Google's Guide: https://developers.google.com/identity/protocols/oauth2/service-account
Authorization protocol: OAuth 2.0
Initial Google API Set up
This guide walks you through how to set up a Google Service Account with multiple Google APIs when initially registering your app with Google. There is no overarching "Google Workspace Service Account or API" in the Google Developers Console.
If you have previously set up a Service Account, please reference the Service Account guide with the specific API you are looking to add.
User Impersonation tokens
Google Service Accounts allow you to retrieve access tokens for any user in a G Suite / Google Workspace account with user impersonation. To get tokens for a specific user, use the
provider_user_idquery parameter in the Get User Connection API call. See Retrieve user tokens for more information.
- In the Xkit platform, click "New Connector" in the sidebar.
- Click "Google Workspace Service Account".
- Next, in a separate window, visit the Google Cloud Platform.
- Click "Create Project", enter the name of your application and click "Create".
- From the Google Service Accounts page, click on your project.
- Click "+ Create Service Account" at the top of the page.
- Enter the requested "Service account details" and click "Create".
- Continue through the "Service account permissions" and then click "Done" on the "Grant users access to this service account" to create the service account.
- Click on the recently created service account.
- Scroll down and click on "Add Key" and then "Create new key" to download the JSON file.
- Use the sidebar to go to the "API & Services" dashboard.
- Click "Enable APIs and Services".
- Search for the APIs you require in the Library and click "Enable".
- Return to the Xkit Google Workspace Service Account connector page.
- Click "Select File" and upload the downloaded JSON file; the info will populate in the Xkit fields.
- Click "Save" to update the service provider settings.
- Customize the "Catalog Settings" if desired and click "Save".
- Select the requested scopes and click "Save".
You've now successfully connected multiple APIs through a Service Account using Xkit!
You'll note that the
https://www.googleapis.com/auth/admin.directory.user.readonly scope is required in order to use Google Service Accounts.
Supplying this scope gives you read-only access to the Directory API of the Admin SDK. In order to retrieve tokens for each individual user in a Google Workspace / G Suite organization, you need to:
- Enable the Admin SDK for your application in the developer console
- Call the List Users endpoint to get a list of all users in an organization
- Use each user's email address in the
provider_user_idquery parameter in the Get User Connection API to retrieve an access token for each user
Each individual access token will enable you to impersonate the specific user.
Updated about 1 year ago