You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

生成Access Token时触发未授权错误,GCP多账号权限配置咨询

Fixing "Unauthorized Error" When Generating Access Token for a New GCP User

Hey there, let's walk through how to resolve this permission issue you're facing with your new GCP user. Since your main account has the Owner role, the problem almost always boils down to incorrect role assignments, misconfigured OAuth settings, or mismatched scopes in your token request. Here's what to check step by step:

1. Verify the New User's IAM Role Assignments

First, double-check that the new user has the right permissions to perform the actions you need (like accessing Cloud Storage, training ML models, etc.):

  • Head to the GCP Console's IAM & Admin > IAM page, find the new user, and review their assigned roles.
  • If they need full access similar to your Owner account, assigning the Editor role might suffice, but for better security, use granular roles:
    • For Cloud Bucket operations: roles/storage.admin or roles/storage.bucketCreator + roles/storage.objectCreator
    • For ML model training: roles/ml.admin or roles/ml.jobUser
    • For general Google APIs access: Ensure they have a role that supports the https://www.googleapis.com/auth/cloud-platform scope (most administrative roles do this)
  • Also, confirm that all required APIs (Cloud Storage API, AI Platform Training API, etc.) are enabled in your GCP project—disabled APIs will throw unauthorized errors even with the right roles.

If you're generating tokens via your Android app's Google Sign-In, make sure these settings are correct:

  • Client ID: Ensure you're using the correct Android client ID linked to your app (not a web or other platform ID) in your GoogleSignInOptions configuration.
  • OAuth Consent Screen:
    • If your app is marked as Internal, the new user must be part of your GCP organization.
    • If it's External, add the user as a test user in the consent screen settings (under APIs & Services > OAuth consent screen) until your app is verified.
  • Requested Scopes: The scopes you request in your Android code must align with the user's IAM permissions. For example, if you're accessing Cloud Storage, include https://www.googleapis.com/auth/devstorage.read_write or the broader https://www.googleapis.com/auth/cloud-platform scope.

3. Validate Your Access Token Generation Flow

Make sure your Android code is correctly requesting the right scopes and retrieving the token properly. Here's a quick example of how to set up Google Sign-In with the necessary scopes:

// Configure Google Sign-In with required scopes
GoogleSignInOptions gso = new GoogleSignInOptions.Builder(GoogleSignInOptions.DEFAULT_SIGN_IN)
    .requestScopes(new Scope("https://www.googleapis.com/auth/cloud-platform"))
    .requestIdToken(getString(R.string.default_web_client_id)) // Use your web client ID for token exchange
    .requestEmail()
    .build();

// Initialize the sign-in client
GoogleSignInClient signInClient = GoogleSignIn.getClient(this, gso);

// After successful sign-in, retrieve the credential
GoogleSignInAccount account = GoogleSignIn.getLastSignedInAccount(this);
if (account != null) {
    String accessToken = account.getServerAuthCode(); // Or use getIdToken() depending on your use case
    // Use this token to authenticate API requests
}
  • Note: Using getServerAuthCode() lets you exchange it for a long-lived access token on your backend, while getIdToken() is for ID verification. Choose the right method based on your needs.

4. Wait for IAM Permissions to Propagate

GCP IAM changes don't always take effect immediately—sometimes it takes 5-10 minutes for permissions to roll out to all services. If you just added the user or updated their roles, wait a bit and retry generating the token.

5. Debug the Token & Error Details

To get to the root of the issue, inspect the error response closely:

  • The error message usually specifies which permission is missing (e.g., storage.buckets.create). Use this to narrow down which role you need to assign.
  • You can also generate a token via the gcloud CLI to test:
    # Log in as the new user
    gcloud auth login new-user@example.com
    # Generate access token
    gcloud auth print-access-token
    # Check token details
    curl -H "Authorization: Bearer <YOUR_TOKEN>" https://www.googleapis.com/oauth2/v3/tokeninfo
    
    This will show you the scopes associated with the token and confirm if the user's identity is correctly linked to your project.

By going through these steps, you should be able to resolve the unauthorized error and get the new user's access token working properly.

内容的提问来源于stack exchange,提问作者Shubham Shekhar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:20:48