PERMISSION_DENIED 🔐 Authentication

PERMISSION_DENIED: The caller does not have permission (insufficient permissions)

You are authenticated, but your identity isn’t allowed to perform this action on this resource.

Seen on: REST API

Meaning

Authorization failures return 403. Google Cloud and gRPC APIs say PERMISSION_DENIED (“The caller does not have permission”, or “Permission 'x.y.z' denied on resource”), Microsoft Graph says Authorization_RequestDenied / “Insufficient privileges to complete the operation”, and many REST APIs say insufficient_permissions.

Either the identity lacks a role/permission, the token lacks a scope it needs, or the resource belongs to another project, tenant or owner.

Common causes

  • Role/permission missing for the user or service account
  • Token issued without the needed scope (re-consent required)
  • Resource is in another project/tenant/organisation
  • Resource-level ACL or ownership rule denies access
  • Permission granted recently and not yet propagated or not in the current token

⚡ Quick fix

  1. Read the exact permission named in the error and grant that role
  2. Request the scope and get a new token
  3. Confirm the project/tenant the resource lives in matches the caller’s

Detailed fix by platform

gcloud

  1. gcloud projects add-iam-policy-binding my-project --member=serviceAccount:app@my-project.iam.gserviceaccount.com --role=roles/storage.objectViewer

REST API

  1. bash
    # decode the access token and check its scopes/roles
    echo "$TOKEN" | cut -d. -f2 | base64 -d 2>/dev/null | jq '.scp // .scope, .roles'

How to diagnose

  1. Identity — Which user/service account is calling?
  2. Permission — Exact permission or scope in the error
  3. Resource — Owning project/tenant
  4. Token — Issued before the grant?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.