Admin Directory users.list请求返回400 Bad Request问题求助
Let’s break down why you’re hitting a 400 error on the Users List endpoint, even after successful OAuth2 authentication—both in API Explorer and your .NET client:
First, confirm the Admin SDK is enabled
It’s an easy step to miss: head to your Google Cloud Console, navigate to "APIs & Services > Enabled APIs & Services", and make sure the Admin SDK is turned on. Even with valid authentication, a disabled API will throw unexpected errors.Verify OAuth2 scopes and account privileges
The Users List endpoint requires Google Workspace super admin permissions. Double-check two things:- The account you’re authenticating with is a super admin for your domain.
- You’ve requested the correct scopes:
- Read-only access:
https://www.googleapis.com/auth/admin.directory.user.readonly - Read/write access:
https://www.googleapis.com/auth/admin.directory.user
Non-admin accounts or overly restrictive scopes can trigger authorization-related 400s, even if OAuth appears to succeed.
- Read-only access:
Dig into the 400 error’s specific details
400 errors almost always include a detailed message—don’t stop at just the status code. In API Explorer, check the "Response" tab for theerrorobject; in your .NET client, catch the exception and inspect the error content. Common culprits here:- A missing or invalid
domainparameter (the endpoint often requires this, even for single-domain workspaces) - Malformed query parameters (even empty values that the API rejects)
- A missing or invalid
API Explorer-specific checks
Even if you removed all visible parameters, the tool might retain hidden defaults or invalid state. Try these fixes:- Reset the API Explorer form (look for a "Reset" button) to clear any leftover invalid values
- Confirm you’ve selected the correct Google Workspace domain in the top-right dropdown of the interface
- Inspect the raw request URL/payload to ensure there are no extra characters or empty parameters being sent
.NET client configuration issues
If the problem persists in your code:- Ensure you’re using the latest version of the
Google.Apis.Admin.Directory.directory_v1NuGet package—old versions can have bugs with request formatting - If using a service account, confirm domain-wide delegation is set up correctly and you’re impersonating a super admin account (via
ServiceAccountCredential.Initializer.WithUser("admin@yourdomain.com")) - Enable logging in the Google API client or use tools like Fiddler to inspect outgoing requests for malformed parameters or headers
- Ensure you’re using the latest version of the
Start with the error details—they’ll point you directly to the root cause more often than not.
内容的提问来源于stack exchange,提问作者zenocon

