GET /v1beta/models returns 200 OK, but generateContent returns HTTP 403 "Your project has been denied access"

Hi Gemini API Team,

I am experiencing an asymmetric gateway authorization issue on a free-tier Google AI Studio API key.

While querying the model catalog (GET /v1beta/models) authenticates successfully and returns a 200 OK with available models, calling generateContent (POST) on any of those listed models fails immediately with an HTTP 403 PERMISSION_DENIED error.

1. Diagnostic Findings

Request Method & Endpoint Response Code Result
GET /v1beta/models?key={KEY} 200 OK Successfully returns active models (gemini-2.5-flash, gemini-flash-latest, etc.)
POST /v1beta/models/gemini-flash-latest:generateContent?key={KEY} 403 PERMISSION_DENIED Returns project denial error
POST /v1beta/models/gemini-2.5-flash:generateContent?key={KEY} 403 PERMISSION_DENIED Returns project denial error

2. Exact Error Payload (HTTP 403)

JSON

{
  "error": {
    "code": 403,
    "message": "Your project has been denied access. Please contact support.",
    "status": "PERMISSION_DENIED"
  }
}

3. Minimal Reproducible Apps Script Code (Sanitized)

JavaScript

// 1. THIS WORKS (Returns 200 OK + Model Catalog JSON)
function testListModels() {
  const apiKey = "AQ.Ab8RN...[REDACTED_KEY]";
  const url = `https://generativelanguage.googleapis.com/v1beta/models?key=${apiKey}&pageSize=100`;
  
  const res = UrlFetchApp.fetch(url, { "method": "get", "muteHttpExceptions": true });
  Logger.log(`[LIST MODELS CODE] ${res.getResponseCode()}`); // Logs: 200
}

// 2. THIS FAILS (Returns 403 PERMISSION_DENIED)
function testGenerateContent() {
  const apiKey = "AQ.Ab8RN...[REDACTED_KEY]";
  const url = `https://generativelanguage.googleapis.com/v1beta/models/gemini-flash-latest:generateContent?key=${apiKey}`;

  const payload = {
    "contents": [{"parts": [{"text": "Hello, world!"}]}]
  };

  const options = {
    "method": "post",
    "contentType": "application/json",
    "payload": JSON.stringify(payload),
    "muteHttpExceptions": true
  };

  const res = UrlFetchApp.fetch(url, options);
  Logger.log(`[GENERATE CONTENT CODE] ${res.getResponseCode()}`); // Logs: 403
  Logger.log(`[RESPONSE BODY] ${res.getContentText()}`);
}

4. Questions for Engineering / Developer Support

  1. Gateway Restriction: Why would an API key successfully pass authentication for model discovery (models.list), but get blocked with "Your project has been denied access" on inference (generateContent)?

  2. Account Policy / Flags: Is there an automated security or age/identity verification check on unbilled projects that restricts content generation endpoints while leaving catalog listing active?

  3. Resolution: How can this project-level inference restriction be cleared for free-tier development?