生成Access Token时触发未授权错误,GCP多账号权限配置咨询
Hey there, let's walk through how to resolve this permission issue you're facing with your new GCP user. Since your main account has the Owner role, the problem almost always boils down to incorrect role assignments, misconfigured OAuth settings, or mismatched scopes in your token request. Here's what to check step by step:
1. Verify the New User's IAM Role Assignments
First, double-check that the new user has the right permissions to perform the actions you need (like accessing Cloud Storage, training ML models, etc.):
- Head to the GCP Console's IAM & Admin > IAM page, find the new user, and review their assigned roles.
- If they need full access similar to your Owner account, assigning the
Editorrole might suffice, but for better security, use granular roles:- For Cloud Bucket operations:
roles/storage.adminorroles/storage.bucketCreator+roles/storage.objectCreator - For ML model training:
roles/ml.adminorroles/ml.jobUser - For general Google APIs access: Ensure they have a role that supports the
https://www.googleapis.com/auth/cloud-platformscope (most administrative roles do this)
- For Cloud Bucket operations:
- Also, confirm that all required APIs (Cloud Storage API, AI Platform Training API, etc.) are enabled in your GCP project—disabled APIs will throw unauthorized errors even with the right roles.
2. Check OAuth 2.0 Client & Consent Screen Configuration
If you're generating tokens via your Android app's Google Sign-In, make sure these settings are correct:
- Client ID: Ensure you're using the correct Android client ID linked to your app (not a web or other platform ID) in your
GoogleSignInOptionsconfiguration. - OAuth Consent Screen:
- If your app is marked as Internal, the new user must be part of your GCP organization.
- If it's External, add the user as a test user in the consent screen settings (under APIs & Services > OAuth consent screen) until your app is verified.
- Requested Scopes: The scopes you request in your Android code must align with the user's IAM permissions. For example, if you're accessing Cloud Storage, include
https://www.googleapis.com/auth/devstorage.read_writeor the broaderhttps://www.googleapis.com/auth/cloud-platformscope.
3. Validate Your Access Token Generation Flow
Make sure your Android code is correctly requesting the right scopes and retrieving the token properly. Here's a quick example of how to set up Google Sign-In with the necessary scopes:
// Configure Google Sign-In with required scopes GoogleSignInOptions gso = new GoogleSignInOptions.Builder(GoogleSignInOptions.DEFAULT_SIGN_IN) .requestScopes(new Scope("https://www.googleapis.com/auth/cloud-platform")) .requestIdToken(getString(R.string.default_web_client_id)) // Use your web client ID for token exchange .requestEmail() .build(); // Initialize the sign-in client GoogleSignInClient signInClient = GoogleSignIn.getClient(this, gso); // After successful sign-in, retrieve the credential GoogleSignInAccount account = GoogleSignIn.getLastSignedInAccount(this); if (account != null) { String accessToken = account.getServerAuthCode(); // Or use getIdToken() depending on your use case // Use this token to authenticate API requests }
- Note: Using
getServerAuthCode()lets you exchange it for a long-lived access token on your backend, whilegetIdToken()is for ID verification. Choose the right method based on your needs.
4. Wait for IAM Permissions to Propagate
GCP IAM changes don't always take effect immediately—sometimes it takes 5-10 minutes for permissions to roll out to all services. If you just added the user or updated their roles, wait a bit and retry generating the token.
5. Debug the Token & Error Details
To get to the root of the issue, inspect the error response closely:
- The error message usually specifies which permission is missing (e.g.,
storage.buckets.create). Use this to narrow down which role you need to assign. - You can also generate a token via the
gcloudCLI to test:
This will show you the scopes associated with the token and confirm if the user's identity is correctly linked to your project.# Log in as the new user gcloud auth login new-user@example.com # Generate access token gcloud auth print-access-token # Check token details curl -H "Authorization: Bearer <YOUR_TOKEN>" https://www.googleapis.com/oauth2/v3/tokeninfo
By going through these steps, you should be able to resolve the unauthorized error and get the new user's access token working properly.
内容的提问来源于stack exchange,提问作者Shubham Shekhar

