Hi Gemini API Team,
I am experiencing an asymmetric gateway authorization issue on a free-tier Google AI Studio API key.
While querying the model catalog (GET /v1beta/models) authenticates successfully and returns a 200 OK with available models, calling generateContent (POST) on any of those listed models fails immediately with an HTTP 403 PERMISSION_DENIED error.
1. Diagnostic Findings
| Request Method & Endpoint | Response Code | Result |
|---|---|---|
GET /v1beta/models?key={KEY} |
200 OK | Successfully returns active models (gemini-2.5-flash, gemini-flash-latest, etc.) |
POST /v1beta/models/gemini-flash-latest:generateContent?key={KEY} |
403 PERMISSION_DENIED | Returns project denial error |
POST /v1beta/models/gemini-2.5-flash:generateContent?key={KEY} |
403 PERMISSION_DENIED | Returns project denial error |
2. Exact Error Payload (HTTP 403)
JSON
{
"error": {
"code": 403,
"message": "Your project has been denied access. Please contact support.",
"status": "PERMISSION_DENIED"
}
}
3. Minimal Reproducible Apps Script Code (Sanitized)
JavaScript
// 1. THIS WORKS (Returns 200 OK + Model Catalog JSON)
function testListModels() {
const apiKey = "AQ.Ab8RN...[REDACTED_KEY]";
const url = `https://generativelanguage.googleapis.com/v1beta/models?key=${apiKey}&pageSize=100`;
const res = UrlFetchApp.fetch(url, { "method": "get", "muteHttpExceptions": true });
Logger.log(`[LIST MODELS CODE] ${res.getResponseCode()}`); // Logs: 200
}
// 2. THIS FAILS (Returns 403 PERMISSION_DENIED)
function testGenerateContent() {
const apiKey = "AQ.Ab8RN...[REDACTED_KEY]";
const url = `https://generativelanguage.googleapis.com/v1beta/models/gemini-flash-latest:generateContent?key=${apiKey}`;
const payload = {
"contents": [{"parts": [{"text": "Hello, world!"}]}]
};
const options = {
"method": "post",
"contentType": "application/json",
"payload": JSON.stringify(payload),
"muteHttpExceptions": true
};
const res = UrlFetchApp.fetch(url, options);
Logger.log(`[GENERATE CONTENT CODE] ${res.getResponseCode()}`); // Logs: 403
Logger.log(`[RESPONSE BODY] ${res.getContentText()}`);
}
4. Questions for Engineering / Developer Support
-
Gateway Restriction: Why would an API key successfully pass authentication for model discovery (
models.list), but get blocked with"Your project has been denied access"on inference (generateContent)? -
Account Policy / Flags: Is there an automated security or age/identity verification check on unbilled projects that restricts content generation endpoints while leaving catalog listing active?
-
Resolution: How can this project-level inference restriction be cleared for free-tier development?