I'm trying to register an API endpoint to receive RISC security events from Google and have followed their tutorial for doing this. However, I've been struggling to get a successful response from their side and I always get the following unhelpful error:
HTTP 403 Forbidden
Response payload: {
"error": {
"code": 403,
"message": "The caller does not have permission",
"status": "PERMISSION_DENIED"
}
}
Now, this error message is nowhere mentioned in their error code reference docs. I've tried researching but there are very few resources on the topic. I tried to apply most of the stackoverflow answers on the topic with no success.
I'm pretty sure I configured everything correctly in the Google Cloud Console. For instance, I have enabled the RISC API for my project:

Additionally, I assigned the right roles and access rights to my service account:

I'm also following their code suggestions to generate the JWT for my account and I think it's being correctly generated because when I change something I get a different error. Here's the code for generating the JWT:
String createJwt() {
String issuer = "https://accounts.google.com";
PrivateKey privateKey = myPrivateKey;
Algorithm algorithm = Algorithm.RSA256(null, (RSAPrivateKey) privateKey);
Date issuedAt = new Date();
Date expiresAt = new Date(issuedAt.getTime() + 3600000);
return JWT.create()
.withKeyId("MyPrivateKeyId")
.withIssuer("MyClientEmail")
.withSubject("MyClientEmail")
.withAudience("https://risc.googleapis.com/google.identity.risc.v1beta.RiscManagementService")
.withIssuedAt(issuedAt)
.withExpiresAt(expiresAt)
.sign(algorithm);
}
Does anybody know what I'm doing wrong or have any suggestions to fix the problem?