My goal is to update all user email signature from my domain.
I have set up a service account with domain-wide delegation authority.
But I'm stuck with this error:
"error": {
"errors": [
"domain": "global",
"reason": "failedPrecondition",
"message": "Bad Request"
"code": 400,
"message": "Bad Request"
I'm using the same request than the one executed by the API explorer. So it should be well formated...
In the API explorer, it isn't properly working either, i'm having this answer :
"error": {
"errors": [
"domain": "global",
"reason": "forbidden",
"message": "Delegation denied for"
"code": 403,
"message": "Delegation denied for"
It seems like I have permission problems but I can't figure out why.
Here is my PHP test code for information :
public function updateSignAction(){
$client = new \Google_Client();
$httpClient = $client->authorize();
$response = $httpClient->put(
'json' => [
'signature' => "test-via-api"
return $this->render('AdminBundle:GoogleApi:user/update.html.twig', array(
'response' => $response->getBody()->getContents(),
You must authenticate to the API. To do this, there are two ways:
Use OAuth - the Server redirects the user to google's servers, where they can login, grant permission to your app, and pass a token back to you
Service Accounts. These are a little bit more complicated:
First, you'll have to setup an app (done)
Second, you'll have to setup a service account. This is how your app authenticates to google. you've done that, and the certificate you've got contains the private key to authenticate
Third, the user needs to grant your application access to act on behalf of them. This is the point you haven't done yet.
So what you're currently trying is to send mails from the service account, but this is not an Gmail Account.
Please also note: With regular GMail Accounts, you can not use 'Service Accounts'. You'll have to use OAuth. To use Service Accounts, you need to be a Google Apps customer.
To grant your Service Account Permissions to send mails on behalf of your GMails/Google Apps accounts, please follow this document. For One or More API Scopes, you'll have to enter,,,
After you've setup this, it's possible to send mails, just modify the code as follows:
$results = $service->users_messages->send("me", $msg);
won't work, because 'me' referrs to the service account, which can't send mail (see above). Replace me with the user id (mail-address) of the account from which the mails should be send.:
$results = $service->users_messages->send("", $msg);
Then, you'll need to add
$cred->sub = '';
$cred = new \Google_Auth_AssertionCredentials(
array('', ''),
require_once realpath(dirname(__FILE__) . '/../src/Google/autoload.php');
$client_id = '*censored*';
$service_account_name = '*censored*';
$key_file_location = '/tmp/apiKey.p12';
$client = new \Google_Client();
if (isset($_SESSION['service_token'])) {
$key = file_get_contents($key_file_location);
$cred = new \Google_Auth_AssertionCredentials(
array('', '', '',''),
if ($client->getAuth()->isAccessTokenExpired()) {
$mime = "*censored*";
$service = new \Google_Service_Gmail($client);
$msg = new \Google_Service_Gmail_Message();
try {
$results = $service->users_messages->send($userid_from, $msg);
print 'Message with ID: ' . $results->id . ' sent.';
} catch (\Exception $e) {
print 'An error occurred: ' . $e->getMessage();
If there are any questions left, feel free to ask!
I'm updating a PHP application to create new "send mail as" accounts in Gmail (using the Google Service Gmail). I'm able to connect to the account and view alias information from my code so the connection is not the issue. Here is my code
$scopes = array(
$client = new \Google_Client();
try {
$gmail = new Google_Service_Gmail($client);
$smtpadd = new Google_Service_Gmail_SendAs(array('displayName' => 'display name','sendAsEmail' => '','treatAsAlias' => false, 'isPrimary' => 'true', 'isDefault' => 'false', 'smtpMsa' => array(
'host' => '',
'port' => 587,
'username' => 'username',
'password' => 'mypassword'
$results = $gmail->users_settings_sendAs->create('',$smtpadd);
} catch (exception $e) {
print "Error" . $e->getMessage();
The only time I get a 500 internal error is when I try to add a new "send mail as" account with smtp MSA information. Also this code was working before and recently stop and gave me the 500 internal error.
Here is the error code
Google\Service\Exception: {
"code": 500,
"message": "Internal error encountered.",
"errors": [
"message": "Internal error encountered.",
"domain": "global", "reason": "backendError"
} ],
"status": "INTERNAL"
In order to send emails with a service account your workspace admin must have configured domain wide delegation to the user on your service account who you wish you send emails on behalf of.
This code should show you how to authorize your application. It will just list all the messages from your delegated user.
scopes = array(
$client = new Google_Client();
$client->setApplicationName("Gmail delegation sample");
$service = new Google_Service_Gmail($client);
$messages = $service->users_messages->listUsersMessages('me');
If that works then you should consult users.settings.sendAs#SendAs to check the property body for the users_settings_sendAs->create method.
