"com.google.apps.framework.auth.IamPermissionDeniedException" and "The name in the URL does not match the name in the request body" errors

I’m building a Dialogflow ES agent entirely in the Dialogflow console. There is no code involved: the agent only uses intents, contexts and fallback intents created in the Dialogflow console. The Web Demo integration worked at first, but after I changed some settings (I’m not sure which), every integration attempt fails.

Steps to reproduce:

  • Open the agent in the Dialogflow ES console.

  • Go to Integrations.

  • The following orange error pops up 6 times in a row:

com.google.apps.framework.auth.IamPermissionDeniedException: Permission 'dialogflow.agents.get' not granted to cloud-ml-dialogflow-frontend@prod.google.com, because no ALLOW or ALLOW_WITH_LOG rule includes that permission.

  • I click Web Demo (or Dialogflow Messenger) and try to enable it. Another error pops up ([PII Removed by Staff]is my project name/ID):
The name in the URL (projects/(PII Removed by Staff)/locations/global/agent/integrations/webdemo) does not match the name in the request body (projects/(PII Removed by Staff)/agent/integrations/webdemo).

  • Despite the errors, Web Demo appears to be enabled and I receive a link. When I open the link, I get a 404 error:
The requested URL was not found on this server.

Setup:

Dialogflow ES, [Trial or Essentials] edition Agent region: global Google account type: personal Gmail The agent works correctly in the console’s “Try it now” panel

What I’ve tried and still not worked:

  • Granted my account the [your actual roles] role(s) in IAM
  • Confirmed that [service-XXXXXXXX@gcp-sa-dialogflow.iam.gserviceaccount.com] has the Dialogflow Service Agent role (visible after ticking “Include Google-provided role grants” in IAM)
  • The Dialogflow Service Agent exists and has the Dialogflow Service Agent role.
  • Confirmed that the Dialogflow API is enabled for the project
  • Tried incognito window, another browser, signing out of other Google accounts, logging out, …
  • [cloud-ml-dialogflow-frontend@prod.google.com] has Dialogflow API Admin and Dialogflow API Reader on the project.
  • Policy Troubleshooter shows the Allow policy permits dialogflow.agents.get.
  • No IAM Deny policy exists.
  • dialogflow.googleapis.com is enabled.
  • A direct REST request to dialogflow.googleapis.com/v2/projects/PIIRemovedbyStaff/agent succeeds and returns the agent.
  • The issue reproduces with a newly created Dialogflow ES agent.
  • The issue reproduces in Chrome Incognito.
  • The error occurs specifically when opening Integrations; other agent pages remain accessible.

Expected behavior: Integrations page loads normally so built-in integrations such as Web Demo/Dialogflow Messenger can be configured.

How can I fix these errors so that the Web Demo integration works again?