Google Workspace Domain-wide Delegation

In order for 1Password SaaS Manager to access certain Google APIs you must enable Domain-wide Delegation for SaaS Manager.

Domain-wide Delegation is required for SaaS Manager to make Gmail related API calls, and also for Google Cloud Identity APIs (used for reading and managing device data).

This impacts actions including:

  • Set email forwarding address
  • Assign delegated access to email
  • Set out of office
  • Block or wipe device

Note

This is a once-only task that must be performed by someone with a Google Workspace Super Admin role.

You do not need to reconnect Google after making this change - it will take immediate effect.

  1. Login to the Google Admin console

  2. Go to Security > Access and data control > API Controls

  3. Click Manage Domain Wide Delegation

    Google Admin domain-wide delegation controls

  4. Click Add New

    Google Admin domain-wide delegation controls with Add New selected

  5. Enter the Client ID:

    116083431084425988869

  6. Depending on the features you require, add the following OAuth scopes:

    Gmail related actions:

    https://www.googleapis.com/auth/gmail.settings.sharing

    https://www.googleapis.com/auth/gmail.settings.basic

    Device related actions:

    https://www.googleapis.com/auth/cloud-identity.devices

    Google Admin domain-wide delegation client ID and OAuth scope form

  7. Click Authorize



Published: