VectleSkillsError 403: Your application has authenticated using end user credentials which are not supported

Error 403: Your application has authenticated using end user credentials which are not supported

Export

Fixes gcloud and API calls failing with Error 403: Your application has authenticated using end user credentials which are not supported. Use when application-default credentials from gcloud auth application-default login hit APIs that require a billing/quota project. Sets the quota project or switches to a service account. Not for invalid_grant, which is a dead refresh token, or IAM permission denied.

Error 403: Your application has authenticated using end user credentials which are not supported

TL;DR: some Google APIs refuse user credentials from ADC — they need a billing project attached to the call. Run gcloud auth application-default set-quota-project [project] once, or pass --billing-project=[project] on the command. Re-running gcloud auth login alone changes nothing.

Error 403: Your application has authenticated using end user credentials from the Google Cloud SDK or Google Cloud Shell which are not supported by the API.
We recommend configuring the billing/quota_project setting in gcloud or using a service account through the auth/impersonate_service_account setting.

Steps

  1. Confirm the shape of the problem: the call 403s with the message above even though gcloud auth application-default print-access-token returns a token fine. The credential works — the API just wont bill it.
  1. Attach a quota project to ADC:
gcloud auth application-default set-quota-project [project-id]

Expected: Quota project [project-id] was added to ADC which can be used by Google client libraries for billing and quota.

  1. Or set it per command instead:
gcloud scc notifications describe [name] --organization [org-id] --billing-project=[project-id]
  1. Or impersonate a service account (needs iam.serviceAccounts.getAccessToken on it):
gcloud ... --impersonate-service-account=[service account email]
  1. Retry the original command. Expected: the 403 is gone.

When this applies

  • the exact 403 about end user credentials not being supported
  • Cloud Shell or ADC user credentials calling APIs like securitycenter or accesscontextmanager
  • terraform plan failing with this text when the provider uses your user-creds ADC

When it doesnt

  • invalid_grant: Token has been expired or revoked — dead refresh token, re-run gcloud auth login
  • API not enabled without the end-user-credentials text — enable the API on the project
  • plain permission denied — the credential is fine, the IAM role is missing

Compatibility

Google Cloud SDK, all recent versions. ADC file: ~/.config/gcloud/applicationdefaultcredentials.json.

Why it happens

ADC user credentials carry no quota project, so APIs that bill per call reject them outright. The gcloud CLI usually supplies the project from its own config, but ADC consumers — client libraries, terraform, and some gcloud paths in Cloud Shell — dont, so the call arrives unbilled and gets 403d.

Edge cases

  • you need the serviceusage.services.use permission on the quota project or the set-quota-project call fails
  • the terraform Google provider has its own quotaproject and impersonateservice_account settings for the same problem
  • pick a project you own: the quota project gets billed for the API usage

Find this skill again

curl -s 'https://vectle.com/api/v1/search?q=gcloud+end+user+credentials+not+supported+quota+project'

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Error+403%3A+Your+application+has+authenticated+using+end+user+credentials+which+are+not+supported&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.