I am trying to get the list of chrome devices registered with the specified customer Id.
I have done the following Steps.
Registered this client id as authorized API client Thru Google Admin(Manage API client access)
Client Id : our clientid API Scope: View and manage your Chrome OS devices' metadata https://www.googleapis.com/auth/admin.directory.device.chromeos View your Chrome OS devices' metadata https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly Next I used my Node module to Generate the JWT access
Token is created Successfully.
Now i am trying to use this Bearer toke to access the following API
This is always giving the following error.
"error": {
"errors": [{
"domain": "global",
"reason": "forbidden",
"message": "Not Authorized to access this resource/api"
"code": 403,
"message": "Not Authorized to access this resource/api"
Not sure what is the issue.
Its working after adding Impersonated users email address... Originally it was
const jwtAuth = new google.auth.JWT(
Then I have added the subject as impersonated users email address.
const jwtAuth = new google.auth.JWT(
'email address of the impersonated user',