Troubleshoot federated cloud access changedclaude-tag/admins/federated-access/troubleshooting
Nearest release: v2.1.283, published 10 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 26 Sep 2026 05:05 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 26 Sep 2026 05:07 UTC.
Upstream edited
Recorded here
Lines+15added
Lines−9removed
From line
225
where the diff opens
First seen
10 Sep 2026
this site's first read of the page
Recorded edits6to this page, all time
The whole hunk
from line 225, old and new numbered
/
from line 225
225225
226226**What you see**
227227
228Claude reports a 403 from an AWS or Google Cloud API, with the provider's own error body rather than a reason beginning "request blocked".
228Claude reports a 403 from an AWS or Google API, with the provider's own error body rather than a reason beginning "request blocked".
229229
230230**What it means**
231231
232The token exchange worked and Claude called the API with the exchanged credential, but the role or identity lacks permission for that action. For Google Cloud, the exchange always requests the `cloud-platform` scope, so IAM alone decides what the credential can do.
232The token exchange worked and Claude called the API with the exchanged credential, but the API refused the call for one of these reasons:
233233
234* **A missing permission.** The role or identity lacks permission for that action.
235* **A Google API that needs an OAuth scope of its own.** For Google Cloud, the exchange always requests the `https://www.googleapis.com/auth/cloud-platform` scope, and there's no setting to change it. Google Cloud APIs accept that scope, and IAM decides what the credential can do on those APIs. APIs that need an OAuth scope of their own, such as the Google Drive, Calendar, and Gmail APIs, answer 403 for insufficient scopes whatever IAM allows.
236
237If the 403 comes from a Google Cloud API, such as Cloud Storage, the OAuth scope isn't the cause, so check the permission. If the 403 comes from an API that needs an OAuth scope of its own, such as the Google Drive, Calendar, or Gmail API, the cause is the OAuth scope.
238
234239**How to resolve**
235240
236Grant the IAM permission to the AWS role, the Google Cloud service account, or the federated identity when no service account is named. For AWS, a 403 also makes Claude assume the role again on the next request, so a fix takes effect on the next try.
241* **A missing permission.** Grant the IAM permission to the AWS role, the Google Cloud service account, or the federated identity when no service account is named. For AWS, a 403 also makes Claude assume the role again on the next request, so a fix takes effect on the next try.
242* **A Google API that needs an OAuth scope of its own.** A federated connection can't reach that API. To connect Google Drive, Calendar, or Gmail another way, see [Choose OAuth or a service account](/docs/claude-tag/admins/connections/google#choose-oauth-or-a-service-account). If a channel gets both that connection and the federated connection, keep the two from covering the same host; see [Which credential wins](/docs/claude-tag/admins/attach-to-scope#which-credential-wins).
237243
238244## Rejections in your own logs
239245
No line in this hunk matches that.