> For the complete documentation index, see [llms.txt](https://oten.gitbook.io/identity-support/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://oten.gitbook.io/identity-support/integration/provisioning-connector/google-workspace-configuration.md).

# Google Workspace Configuration

{% hint style="info" %}
Auto provisioning integrate with Google workspace documentation

The google workspace account must be the role and permission:

* Permission `resourcemanager.projects.create`
* Role `roles/resourcemanager.organizationAdmin`
  {% endhint %}

### **1 - Auto provisioning from Oten to Google Workspace**&#x20;

**STEP 1: Create a Google Cloud Project**

Login to [Google Cloud](https://console.cloud.google.com/) and create a project or chose an existing project. The project name can be "IdP Auto Provisioning" or whatever you prefer.

*Create new project*

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FWmBtt72eei45IzxfqTI6%2F1.webp?alt=media&amp;token=8ed27118-3bfa-4cd9-b987-10ede8d74d9f" alt=""><figcaption></figcaption></figure>

*Or Choose a current project*

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FZsZmzI84Gi4kW4y4MwKi%2F2.webp?alt=media&amp;token=46cfc16c-33e9-4cd0-827c-d5a2cbf268a9" alt=""><figcaption></figcaption></figure>

#### STEP 2: Enable the Admin SDK API <a href="#step-2-enable-the-admin-sdk-api" id="step-2-enable-the-admin-sdk-api"></a>

* In the `APIs & Services` click `+ENABLE APIS AND SERVICES`

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FMFHHjxMDEz4uYOGEGHbW%2Fimage.webp?alt=media&amp;token=a6610d65-9ba8-4b0f-b5a4-796ee90dadc4" alt=""><figcaption></figcaption></figure>

* In the `Search for APIs & Services` enter `Admin SDK API`

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FJkEKPhe7k1qH0KuCAYiH%2F4.webp?alt=media&amp;token=b148a825-f04d-48de-b2ab-6f04eb28f1fc" alt=""><figcaption></figcaption></figure>

* Click `ENABLE`

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2F5NAezqAGsZFIyBg3Ug8C%2F5.webp?alt=media&amp;token=95729005-ed59-4891-b12c-95b103cff5ae" alt=""><figcaption></figcaption></figure>

#### STEP 3: Create a Service Account <a href="#step-3-create-a-service-account" id="step-3-create-a-service-account"></a>

The service account created here will be used to access the Google Workspace user and group information.

* In the `IAM and Admin` menu select `Service accounts`

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2F7GECNPGchiyJa9U7jAXx%2F6.webp?alt=media&amp;token=193c1869-fbef-4fab-9ae1-3be0bd682edd" alt=""><figcaption></figcaption></figure>

* Click `+CREATE SERVICE ACCOUNT` with suggested service account name: `auto-provisioning`

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FJQZMtVzEFTg3QDgsGv6N%2F7.webp?alt=media&amp;token=432de2b1-8830-4e3b-8ca9-de9633c6115f" alt=""><figcaption></figcaption></figure>

* For newly created service account click `Actions`/dots and select `Manage Keys`

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2Frt072AxH0xpN49Gg0lqd%2F8.webp?alt=media&amp;token=d9956b58-c84d-40d7-ace9-ace99a11277a" alt=""><figcaption></figcaption></figure>

* Click `ADD KEYS` -> `Create New Key.` Choose JSON key type then `CREATE`

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2Fc8eEZ0GEUQ5tSLhOD36e%2F9.webp?alt=media&amp;token=f5c54824-bf2a-483b-8968-7ec98fcfef30" alt=""><figcaption></figcaption></figure>

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FfyogozYv8oE9GoOkZYI7%2F10.webp?alt=media&amp;token=7f65713e-70e6-4ea2-817d-62bdd80fbf3b" alt=""><figcaption></figcaption></figure>

* A JSON file with service account credentials will be downloaded to your computer

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FheQofFgCR8AjhKhtAmov%2F11.webp?alt=media&amp;token=d6b0afe6-0148-4edc-912e-7361e4e08232" alt=""><figcaption></figcaption></figure>

#### STEP 4: Copy the Client ID <a href="#step-4-copy-the-client-id" id="step-4-copy-the-client-id"></a>

Navigate to your Service Account and select `DETAILS` tab > `Advanced Settings`

In the `Domain-wide delegation` section copy the `Client ID`. You will need to grant this Client ID access to the Google Workspace Directory in the next step.

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FuQjqSqw3srvallb2A0Pu%2F12.webp?alt=media&amp;token=6cfa34ec-5b39-49ae-bbe9-dc48b76bf36d" alt=""><figcaption></figcaption></figure>

#### STEP 5: Authorize Service Account on Google Workspace <a href="#step-5-authorize-service-account-on-google-workspace" id="step-5-authorize-service-account-on-google-workspace"></a>

In the Google Workspace Panel ([https://admin.google.com](https://admin.google.com/)):

* Navigate to `Security` → `Access and data control` -> `API controls`

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FFlVGWvFabvGAOCB3cvMO%2F13.webp?alt=media&amp;token=a7ce90d9-bfc3-4c27-a844-e980f7cc8d49" alt=""><figcaption></figcaption></figure>

* Under the `Domain wide delegation` click `MANAGE DOMAIN WIDE DELEGATION`
* Click `Add new` in `API Clients`
* Paste the `Client ID` (copied from previous step)

Paste the following text into `OAuth scopes (comma-delimited)`

`https://www.googleapis.com/auth/admin.directory.user,https://www.googleapis.com/auth/admin.directory.user.alias,https://www.googleapis.com/auth/admin.directory.group,https://www.googleapis.com/auth/admin.directory.group.member`&#x20;

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2F0jLElp58wC3C1m6oOTwl%2F14.webp?alt=media&amp;token=c5f3fdb8-b74e-4288-916d-60f2dd6b8e8f" alt=""><figcaption></figcaption></figure>

* Click `AUTHORIZE` - These scopes grant Service Account read-only access to Google Workspace Directory Users, Groups and Membership.

#### STEP 6: Retrieve the Primary Email <a href="#step-6-retrieve-the-primary-email" id="step-6-retrieve-the-primary-email"></a>

* In Google Workspace ([https://admin.google.com](https://admin.google.com/)), navigate to `Account` -> `Account settings`
* Copy the `Primary admin` email into the clipboard (upper right area) for use in the next step.

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FVtmfzP3cMCWzQORXEwTw%2F15.webp?alt=media&amp;token=54dcf929-eaf3-4406-be3b-51aa43197d68" alt=""><figcaption></figcaption></figure>

#### How to set up in IDP <a href="#add-credential-account-service-key-and-primary-admin-to-oten-admin" id="add-credential-account-service-key-and-primary-admin-to-oten-admin"></a>

* Go to `https://admin.oten.com` → Settings → **Auto provisioning** → click **Add provider**

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2Fj8P63wh9wnZSLoekFyug%2Fimage%20(1).webp?alt=media&amp;token=8f66487c-9ed4-4d09-bff9-a7692b90a0d3" alt=""><figcaption></figcaption></figure>

* In **Add provider** → select **Google Workspace**, input **primary admin email** and upload **service account keys** (JSON file) → click **Add provider**

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FgQ4GWQ3WRs29Sij0uWGn%2Fimage-20260528-063244.png?alt=media&amp;token=3cdabe04-3eff-485d-bad5-1f6502c92b2b" alt=""><figcaption></figcaption></figure>

* After add **Google Workspace provider** success → Click Enable **Google Workspace**

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FPtljzQ914b92ylO8zTLd%2Fimage%20(3).webp?alt=media&amp;token=f4edfa59-2893-4ffd-8ac2-7d1fc39925ae" alt=""><figcaption></figcaption></figure>

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2Fi8FeYnPdqWYl4ji4bfsD%2Fimage%20(4).webp?alt=media&amp;token=849d2917-cc7c-41d4-9aec-59d23f0d33e8" alt=""><figcaption></figcaption></figure>

