enterprise-application-connectors · prepared

Google Workspace APIs connector boundary

Official-source OAuth scope, user-consent, service-account, domain-wide delegation, and sensitive-scope boundaries for Google Workspace connectors.

version 1.0.0freshness currentobserved 2026-08-27T01:30:00Z

resource.connector.google-workspace-apis
sha256:879850675d556568d13414a5a5748aa68985a032821b6a5828f5e97d20444f72

Open canonical machine JSON →

Evidence-backed facts

  1. Each Google Workspace API defines OAuth scopes that state the data type and access level requested; a connector must select the narrowest API-specific scope. informative
  2. Write capability depends on the exact API method and granted scope and cannot be inferred from successful authentication or a broader product name. informative
  3. User access uses OAuth consent; server-to-server access can use service accounts, and domain-wide delegation requires Workspace administrator authorization and explicit scopes. informative
  4. Sensitive or restricted scopes can require additional review, and no connector may infer domain-wide access from a service-account credential alone. informative