件
request = storage.objects().list(bucket=CLOUD_STORAGE_BUCKET, prefix=REPORT_PREFIX)
response = request.execute()
file_list = response.get('items', [])

if not file_list:
    print("未找到匹配的报表文件,请检查桶名、路径前缀和服务账号权限")
else:
    for file_obj in file_list:
        file_name = file_obj['name']
        print(f"正在下载报表:{file_name}")
        # 获取文件内容
        content = storage.objects().get_media(bucket=CLOUD_STORAGE_BUCKET, object=file_name).execute()
        # 写入本地文件
        local_file_name = file_name.split('/')[-1]
        with open(local_file_name, 'wb') as f:
            f.write(content)

补充注意事项

  • 确认服务账号已被添加到Play Console的用户列表中,拥有查看报表的对应权限即可,无需授予管理员权限。
  • 桶名中pubsite_prod_rev_后的数字为你的Play开发者账号ID,需核对准确,不要直接复制示例值。
  • 如果是首次添加服务账号到Play Console,权限生效可能有5-10分钟延迟,等待后再测试即可。

内容的提问来源于stack exchange,提问作者Aquen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.29 22:46:03