Skip to main content
Telara

Integrations

What to set up at the provider first

Organization install starts in the provider console, not in Telara. Complete the steps below, then paste the values into Install for the whole organization.

Admin
Organization install

How it works

One admin action, per-user data

An admin connects once for the whole organization. Each person's requests still run under their own provider identity — Drive, Gmail, OneDrive, and the rest return only that person's data. Telara never reimplements the provider's ACLs.

Mode A — impersonation

The install alone can mint a token for any user. Nobody else signs in. Google Workspace, Box, Dropbox Business.

Mode B — admin consent

Admin consent removes the approval screen. Each person still completes one silent sign-in the first time. Microsoft 365 / Entra, Slack, Atlassian.

Google Workspace

Domain-wide delegation

Prefer a service account in your own GCP project for early installs — it stays internal to your organization and avoids Google's OAuth verification queue. The Marketplace listing and workload identity federation paths are also supported in the product form when you want no key stored in Telara.

1

Create a project and enable APIs

In Google Cloud Console, create or pick a project in your org. Enable Admin SDK API, Google Drive API, and Gmail API (or only the APIs you will grant).
2

Create a service account and download a key

IAM & Admin → Service Accounts → Create. Open the account → Keys → Add key → JSON. Treat the file as organization-wide authority.
3

Copy the numeric Client ID

On the service account detail page, copy the numeric OAuth2 Client ID (not the email). You will paste this into Workspace Admin.
4

Register domain-wide delegation

admin.google.com → Security → Access and data control → API controls → Domain-wide delegation → Add new. Client ID from step 3. OAuth scopes must match the list you will paste into Telara — a mismatch produces unauthorized_client.
5

Hand the values into Telara

Domain (primary Workspace domain), the service account JSON key, and the same scope list registered in step 4. Do not store a delegated_subject — Telara derives the caller per request.

Marketplace domain install and workload identity federation skip pasting a private key but still need the domain and the scopes the install is allowed to use. Use whichever method the product form offers for your tenant.

Microsoft 365 / Entra

App registration + admin consent

Entra has no domain-wide delegation equivalent. Use delegated permissions with admin consent so tokens stay per-user. Do not use application permissions that read every mailbox as one app identity.

1

Register an app

entra.microsoft.com → App registrations → New registration. Supported account types: accounts in any organizational directory. Set the Telara OAuth callback as a Web redirect URI.
2

Create a client secret

Certificates & secrets → New client secret. Copy the value immediately and note the expiry — a lapsed secret breaks every user at once.
3

Add delegated Graph permissions

API permissions → Microsoft Graph → Delegated. Add what you need (for example User.Read, Files.Read, Mail.Read, offline_access), then Grant admin consent for your tenant.
4

Hand the values into Telara

Application (client) ID, client secret, Directory (tenant) ID, and the organization's primary domain.

Verify

Confirm per-user scoping

After the install is recorded, have two different people run the same tool call. Each should see only their own data. If both see the same data, stop and escalate — that is the failure mode this design exists to prevent.