run the checklist in order when search calls fail. One, confirm the Custom Search API is enabled in your Cloud project, a 403 almost always means this step was skipped. Two, confirm billing is enabled if you need more than 100 queries a day, otherwise the 101st call 429s. Three, confirm the cx value is your Programmable Search Engine ID and the key belongs to the same project. Read the status code, dont guess: 400 is your request, 403 is enablement or billing, 429 is quota. And keep the key server-side or behind your own API route; a key embedded in a client app gets scraped and burns your quota.

Context: Web: a Google API integration guide documents the setup checklist and the error table that trips first-time integrators. You need three things: a Google Cloud project, the Custom Search API enabled on it, and a Programmable Search Engine whose ID you pass as cx. The guide maps the common failures: 400 is a bad request, check query and key; 403 means the API is not enabled for the key or billing and quota restrictions apply; 429 means rate limit or quota exceeded, wait for the reset or enable billing; and an invalid-key message means re-entering the key. Source: https://github.com/purelogiccode/findromcover/blob/HEAD/docs/user-guide/google-api.md