{"record":{"id":"dae555595889a701","repo":"googleapis/mcp-toolbox","slug":"failed-to-call-userinfo-endpoint-w","errorCode":null,"errorMessage":"failed to call userinfo endpoint: %w","messagePattern":"failed to call userinfo endpoint: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/sources/util.go","lineNumber":89,"sourceCode":"\tcase \"psc\":\n\t\topts = append(opts, cloudsqlconn.WithDefaultDialOptions(cloudsqlconn.WithPSC()))\n\tdefault:\n\t\treturn nil, fmt.Errorf(\"invalid ipType %s. Must be one of `public`, `private`, or `psc`\", ipType)\n\t}\n\n\tif useIAM {\n\t\topts = append(opts, cloudsqlconn.WithIAMAuthN())\n\t}\n\treturn opts, nil\n}\n\n// GetIAMPrincipalEmailFromADC finds the email associated with ADC\nfunc GetIAMPrincipalEmailFromADC(ctx context.Context, dbType string) (string, error) {\n\t// Finds ADC and returns an HTTP client associated with it\n\tclient, err := google.DefaultClient(ctx,\n\t\t\"https://www.googleapis.com/auth/userinfo.email\")\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to call userinfo endpoint: %w\", err)\n\t}\n\n\t// Retrieve the email associated with the token\n\tresp, err := client.Get(\"https://oauth2.googleapis.com/tokeninfo\")\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to call tokeninfo endpoint: %w\", err)\n\t}\n\tdefer resp.Body.Close()\n\n\tbodyBytes, err := io.ReadAll(resp.Body)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"error reading response body %d: %s\", resp.StatusCode, string(bodyBytes))\n\t}\n\tif resp.StatusCode != http.StatusOK {\n\t\treturn \"\", fmt.Errorf(\"tokeninfo endpoint returned non-OK status %d: %s\", resp.StatusCode, string(bodyBytes))\n\t}\n\n\t// Unmarshal response body and get `email`","sourceCodeStart":71,"sourceCodeEnd":107,"githubUrl":"https://github.com/googleapis/mcp-toolbox/blob/8cc6e09de2ad7b8bffc77751799585a1401a48eb/internal/sources/util.go#L71-L107","documentation":"google.DefaultClient failed while resolving Application Default Credentials for the userinfo.email scope — ADC is missing, expired, or the credential file is malformed, so no authenticated HTTP client can be built for the IAM email lookup.","triggerScenarios":"Thrown at internal/sources/util.go:89 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Run gcloud auth application-default login","Set GOOGLE_APPLICATION_CREDENTIALS to a valid service account key","Verify the credential scopes include userinfo.email"],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"8cc6e09de2ad7b8bffc77751799585a1401a48eb","analyzedAt":"2026-09-05T01:10:36.887Z","contentChangedAt":"2026-09-05T01:10:36.887Z","schemaVersion":2},"datasetVersion":"2026-09-08T10:18:20.063Z"}