Important: If you're using an email associated with a Google Workspace account, please ensure that it has Super Admin permissions enabled. See the “Become a Super Admin” section below for more information
How-To
1. Open a Private browser tab.
2. Go to console.cloud.google.com.
3.Make sure you’re signed in with the same Google account you use for your Play Console.
IAM/Permissions
In Cloud Console, open the Project Switcher.
Note: You might see “Select a project,” “No organization,” or your organization’s domain name instead.
Click the three-dot icon in the top-right → then IAM/Permissions.
Make sure your organization’s domain now appears in the Project Switcher.
Add the Organization Policy Administrator Role
Find your email address and click the pencil icon to the right of it.
Click + Add another role → then in the dropdown menu that appears, search for Organization Policy Administrator.
Select Organization Policy Administrator → then click Save.
Add Permissions to the Organization
Repeat the same steps for the organization, so it also has the Organization Policy Administrator role.
Navigate to "Disable Service Account Key Creation":
Wait a few minutes, then refresh your browser a couple times.
Click Organization Policies in the left-hand menu.
Search for constraints/iam.disableServiceAccountKeyCreation in the filter bar.
Click the Disable service account key creation item that shows Active under the Enforcement state column.
Turn Constraint Off
Click Manage policy → then scroll down and click Enforced.
Change Enforcement to Off → then click Done.
Click the blue Set policy button.
Create your API Key
Wait 1 hour, then refresh your browser a couple times.
Return to the Project Switcher menu by clicking the item in the upper left corner.
Select your Subsplash project.
Scroll down in the left-hand menu, and click Service Accounts.
Return to the creation of your API User and Private Key
Become a Super Admin
Open the Admin Console:
Go to admin.google.com.
Click Manage under the Users.
Assign Super Admin privileges:
Select the account you used for your Google developer account.
Scroll to Admin roles and privileges.
If you do not have a role yet, select ASSIGN ROLES.
If you already have a role, click the down icon
next to Admin roles and privileges → then click the pencil icon
Toggle on the Super Admin role.
Scroll down and click SAVE.
If you were able to become a Super Amin: Wait at least 3 hours for the permissions to fully update across Google’s system, then proceed to fix service account key creation.
If you can't update your role because you don’t have Super Admin privileges, you’ll need someone in your organization who is a Super Admin to grant you that role in Google Workspace.






