Setup·7 min read

How to set up a Google Play service account to read and reply to reviews

Create a Google Cloud service account, give it the right Play Console permissions, and use the Google Play Developer API to read and reply to app reviews. With common errors.

To read and answer Google Play reviews from your own tools, Google uses a service account: a robot account that belongs to a Google Cloud project and that you invite to Play Console, like a teammate. It authenticates with a JSON key file.

Setting it up touches two consoles, Google Cloud and Play Console. Here’s the whole path, with the minimal permissions for reviews.

What you need

  • A Google Play developer account where you’re the owner or an admin (to invite users), and the package name of your app, like com.example.app.
  • A Google Cloud project. Any project works; creating a new one called “Play reviews” keeps things tidy. It doesn’t need billing.

Part 1: create the service account in Google Cloud

  1. Enable the API

    In Google Cloud Console, select your project and enable the Google Play Android Developer API.
  2. Create the service account

    Go to IAM & Admin → Service Accounts → Create service account. Give it a name like “play-reviews”. You can skip the optional role and user access steps: Play Console handles the permissions.
  3. Create a JSON key

    Open the new service account → Keys → Add key → Create new key → JSON. A .json file downloads. It contains the private key, so store it like a password.
  4. Copy the service account email

    It looks like [email protected]. You’ll need it in Play Console.

Part 2: give it access in Play Console

  1. Invite the service account

    In Play Console → Users and permissions, click Invite new users and paste the service account email.
  2. Grant only what reviews need

    Under App permissions, add your app(s) and allow View app information (read-only) and Reply to reviews. You don’t need any account-wide permissions. Then click Invite user; a service account doesn’t have to accept anything.

Older Play Console accounts may also show a Setup → API access page for linking a Google Cloud project. If you see it, you can link your project there; on most accounts today, inviting the service account as above is all that’s needed.

Check that it works

Your code exchanges the JSON key for a short-lived access token (OAuth 2.0 with the androidpublisher scope). Google’s client libraries do this for you. Then list the reviews:

GET https://androidpublisher.googleapis.com/androidpublisher/v3/applications/com.example.app/reviews?maxResults=100
Authorization: Bearer <access token>

And reply to one (up to 350 characters):

POST https://androidpublisher.googleapis.com/androidpublisher/v3/applications/com.example.app/reviews/REVIEW_ID:reply
Authorization: Bearer <access token>
Content-Type: application/json

{ "replyText": "Thanks for the report! It's fixed in version 2.4." }

Replies appear on Google Play right away, and the reviewer gets a notification. Replying again to the same review replaces your previous reply.

Limits to know about

  • Only the last 7 days. The API returns reviews with text that were written or edited in the last week. To keep your full history, fetch new reviews regularly and store them. For older reviews, use Play Console’s monthly review reports (Download reports → Reviews).
  • Reviews without text (just stars) aren’t returned by the API.
  • 350 characters per reply. Keep replies short and specific.
  • Quotas. The reviews API has daily request limits that are generous for normal use. Polling every few hours is plenty.

Common errors

ErrorWhat it means
403 The caller does not have permissionThe service account wasn’t invited for this app, lacks “Reply to reviews”, or the permission hasn’t become active yet.
401 / invalid_grantThe JSON key was deleted or disabled in Google Cloud, or your server’s clock is off.
404 Package not foundA typo in the package name, or the app isn’t in this developer account.
400 on replyThe reply is empty or longer than 350 characters.

Keep the key safe

  • Never commit the JSON file to Git or share it in chat.
  • If it might have leaked, delete the key in Google Cloud (Service account → Keys) and create a new one.
  • Give each tool its own service account, so you can remove one without affecting the others.