### **2 - Auto provisioning from Google Workspace  to Oten**

**Add credential (account service key) and primary admin to Oten Admin**

* Go to [https://admin.oten.com](https://admin.oten.com/) → Settings → **Auto provisioning** → click **Add provider**

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2F38FwsX8Mv6K7fFVWvSqV%2Fimage-20260527-104419.png?alt=media&amp;token=697bf39a-a477-4aa2-8aba-69f0b61e92d1" alt=""><figcaption></figcaption></figure>

* In **Add provider** → select **Google Workspace**, input **primary admin email**, choose **direction** and upload **service account keys** (JSON file) → click **Add provider**

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2Fd2iEDlFIjejiT2ZuLA4W%2Fimage-20260528-063244.png?alt=media&amp;token=efc74685-5ed1-4417-9f30-f39f6478bd60" alt=""><figcaption></figcaption></figure>

* After add **Google Workspace provider** success → Click Enable **Google Workspace**

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2Fh4Wipm5fPfWFyA14Qv2S%2Fimage-20260528-063015.png?alt=media&amp;token=22d4885c-1ce7-468e-a625-2b4312da8ab0" alt=""><figcaption></figcaption></figure>

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FrkfZHW4RqEZVz3Bv5cTk%2Fimage-20260528-063114.png?alt=media&amp;token=55722aee-20d7-4946-ab33-dedcc40cdfc3" alt=""><figcaption></figcaption></figure>

#### Google Workspace - the provisioning configuration <a href="#google-workspace-the-provisioning-configuration" id="google-workspace-the-provisioning-configuration"></a>

During synchronization, the value from the trusted source will overwrite the counterpart in the event of a conflict.

<figure><img src="https://40810359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNLjw84bGTVza9xA8NxxB%2Fuploads%2FjZpW3VrohwK2Z6Pk3u6Z%2Fimage-20260612-025655.png?alt=media&amp;token=bedd7f7e-c6f5-4f98-b6b3-77aaa1521ec6" alt=""><figcaption></figcaption></figure>

