This sounds like a 3rd-party access setting. I'm guessing that if they add the ID of googleforeducommunity.com to their trusted or limited list under Security > Access and data control > API controls they should be able to gain access.
I think the ID is:
49141677375-l1mm34l378slijqmfg31dv2624kj2iss.apps.googleusercontent.com
Edit:
For whoever needs to find an ID to a web app
When you're on the Error 400 screen you can copy the URL and find "client_id=" and whatever is behind it is the ID you can manually add to the list. The ID ends in apps.googleusercontent.com.