Yandex Cloud
Search
Contact UsTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
All solutions
    • All solutions for IAM
    • Resolving errors when assigning the `resource-manager.clouds.owner` owner role to a cloud user
    • Resolving errors related to invitations to a cloud organization
    • Resolving the `The signature of response or assertion was invalid` error when signing in to a federated account
    • Resolving issues when creating OAuth tokens on behalf of Yandex ID accounts
    • Fixing the `publicAccessBindings` error when moving a cloud across organizations
    • Resolving the `OAuth token is invalid or expired` error
    • Fixing the `Contact your organization administrator for a new invitation` error
    • Resolving the `Service account is not available` error
    • Fixing the `PROHIBITED_BILLING_ACCOUNT_USAGE_STATUS` error
    • Resolving the `Validation failed - access_binding_deltas Number of elements must be in the range of 1 to 1000` error
    • Federated user is not displayed in the organization's user list
    • User does not see an invitation to an organization or `admin` role
    • Unknown user detected in an organization
    • Resolving the `Invalid login` error
    • Resolving the `Forbidden` error when operating under a service account
    • How to delete a cloud
    • How to cancel pending cloud deletion
    • How to change the cloud owner
    • How to change the organization owner
    • How to delete an organization
    • How long a session lasts when authenticating a federated user
    • What minimum role a user requires to access the YC management console

In this article:

  • Issue description
  • Solution
  • If the issue persists
  1. Identity and Access Management
  2. Resolving issues when creating OAuth tokens on behalf of Yandex ID accounts

Resolving Issues when creating OAuth tokens on behalf of Yandex ID accounts

Written by
Yandex Cloud
Updated at December 17, 2025
  • Issue description
  • Solution
  • If the issue persists

Issue descriptionIssue description

When trying to create an OAuth token on behalf of a Yandex ID user, you get this error message:

Forbidden to get tokens with these permissions for this application.

SolutionSolution

Check out this page: you may find out in detail how to get a token.

Note that in most Yandex Cloud use cases, you can use service accounts.

If the issue persistsIf the issue persists

If the above actions did not help solve the issue, contact the Yandex ID support. You can find the button expanding the feedback form at the bottom of the page.

Was the article helpful?

Previous
Resolving the `The signature of response or assertion was invalid` error when signing in to a federated account
Next
Fixing the `publicAccessBindings` error when moving a cloud across organizations
© 2025 Direct Cursus Technology L.L.C.