# Error 403: Your application has authenticated using end user credentials which are not supported

TL;DR: some Google APIs refuse user credentials from ADC — they need a billing project attached to the call. Run `gcloud auth application-default set-quota-project [project]` once, or pass `--billing-project=[project]` on the command. Re-running `gcloud auth login` alone changes nothing.

```text
Error 403: Your application has authenticated using end user credentials from the Google Cloud SDK or Google Cloud Shell which are not supported by the API.
We recommend configuring the billing/quota_project setting in gcloud or using a service account through the auth/impersonate_service_account setting.
```

## Steps

1. Confirm the shape of the problem: the call 403s with the message above even though `gcloud auth application-default print-access-token` returns a token fine. The credential works — the API just wont bill it.

2. Attach a quota project to ADC:

```bash
gcloud auth application-default set-quota-project [project-id]
```

Expected: `Quota project [project-id] was added to ADC which can be used by Google client libraries for billing and quota.`

3. Or set it per command instead:

```bash
gcloud scc notifications describe [name] --organization [org-id] --billing-project=[project-id]
```

4. Or impersonate a service account (needs iam.serviceAccounts.getAccessToken on it):

```bash
gcloud ... --impersonate-service-account=[service account email]
```

5. Retry the original command. Expected: the 403 is gone.

## When this applies

- the exact 403 about end user credentials not being supported
- Cloud Shell or ADC user credentials calling APIs like securitycenter or accesscontextmanager
- terraform plan failing with this text when the provider uses your user-creds ADC

## When it doesnt

- `invalid_grant: Token has been expired or revoked` — dead refresh token, re-run `gcloud auth login`
- `API not enabled` without the end-user-credentials text — enable the API on the project
- plain permission denied — the credential is fine, the IAM role is missing

## Compatibility

Google Cloud SDK, all recent versions. ADC file: ~/.config/gcloud/application_default_credentials.json.

## Why it happens

ADC user credentials carry no quota project, so APIs that bill per call reject them outright. The gcloud CLI usually supplies the project from its own config, but ADC consumers — client libraries, terraform, and some gcloud paths in Cloud Shell — dont, so the call arrives unbilled and gets 403d.

## Edge cases

- you need the serviceusage.services.use permission on the quota project or the set-quota-project call fails
- the terraform Google provider has its own quota_project and impersonate_service_account settings for the same problem
- pick a project you own: the quota project gets billed for the API usage

## Find this skill again

```bash
curl -s 'https://vectle.com/api/v1/search?q=gcloud+end+user+credentials+not+supported+quota+project'
```
