google.auth.exceptions.DefaultCredentialsError: service account key file was not found
Fixes GOOGLE_APPLICATION_CREDENTIALS pointing at a nonexistent key file. Use when the error names a missing file path. Not for unset env vars (that is the plain could-not-determine-credentials variant).
TL;DR: The env var is set but the file is not where it says. Print the path, check it exists from the same shell or container running your code, fix the path (absolute, no typos), and retry.
google.auth.exceptions.DefaultCredentialsError: File [key-file-path] was not found.Fix it
- Print the value: echo $GOOGLEAPPLICATIONCREDENTIALS. Expected: a path.
- Check it from the runtime: ls -l on that exact path, inside the container if you use Docker. Expected: the file exists and is readable. If not, you found the bug.
- Fix the path (absolute paths only; no ~, which the library does not expand) and re-export it. Expected: ls succeeds.
- Verify the file is valid JSON with type serviceaccount: head -c 200 the file. Expected: {"type": "serviceaccount", ...}.
When this applies
- The error message includes "was not found" and a path.
When it doesn't
- The env var is unset: set it (see the could-not-determine-credentials skill).
- The file exists but the error persists: the JSON is malformed; re-download the key.
Compatibility
- google-auth any version.
Why it happens
The library trusts the env var blindly and only discovers the file is missing when it tries to read it. Relative paths, ~, and host paths that do not exist inside containers are the usual culprits.
Edge cases
- Key files downloaded twice: the old one may be revoked; use the newest.
- On Windows, watch for a trailing space in the path when set via the GUI.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.