Skip to main content
Telara

Integrations / Google Cloud Identity

Google Cloud Identity logo

Google Cloud Identity

Google Cloud Identity Groups API for security groups, direct memberships, transitive memberships, and identity-mapped groups.

OAuth 2.0
Indexes
Actions

What Telara does

Capability matrix

Before you connect

Prerequisites

A Google Cloud Identity or Workspace customer.
Super admin who can approve Admin SDK directory access.

Vendor setup

Get the credential

1
Click Connect in Telara
Settings → Integrations → Google Cloud Identity. Telara sends you to Google. You do not create an OAuth client in Google Cloud unless the form asks you to reuse one.
2
Approve as super admin
Sign in with a super admin. On the consent screen, allow the directory permissions this page lists. Click Allow.
3
Return to Telara
Google redirects you back. Finish Connect under Settings → Integrations if it is not already marked connected.

Permissions Telara requests

  • https://www.googleapis.com/auth/cloud-identity.groups.readonly
    OAuth 2.0
  • https://www.googleapis.com/auth/cloud-identity.groups
    OAuth 2.0
  • https://www.googleapis.com/auth/admin.directory.user.readonly
    OAuth 2.0
  • https://www.googleapis.com/auth/admin.directory.user
    OAuth 2.0
  • https://www.googleapis.com/auth/admin.directory.group.readonly
    OAuth 2.0
  • https://www.googleapis.com/auth/admin.directory.group
    OAuth 2.0
  • https://www.googleapis.com/auth/admin.directory.group.member.readonly
    OAuth 2.0
  • https://www.googleapis.com/auth/admin.directory.group.member
    OAuth 2.0

In Telara

Connect in Telara

OAuth 2.0

In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.

Knowledge

What gets indexed

ResourceCoverage
GroupPartial — not every record the vendor holds is synced

Sync

Freshness & sync

ResourceLagDeletions
GroupUp to 1 dayRemoved records disappear on the next full sync

Data handling

Permissions & data handling

The scopes above are the permissions this connector requests. They come from the catalog, not from a hand-written page.

Excluded from semantic search: Group.

After connect

Verify it worked

This connector does not declare a credential probe yet. A saved connection means Telara stored the credential, not that the vendor accepted it.

Honesty

Known limitations

Delegated admins who cannot open the Directory API will consent and still see no users.
Cloud Identity Free vs Premium changes which devices and groups APIs return.