Google Create Enterprise获取注册URL请求403错误(未注册为MDM)
解决Android Enterprise API调用返回"forbiddenNotAnMdm"错误的问题
这个403错误其实很好理解——你的Google Cloud项目还没完成Android Enterprise官方的MDM提供商注册,虽然你用的认证和权限在Android Management API里能正常运行,但Android Enterprise API对调用方有更严格的身份要求。
为什么会有这个差异?
Android Management API是Google推出的简化版设备管理接口,它不需要你单独注册为MDM提供商,只要项目启用了API、权限配置正确就能调用。但你现在用的androidenterprise/v1/enterprises/signupUrl属于更底层的Android Enterprise API,这个接口只对Google官方认可的MDM解决方案提供商开放。
怎么解决?
给你两个实用方向:
- 优先推荐:直接复用已验证的Android Management API
既然https://content-androidmanagement.googleapis.com/v1/signupUrls能正常工作,完全可以基于这个接口实现创建企业的流程,它已经封装了和Android Enterprise对接的全部逻辑,不需要你再走复杂的MDM注册流程。 - 如果必须使用Android Enterprise API
那你得完成MDM提供商的官方注册:- 先确认你的Google Cloud项目已经启用了Android Enterprise API;
- 提交你的MDM解决方案信息到Google官方的Android Enterprise MDM注册通道,等待审核通过。只有审核通过后,你的项目才能调用这类需要MDM身份的接口。
附你的调用代码和错误响应
调用代码
error_reporting(0); $projectId = "api-7288506515928753288-19357"; $callbackUrl = url('emm/create/enterprise'); $callbackUrl = str_replace('http://', 'https://', $callbackUrl); $authFile = storage_path('app/key/dv-505f70dd1be9.json'); putenv("GOOGLE_APPLICATION_CREDENTIALS={$authFile}"); $client = new Google_Client(); $client->useApplicationDefaultCredentials(); $client->addScope('https://www.googleapis.com/auth/androidenterprise'); // returns a Guzzle HTTP Client $httpClient = $client->authorize(); $response = $httpClient->post("https://www.googleapis.com/androidenterprise/v1/enterprises/signupUrl?callbackUrl={$callbackUrl}"); $response = json_decode( $response->getBody()->getContents() ); // $request->session()->put('signupUrlName', $response->name); // $request->session()->put('signupUrl', $response->url); return json_encode( $response );
错误响应
{ "error": { "errors": [ { "domain": "androidenterprise", "reason": "forbiddenNotAnMdm", "message": "The caller is not registered as an MDM." } ], "code": 403, "message": "The caller is not registered as an MDM." } }
内容的提问来源于stack exchange,提问作者Divyesh
相关产品推荐
相关产品推荐

