Generating OAuth 2.0 Authentication Credentials

The Google Workspace SaaS connector uses the OAuth 2.0 protocol for authentication and authorization of the Google Workspace APIs. It supports the following OAuth 2.0 scenarios:


This is the companion discussion topic for the documentation at https://documentation.sailpoint.com/connectors/saas/googleworkspace/help/saas_connectivity/google_workspace/prereqs_for_oauth_2_0.html

The listing of Scopes within this documentation is needlessly complex + the scopes listed here: Generating OAuth 2.0 Authentication Credentials is incomplete and missing https://www.googleapis.com/auth/admin.directory.group so both account/entitlement aggregation will fail.

For overall visibility it’s good to list which scopes are required for which operation so users can pick and choose but I’d propose keeping a single list of required scopes for full basic functionality + scopes required for CIEM.