> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/google-workspace-ma/installation/creating-and-authorizing-a-google-workspace-service-account.md).

# Creating and authorizing a Google Workspace service account

Step 1. Create a new user in your Google Workspace instance, and make this user an administrator. This will be the account the FIM service uses to administrator the Google Workspace instance.

Step 2. Using that account, login to the [Google Developers Console](https://console.developers.google.com)

Step 3. Create a new API project

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-8754e2556e452e0bea6142d20d5ee3f712bca68e%2F1-Credentials.PNG?alt=media)

Step 4. Give the API project an appropriate name

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-ce92e9c7bc4a8a7ee3946d57e2176b10806e83ca%2F2-CreateProfile.png?alt=media)

Step 5. When the project has been created, go to the `APIs & Services` page, and select `Credentials`. Create a new set of credentials of the service account key type

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-07a7177cbad6779a84fdf3ad6f9a4b2c0cdf62cb%2F3-CreateCredentials.PNG?alt=media)

Step 6. Select the option to create a new service account, providing a service account name and ID, and assigning the 'service account user' role. Ensure that 'p12' is selected as the key type

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-2b515c95671ac9610ae22d63f9db5dacd4cb357e%2F4-SelectKeyType.PNG?alt=media)

Step 7. Save the resulting p12 file, noting the secret provided. This will be used by the management agent to authenticate to the Google APIs later

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-4a5551ca700883ca2928a7aaa9d76b20d7ef84dd%2F5-PrivateKey.PNG?alt=media)

Step 8. Once the service account has been created, select the option to manage service accounts

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-d5da35204b6cad1cb735a0bd96643f81470759af%2F6-ManageServiceAccounts.PNG?alt=media)

Step 9. Click on the same of the service account to edit it

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-7d8ecb54dae87321e1a44b136c224ac2114c7616%2F6b-EditServiceAccount.png?alt=media)

Step 10. Select the option to edit the service account, enable domain-wide delegation on the account, and provide a product name (this is not seen by end users)

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-84bc4c865f2352f18227acaaa45de478ddf45ad7%2F7-EditServiceAccount.png?alt=media)

Step 11. Return to the service accounts list, and from the list of service accounts, select the option to 'view client ID'

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-e5e3605916e86f218f3a10e56ee822e24f3fd44e%2F9-ViewClientID.png?alt=media)

Step 12. Record the client ID provided, as well as the service account email address. These will be needed later in the configuration process.

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-ad7b579028aa87a0b03c62d757bc056571a3fb00%2F10-GetClientID.png?alt=media)

Step 13. Click on 'library' on the API manager page, and search for the `Admin SDK`, `Gmail`, `Group Settings`, `Google Calendar` and `Classroom` APIs and enable them for use in your project

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-19043c27c5606933c68a024b9dd8f416b1470551%2F9B-EnableAPIs.PNG?alt=media)

Step 14. Log into the google admin console. Select the security option

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-91055d6283086f33bb53c36a4506148d32878fed%2F11-AdminConsole.PNG?alt=media)

Step 15. Expand to the advance settings section, and select Manage API client access

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-f8eb596dacb816ecb1571bff1b502a52014ddb11%2F12-ManageAPIClientAccess.PNG?alt=media)

Step 16. Add a new client by providing the client ID obtained in step 12, and the following string for the API scopes. You can either add all scopes, or choose only the \[\[specific scopes you need|Required-permissions-and-scopes]] based on the object types you want to manage.

```
https://www.googleapis.com/auth/admin.directory.domain.readonly,http://www.google.com/m8/feeds/contacts/,https://www.googleapis.com/auth/admin.directory.user,https://www.googleapis.com/auth/admin.directory.group,https://www.googleapis.com/auth/admin.directory.group.member,https://www.googleapis.com/auth/admin.directory.userschema.readonly,https://www.googleapis.com/auth/apps.groups.settings,https://www.googleapis.com/auth/admin.directory.resource.calendar,https://www.googleapis.com/auth/calendar,https://www.googleapis.com/auth/gmail.settings.basic,https://www.googleapis.com/auth/gmail.settings.sharing,https://www.googleapis.com/auth/classroom.courses,https://www.googleapis.com/auth/classroom.rosters
```

![](https://2977586855-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F167YoOyroarpXK3iBDAV%2Fuploads%2Fgit-blob-cff1c5055c9bbc0684047fb16804c176ec37c883%2F13-AddScopes.PNG?alt=media)

### Troubleshooting

It can take up to 24 hours for domain-wide delegation to take effect. Although in most cases, it takes 5-10 minutes. During this time you may receive an error when trying to create the MA, with an event log message that contains the text `Client is unauthorized to retrieve access tokens using this method`


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/google-workspace-ma/installation/creating-and-authorizing-a-google-workspace-service-account.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
