G Suite Admin SDK Directory API示例报错Bad Request 排查咨询
listUsers() Hey there, let's break down how to dig into this vague "Bad Request" error when calling listUsers() in the Node.js Google Admin SDK. Here are the most common fixes and debugging steps to narrow things down:
1. Confirm the Admin SDK Directory API is Enabled
First off, double-check that you've actually turned on the Admin SDK Directory API in your Google Cloud Console. This is a super easy step to miss, and it's a frequent cause of silent bad requests:
- Navigate to your Google Cloud project's API library
- Search for "Admin SDK Directory API"
- If it's marked as "Disabled", click "Enable" and wait a minute for the changes to propagate
2. Validate Your Authentication Scopes
The auth object you're passing might lack the necessary permissions to access user data. For listing users, you need at least one of these scopes:
https://www.googleapis.com/auth/admin.directory.user.readonly(read-only access, recommended for this use case)https://www.googleapis.com/auth/admin.directory.user(full user management access)
Make sure your auth client setup includes the correct scope. For example, if using a service account:
const auth = new google.auth.JWT( client_email, null, private_key, ['https://www.googleapis.com/auth/admin.directory.user.readonly'], // Critical: include the right scope here 'admin@your-domain.com' // The super admin email you're impersonating );
3. Check the customer Parameter
You're using customer: 'my_customer'—this value only works if you're authenticating as a super admin of your Google Workspace domain. If you're using a regular admin account or a service account without proper impersonation, this will fail:
- If you're not a super admin, replace
customer: 'my_customer'withdomain: 'your-domain.com'(use your actual Workspace domain) - For service accounts, ensure you've enabled domain-wide delegation and are impersonating a valid super admin user
4. Get Detailed Error Context
The default error message is too vague—modify your error handling to log the full error object, which will include specific details like error codes or permission issues:
if (err) { console.log('Full API error details:', JSON.stringify(err, null, 2)); return; }
This will show you things like statusCode, an errors array with specific reasons (e.g., "insufficientPermissions" or "invalidParameter"), which will point you directly to the root problem.
5. Verify Admin Privileges (For User Accounts)
If you're using a regular user account (not a service account) for authentication, make sure that account has the Users > View users privilege assigned in your Google Workspace admin console. Without this permission, the API will reject your request with a bad response.
6. Check API Quotas and Rate Limits
While "Bad Request" isn't the typical quota error, it's worth ruling out. Head to the Google Cloud Console's "APIs & Services" > "Dashboard" > "Quota" to confirm you haven't hit the rate limits for the Admin SDK Directory API.
内容的提问来源于stack exchange,提问作者AdamG

