You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Google Cloud Vision API处理PDF OCR时遇403权限拒绝错误求助

Fixing PermissionDenied 403 Error with Google Cloud Vision API for PDF OCR

Hey there, I’ve run into this exact 403 issue a few times when working with Vision API and Cloud Storage, so let’s walk through the most likely fixes step by step:

1. Verify Your Service Account Has the Right Permissions

The most common culprit is missing permissions on the service account linked to your OAuth key. You need two core permissions at minimum:

  • Cloud Vision API User: Lets the account call the Vision API endpoints.
  • Storage Object Viewer: Lets the account read the PDF file from your Cloud Storage bucket.

To add these:

  • Go to the IAM & Admin section in your Google Cloud Console.
  • Find the service account associated with your key1.json file (look for the client_email field in the key file to identify it).
  • Click the pencil icon to edit permissions, then add the two roles mentioned above.

2. Make Sure the Cloud Vision API is Enabled

It’s easy to overlook this step! Even if you have the right permissions, if the API isn’t enabled for your project, you’ll get a 403 error:

  • Go to the APIs & Services > Library in the Cloud Console.
  • Search for "Cloud Vision API" and check if it says "Enabled". If not, click the Enable button.

3. Double-Check Your Credential Path & Environment Variable

Sometimes the path to your key file is incorrect, or the environment variable isn’t being picked up properly:

  • Use an absolute path for your key file (e.g., /home/user/mykeys/key1.json instead of mykeys/key1.json) to avoid relative path confusion.
  • Test if the environment variable is set correctly by running this in your terminal before executing the script:
    echo $GOOGLE_APPLICATION_CREDENTIALS
    
    It should output the full, correct path to your key file. If not, set it explicitly in your script before initializing the Vision client:
    import os
    os.environ["GOOGLE_APPLICATION_CREDENTIALS"] = "/full/absolute/path/to/key1.json"
    

4. Confirm All Resources Are in the Same Project

Your Cloud Storage bucket, the service account’s project, and the enabled Vision API must all belong to the same Google Cloud project. It’s easy to mix up projects if you have multiple ones:

  • Check the project_id field in your key file.
  • Verify your bucket is in that same project (go to Cloud Storage, click the bucket, check the "Project ID" field in the details panel).
  • Ensure the Vision API is enabled for that specific project.

5. Check Bucket-Level IAM Permissions (If Needed)

In some cases, even if the service account has Storage Object Viewer at the project level, the bucket’s individual IAM policy might block access:

  • Go to your Cloud Storage bucket, click the Permissions tab.
  • Add the service account’s email with the Storage Object Viewer role here to rule out bucket-level restrictions.

If you’re still hitting the 403 after these steps, enable debug logging to get more context about the API call:

import logging
logging.basicConfig(level=logging.DEBUG)

This will show detailed logs that might point to a specific permission or configuration issue.

内容的提问来源于stack exchange,提问作者vamsi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:27:24