$alias = new Google_Service_Gmail_SendAs();
$alias ->sendAsEmail('');
$service->users_settings_sendAs->create($this->email, $this->email, $alias);
I want to change all signatures from my Gmail domain. This domain has many accounts, and I need to change it from server-side.
I'm using php, and I started my project with:
php composer.phar require google/apiclient:2.0
I wrote one code, but when I try to update one email (like, I receive:
{ "error": { "errors": [ { "domain": "global", "reason": "insufficientPermissions", "message": "Insufficient Permission" } ], "code": 403, "message": "Insufficient Permission" } }
My code (using API client library) is something like:
// initialize gmail
function getService() {
try {
include_once __DIR__ . '/vendor/autoload.php';
$client = new Google_Client();
$credentials_file = __DIR__ . '/credentials/gmailAPI.json';
// set the location manually. Credential server-side
$gmail = new Google_Service_Gmail($client);
return $gmail;
} catch (Exception $e) {
throw new Exception($e->getMessage());
function updateSignature(&$gmail) {
try {
// Start sendAs
$signature = new Google_Service_Gmail_SendAs();
// Configure Signature
$signature->setSignature("Any HTML text here.");
// Update account and print answer
} catch (Exception $e) {
throw new Exception($e->getMessage());
try {
$gmail = getService();
} catch (Exception $e) {
echo $e->getMessage();
My credential file (gmailAPI.json) is one service account key, and I'm using Google for Work.
I created this credential using one administrator account from this domain.
My credential file is:
"type": "service_account",
"project_id": "myProjectId",
"private_key_id": "myPrivateKeyid",
"private_key": "myPrivateKey",
"client_email": "",
"client_id": "myId",
"auth_uri": "url",
"token_uri": "url",
"auth_provider_x509_cert_url": "url",
"client_x509_cert_url": "url"
Edit 1
I changed the scopes as instructed, and now my scopes are:
I also added permision on Google (/AdminHome?chromeless=1#OGX:ManageOauthClients) to my service account key.
I tried API explorer and it works. When i changed the scopes, the error changed to:
{ "error": { "errors": [ { "domain": "global", "reason": "failedPrecondition", "message": "Bad Request" } ], "code": 400, "message": "Bad Request" } }
I'm using this command:
I tried also
But I received same error.
Thank You everyone.
I tried a lot of codes, and finally found one that works.
include_once __DIR__ . '/vendor/autoload.php';
// credential file (service account)
$credentials_file = __DIR__ . '/credentials/gmailAPI.json';
// Initialize Google Client
$client = new Google_Client();
// scopes to change signature
// *important* -> Probably because delegated domain-wide access.
// Initialize Gmail
$gmail = new Google_Service_Gmail($client);
// set signature
$signature = new Google_Service_Gmail_SendAs();
$signature->setSignature("HTML code here.");
// update signature
$response = $gmail->users_settings_sendAs->update("","",$signature)->setSignature();
// get signature
$response = $gmail->users_settings_sendAs->get("","")->getSignature();
echo json_encode($response);
I commented all code, and I used to create it.
Atention -> You need to give permission on Gmail, and create server key (with domain-wide access).
I think your access token doesn't contain all scopes you want. First try in API explorer. Check what are the scopes API explorer request from you and then add those scopes to your code(place where you get permission).
hope this solves your problem
Well, the error 403 or Insufficient Permission is returned when you have not requested the proper or complete scopes you need to access the API that you are trying to use. Here is the list of scopes with description that you can use with Gmail API.
To know the scope that you are using, you can verify it with this:
Note: You need to include all the scope that you are using and make
sure you enable all the API that you use in the Developer Console.
This Delegating domain-wide authority to the service
might also help.
For more information, check these related SO questions:
Gmail API: Insufficient Permission
How do I get around HttpError 403 Insufficient Permission?
I'm trying to set publish permissions for gmail to a pubsub topic in google cloud.
The application where I implemented this code is running in AWS.
It's a PHP application and I'm using version 2.0.0-RC7 of the google PHP api client.
In code, I implemented the flow as described in the documentation:
Create a topic (Works)
Create a subscription (works)
Grant publish rights to gmail (here I get stuck)
The first two actions are done with the same google client instance, that is authenticated with the service account credentials.
