PERMISSION_DENIED: The caller does not have permission (insufficient permissions)
You are authenticated, but your identity isn’t allowed to perform this action on this resource.
Meaning
Authorization failures return 403. Google Cloud and gRPC APIs say PERMISSION_DENIED (“The caller does not have permission”, or “Permission 'x.y.z' denied on resource”), Microsoft Graph says Authorization_RequestDenied / “Insufficient privileges to complete the operation”, and many REST APIs say insufficient_permissions.
Either the identity lacks a role/permission, the token lacks a scope it needs, or the resource belongs to another project, tenant or owner.
Common causes
- Role/permission missing for the user or service account
- Token issued without the needed scope (re-consent required)
- Resource is in another project/tenant/organisation
- Resource-level ACL or ownership rule denies access
- Permission granted recently and not yet propagated or not in the current token
⚡ Quick fix
- Read the exact permission named in the error and grant that role
- Request the scope and get a new token
- Confirm the project/tenant the resource lives in matches the caller’s
Detailed fix by platform
gcloud
gcloud projects add-iam-policy-binding my-project --member=serviceAccount:app@my-project.iam.gserviceaccount.com --role=roles/storage.objectViewer
REST API
- bash
# decode the access token and check its scopes/roles echo "$TOKEN" | cut -d. -f2 | base64 -d 2>/dev/null | jq '.scp // .scope, .roles'
How to diagnose
- Identity — Which user/service account is calling?
- Permission — Exact permission or scope in the error
- Resource — Owning project/tenant
- Token — Issued before the grant?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Report a correction or suggest an improvement
Last updated 7 Oct 2026