**Mapping user Google workspace with Oten**

| **Google user**                                       | **Oten account**                                                                                                                                                           | **Description**                                                                                                                                                                                                                     |        |       |                                                      |        |                  |
| ----------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------ | ----- | ---------------------------------------------------- | ------ | ---------------- |
| <p><code>id</code></p><p>(string)</p>                 | `account.external_id`                                                                                                                                                      | Unique identity of Google                                                                                                                                                                                                           |        |       |                                                      |        |                  |
| <p><code>primaryEmail</code></p><p>(string)</p>       | <ul><li><p><code>account.primary\_email</code></p><p>(<strong>emailName</strong> + <strong>domain</strong>)</p></li><li><code>user\_profile.email</code></li></ul><p> </p> | <ul><li>The Oten account <strong>primary\_email</strong> = <strong>email\_name</strong> (<em>the text before @ of Google primary email</em>) <strong>+ organization.domain.</strong></li><li>The Oten user profile email.</li></ul> |        |       |                                                      |        |                  |
| <p><code>isAdmin</code></p><p>(boolean)</p>           | `user_org_role.role_id`                                                                                                                                                    | <ul><li>Google is Admin (true)</li><li>Oten is <code>role:org:org-admin:admin</code></li></ul>                                                                                                                                      |        |       |                                                      |        |                  |
| <p><code>archived</code></p><p>(boolean)</p>          | `account.status`                                                                                                                                                           | <p><strong>Google</strong> <code>archived = true</code> →</p><p><strong>Oten</strong> <code>Soft Deleted</code></p>                                                                                                                 |        |       |                                                      |        |                  |
| <p><code>suspended</code></p><p>(boolean)</p>         | `account.status`                                                                                                                                                           | <p><strong>Google</strong> <code>archived = true</code> →</p><p><strong>Oten</strong> <code>Deleted</code></p>                                                                                                                      |        |       |                                                      |        |                  |
| <p><code>suspensionReason</code></p><p>(string)</p>   |                                                                                                                                                                            | Output only. Has the reason a user account is suspended either by the administrator or by Google at the time of suspension. The property is returned only if the `suspended` property is `true`.                                    |        |       |                                                      |        |                  |
| <p><code>gender</code></p><p>(string)</p>             | `user_profile.gender`                                                                                                                                                      | <p>The user profile gender</p><p><strong>Google</strong> <code>male                                                                                                                                                                 | female | other | unknow</code></p><p><strong>Oten</strong> <code>male | female | other</code></p> |
| <p><code>phones\[].primary</code></p><p>(boolean)</p> |                                                                                                                                                                            | If `true`, this is the user's primary phone number. A user may only have one primary phone number.                                                                                                                                  |        |       |                                                      |        |                  |
| <p><code>phones\[].value</code></p><p>(string)</p>    | `user_profile.phone_number`                                                                                                                                                | A human-readable phone number. It may be in any telephone number format.                                                                                                                                                            |        |       |                                                      |        |                  |
| <p><code>name.displayName</code></p><p>(string)</p>   | `user_profile.display_name`                                                                                                                                                | The user's display name. Limit: 256 characters.                                                                                                                                                                                     |        |       |                                                      |        |                  |
| `name.givenName` (string)                             | `user_profile.first_name`                                                                                                                                                  | The user's first name. Required when creating a user account.                                                                                                                                                                       |        |       |                                                      |        |                  |
| <p><code>name.familyName</code></p><p>(string)</p>    | `user_profile.last_name`                                                                                                                                                   | The user's last name. Required when creating a user account.                                                                                                                                                                        |        |       |                                                      |        |                  |
| <p><code>thumbnailPhotoEtag</code></p><p>(string)</p> | `user_profile.picture_url`                                                                                                                                                 | The user's photo (avatar).                                                                                                                                                                                                          |        |       |                                                      |        |                  |

With **account status** will be mapping to matrix after

<figure><img src="https://media-cdn.atlassian.com/file/ed50c7cc-eb8b-4f73-bb49-885de45d3dee/image/cdn?allowAnimated=true&#x26;client=6a33d8aa-aa31-42c0-aadd-85f1754351f1&#x26;collection=contentId-313360395&#x26;height=125&#x26;max-age=2592000&#x26;mode=full-fit&#x26;source=mediaCard&#x26;token=eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiI2YTMzZDhhYS1hYTMxLTQyYzAtYWFkZC04NWYxNzU0MzUxZjEiLCJhY2Nlc3MiOnsidXJuOmZpbGVzdG9yZTpjb2xsZWN0aW9uOmNvbnRlbnRJZC0zMTMzNjAzOTUiOlsicmVhZCJdfSwiZXhwIjoxNzgxMjM2NTcxLCJuYmYiOjE3ODEyMzM2OTEsImFhSWQiOiI3MTIwMjA6YzRiNDk4ZmQtM2VkZC00NGRkLTk2YzUtZTU3NmFiODQ2ZTI1IiwiaHR0cHM6Ly9pZC5hdGxhc3NpYW4uY29tL2FwcEFjY3JlZGl0ZWQiOmZhbHNlLCJhdXRoVHlwZSI6InNlc3Npb24ifQ.zpSgLHxOg1gTbJ7OmnDjE5Cc_ijcxwAkY0knSb1vtiY&#x26;width=769#media-blob-url=true&#x26;id=ed50c7cc-eb8b-4f73-bb49-885de45d3dee&#x26;clientId=6a33d8aa-aa31-42c0-aadd-85f1754351f1&#x26;contextId=contentId-313360395&#x26;collection=contentId-313360395" alt=""><figcaption></figcaption></figure>

&#x20;

{% hint style="info" %}
**Reference:**

Google Workspace API documentation

* [Develop on Google Workspace  |  Google for Developers](https://developers.google.com/workspace/guides/get-started)
  {% endhint %}
