Resource calendar synchronization fails with Google Calendar

We’re running Odoo 14 Enterprise and trying to synchronize resource calendars with Google Calendar for our field service team. The integration was working fine until last week when we started getting 403 errors consistently.

The error appears whenever a resource calendar is updated or when we try to push working hours to Google Calendar:


HTTP Error 403: Forbidden
{
  "error": {
    "code": 403,
    "message": "Insufficient Permission: Request had insufficient authentication scopes.",
    "status": "PERMISSION_DENIED"
  }
}

We’ve verified the OAuth2 credentials are still valid in Google Cloud Console, and the calendar API is enabled. The service account has domain-wide delegation configured. Has anyone encountered this specific 403 insufficient permission error with resource calendar sync? Our field operations depend heavily on this integration for scheduling mobile technicians.

This happened to us after a Google Workspace update. The issue was twofold: first, our OAuth client was still using deprecated scopes, and second, the refresh token had expired. Here’s what we did to fix it completely.

In Google Cloud Console, verify these exact scopes are added to your OAuth client:

Then in Odoo, go to Settings > Technical > System Parameters and check the google_calendar_token parameter. If it’s outdated or corrupted, you’ll need to re-authorize.

For service accounts with domain-wide delegation, the configuration must include:


Client ID: [your-service-account-client-id]
Scopes: https://www.googleapis.com/auth/calendar,https://www.googleapis.com/auth/calendar.events

Make sure there are NO spaces after the comma in the scopes list.

After updating Google Cloud settings, you must disconnect and reconnect the calendar integration in Odoo. Go to Settings > General Settings > Integrations > Google Calendar, click Disconnect, save, then click Connect again. This forces a new OAuth flow with the updated scopes.

Also verify in Google Admin Console (admin.google.com) under Security > API Controls > Domain-wide Delegation that your service account is listed and has the correct scopes. If you recently rotated keys or created a new service account, the old authorization might still be cached.

One more critical point: if you’re syncing multiple resource calendars, each calendar in Google must have the service account added as an Editor (not just Viewer). Go to each calendar’s settings and explicitly add your-service-account@project-id.iam.gserviceaccount.com with “Make changes to events” permission.

After these changes, test with a single resource calendar first before enabling sync for your entire field service team.


This draft is based on general Odoo knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.

Check your OAuth scopes in the Google API configuration. The 403 error typically means the access token doesn’t have the required calendar scopes. You need both calendar.events and calendar.readonly scopes for full synchronization.

We had this exact issue two months ago. Google changed some API permission requirements and existing integrations stopped working. The problem was that our OAuth consent screen wasn’t configured with the new sensitive scopes. Go to Google Cloud Console, navigate to OAuth consent screen, and make sure you’ve added https://www.googleapis.com/auth/calendar and https://www.googleapis.com/auth/calendar.events to your scopes list. After updating, you’ll need to re-authorize the connection in Odoo. Also verify that your service account email has Calendar Editor permissions on the target calendars, not just Viewer access.

Have you checked the API quotas? Sometimes 403 can also mean you’ve hit rate limits. Log into Google Cloud Console and check the Calendar API usage metrics.

Tested this on Odoo 16 Community with Google Workspace Business Standard — clearing the google_calendar_token system parameter and re-authorizing via OAuth resolved our sync failures immediately.

I’ve seen this behavior when the domain-wide delegation isn’t properly configured. Even though you mentioned it’s set up, double-check that the Client ID in your domain-wide delegation matches exactly with the OAuth client ID you’re using in Odoo. Also, the scopes must be comma-separated without spaces in the domain delegation settings. One space can break the entire authorization chain. Another thing to verify is whether your Google Workspace admin recently changed any security policies that might restrict API access. We had a case where the admin enabled context-aware access rules that blocked API calls from certain IP ranges.

Check if you’re using a service account or OAuth2 user credentials. For resource calendar sync in Odoo 14, service accounts need specific configuration. The service account must be granted domain-wide delegation AND the scopes must include calendar.events with write permissions.

This solved it! The issue was indeed the scopes configuration in domain-wide delegation. There was a space after the comma in the scopes list which was causing silent authorization failures. After fixing that and re-authorizing in Odoo, the sync started working immediately. Thanks for the detailed walkthrough!