Can you confirm that your runtime agent is using the identity that matches your service account? (account service-[PROJECT_NUMBER]@gcp-sa-aiplatform.iam.gserviceaccount.com).
The ADK agent code has to be deployed to a runtime, and that runtime must use the service account identity which was assigned the IntegrationInvoker role (roles/integrations.integrationInvoker), or you also need to grant this role to whichever identity is running the ADK code.
Thank you for your response @shaaland .
I deployed the agent to agent engine in vertax ia and successfully created a session.
However, I’m not sure which service account is being used at runtime.
Is there a way to verify which identity the runtime is using?
Thank you for the follow-up @oumaima . After reviewing this, we advise reaching out to support. They can then involve specialized team to provide a solution and tailored guidance.
We appreciate you engaging in the forum, and please don’t hesitate to reach out with any future questions.