The code:
$scopes = [
$pushEndpoint = 'https://some.url/google_notifications/';
$client = new Google_Client();
if ($client->isAccessTokenExpired()) {
$service = new Google_Service_Pubsub($client);
// This part works
$topicObject = new Google_Service_Pubsub_Topic();
$service->projects_topics->create($this->getTopicName(), $topic);
// This part also works
$push = new Google_Service_Pubsub_PushConfig();
$subscription = new Google_Service_Pubsub_Subscription();
$service->projects_subscriptions->create($this->getSubscriptionName(), $subscription);
// This part gives the error
$binding = new Google_Service_Pubsub_Binding();
$policy = new Google_Service_Pubsub_Policy();
$setRequest = new Google_Service_Pubsub_SetIamPolicyRequest();
try {
$result = $service->projects_topics->setIamPolicy($this->getTopicName(), $setRequest);
} catch (\Exception $e) {
echo $e->getMessage();
The result is always:
"error": {
"code": 403,
"message": "User not authorized to perform this action.",
"errors": [
"message": "User not authorized to perform this action.",
"domain": "global",
"reason": "forbidden"
Can someone tell me what I'm doing wrong ?
It's really annoying to set those permissions by hand all the time.
To use projects.topics.setIamPolicy method your service account must have a "Pub/Sub Admin" role. You can change a role of the account by visiting "IAM & admin" page for your project:
Okay... I have to say I don't have enough experience on using Google's API, so I'll try to explain as detail as I could.
I need to use PHP to grab the Cloud storage's data, so I tried my credential with gsUtil to grab data from bucket and it works; But when I try to use PHP library to grab data, the API replied me with this content:
"error": {
"errors": [
"domain": "global",
"reason": "forbidden",
"message": "Forbidden"
"code": 403,
"message": "Forbidden"
Since it didn't tell me exactly which step is wrong, so I searched around this site and tried everything which looked similar, but the Situation stands.
Here is the Configuration on my Google Dev. Console:
Api Manager > Overall > Enabled APIļ¼
(a)Drive API.
(b)Cloud Storage.
(c)Cloud Storage JSON API.
Api Manager > Credentials:
(a)Api Key / OAuth 2.0 ID / Service Acc. Key are created.
(b)Server IPs are added to the Api key's accept IP list.
(c)Service Account have the Editor permission to the Project, service acc key is bind to this account too.
$email = '<my gmail>';
$scope = '';
$apiKey = '<my api key>';
$oAuthId = '<OAuth ID>';
$serviceAcc = '<service account id>';
$keyFileLocation = $_SERVER['DOCUMENT_ROOT']. "/<p12 file>";
$bucketId = '<my bucket id>';
$list = array();
$client = new Google_Client();
$cred = new Google_Auth_AssertionCredentials (
if($client->getAccessToken()) {
$reqUrl = "$bucketId/o/";
$request = new Google_Http_Request($reqUrl, 'GET', null, null);
$httpRequest = $client->getAuth()->authenticatedRequest($request);
if ($httpRequest->getResponseHttpCode() == 200) {
$objects = json_decode($httpRequest->getResponseBody());
foreach ($objects->items as $object) {
$list[] = $object->mediaLink;
else {
echo $httpRequest->getResponseHttpCode(); // This is where I got the 403
Please tell me if I missed something.
Ok, I got the Problem: it must impersonate the User account which have the privilege to access the API scope that I mentioned in program.
So some additional codes must be added as following:
$email = '<email account which could access that api>';
$scope = '';
$apiKey = '<my api key>';
$oAuthId = '<OAuth ID>';
$serviceAcc = '<service account id>';
$keyFileLocation = $_SERVER['DOCUMENT_ROOT']. "/<p12 file>";
$bucketId = '<my bucket id>';
$list = array();
$client = new Google_Client();
$cred = new Google_Auth_AssertionCredentials (
Woooooyaaaaa, another problem solved! time to move up for next problem.
When I try to fetch data from Google Analytics, I got error
Error refreshing the OAuth2 token, message: '{ "error" :
"unauthorized_client", "error_description" : "Unauthorized client or
scope in request." }'
I create project in my, create Service account and download .p12 key. Also enable "Analytics API" in project settings, but it doesn't work. This is my code:
$service_account_name = '<Service Email>';
$key_file_location = '<keyName>.p12';
$key = file_get_contents($key_file_location);
$cred = new Google_Auth_AssertionCredentials(
'<My email>'
$service = new Google_Service_Analytics($client);
$result = $service->data_ga->get("ga:<profileID>", "yesterday", "today", "ga:pageviews");
print_r( $result);
What is wrong with my project? Please help.
You are missing the final step which is giving access to your application in the control panel of your domain.
You created the service account, now you need to delegate/authorize the application.