CONNECT APP
Build with Google Workspace Admin
Developer Tools
- OAuth
MCP
Give your agent Google Workspace Admin tools
Every Google Workspace Admin action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's Google Workspace Admin account for each tool call — you store no tokens.
// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
new URL("https://remote.mcp.pipedream.net/v3"),
{
requestInit: {
headers: {
Authorization: `Bearer ${accessToken}`,
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
"x-pd-app-slug": "google_workspace",
},
},
},
)
const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)
const { tools } = await mcp.listTools()
// e.g. run List Activities By Admin:
const result = await mcp.callTool({
name: "google_workspace-list-activities-by-admin",
arguments: {
applicationName: "Application Name",
userKey: "User Key",
},
})# access_token: mint a short-lived token with the Connect SDK — see the MCP guide
headers = {
"Authorization": f"Bearer {access_token}",
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", # any stable ID for this user in your system
"x-pd-app-slug": "google_workspace",
}
async with streamablehttp_client("https://remote.mcp.pipedream.net/v3", headers=headers) as (read, write, _):
async with ClientSession(read, write) as session:
await session.initialize()
tools = await session.list_tools()
# e.g. run List Activities By Admin:
result = await session.call_tool("google_workspace-list-activities-by-admin", {
"applicationName": "Application Name",
"userKey": "User Key",
})API PROXY
Call the Google Workspace Admin API directly
For an endpoint with no pre-built tool, the Connect proxy forwards your request to the Google Workspace Admin API with the connected user's credentials attached. You store no tokens and write no refresh logic.
const resp = await pd.proxy.get({
externalUserId: "{external_user_id}", // any stable ID for this user in your system
accountId: "apn_xxxxxxx",
url: "https://www.googleapis.com/oauth2/v1/userinfo",
})
// Any allowed Google Workspace Admin endpoint works here. Pipedream attaches the
// connected account's credentials to the outgoing request.# The path segment is the target URL, URL-safe base64 encoded:
# https://www.googleapis.com/oauth2/v1/userinfo
curl "https://api.pipedream.com/v1/connect/{project_id}/proxy/aHR0cHM6Ly93d3cuZ29vZ2xlYXBpcy5jb20vb2F1dGgyL3YxL3VzZXJpbmZv?external_user_id={external_user_id}&account_id=apn_xxxxxxx" \
-H "Authorization: Bearer {access_token}" \
-H "x-pd-environment: production"SDK
Run Google Workspace Admin actions from your backend
Connect a user's Google Workspace Admin account once, then run List Activities By Admin on their behalf from your own code — TypeScript, Python, or plain HTTP.
import { PipedreamClient } from "@pipedream/sdk"
const pd = new PipedreamClient({
projectId: process.env.PIPEDREAM_PROJECT_ID!,
clientId: process.env.PIPEDREAM_CLIENT_ID!,
clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
projectEnvironment: "production",
})
const result = await pd.actions.run({
id: "google_workspace-list-activities-by-admin",
externalUserId: "{external_user_id}", // any stable ID for this user in your system
configuredProps: {
google_workspace: { authProvisionId: "apn_xxxxxxx" },
applicationName: "Application Name",
userKey: "User Key",
},
})from pipedream import Pipedream
pd = Pipedream(
client_id="{oauth_client_id}",
client_secret="{oauth_client_secret}",
project_id="{project_id}",
project_environment="production",
)
result = pd.actions.run(
id="google_workspace-list-activities-by-admin",
external_user_id="{external_user_id}", # any stable ID for this user in your system
configured_props={
"google_workspace": {"authProvisionId": "apn_xxxxxxx"},
"applicationName": "Application Name",
"userKey": "User Key",
},
)curl -X POST https://api.pipedream.com/v1/connect/{project_id}/actions/run \
-H "Content-Type: application/json" \
-H "X-PD-Environment: production" \
-H "Authorization: Bearer {access_token}" \
-d '{
"external_user_id": "{external_user_id}",
"id": "google_workspace-list-activities-by-admin",
"configured_props": {
"google_workspace": { "authProvisionId": "apn_xxxxxxx" },
"applicationName": "Application Name",
"userKey": "User Key"
}
}'TOOLS
Google Workspace Admin actions
On-demand operations your product or agent can configure and run on behalf of a connected user.
-
List Activities By Admin
actionRetrieves a report of all Admin console activities done by a specific administrator. See the docs for more informationRead-onlyv0.0.2 -
List Activities By Event Name
actionRetrieves a report of all activities for a specific event name. See the docs for more informationRead-onlyv0.0.2 -
List Activities By Event Name and Admin
actionRetrieves a report of all activities for a specific event name and admin. See the docs for more informationRead-onlyv0.0.2 -
List All Activities
actionRetrieves a report of all administrative activities done for an account. See the docs for more informationRead-onlyv0.0.2
EVENTS
Google Workspace Admin triggers
Event sources your backend can deploy for users and receive through a webhook.
-
New Admin Activity
triggerEmit new admin activitiesv0.0.5 -
New Admin Activity By Application Name
triggerEmit new admin activities by selected userv0.0.5 -
New Admin Activity By User
triggerEmit new admin activities by selected userv0.0.5 -
New Admin Activity By User And Application Name
triggerEmit new admin activities by selected user and application namev0.0.5
MULTI-APP
Use Google Workspace Admin with other popular apps
Most products don't stop at one integration. Pair Google Workspace Admin with the other apps your users rely on, and ship use cases that span both.
REFERENCE
App details
Reference metadata for the Google Workspace Admin connector in the Pipedream registry.
- App slug
- google_workspace
- Authentication
- OAuth
- Categories
- Developer Tools
- Actions
- 4
- Triggers
- 4
- API proxy
- Available
OAuth scopes
These are the scopes Pipedream's managed Google Workspace Admin OAuth client requests when one of your users connects an account. Supply your own OAuth client to request a different set.
- profile
- https://www.googleapis.com/auth/admin.directory.user.security
- https://apps-apis.google.com/a/feeds/alias/
- https://www.googleapis.com/auth/admin.directory.user
- https://www.googleapis.com/auth/admin.directory.user.alias
- https://www.googleapis.com/auth/cloud-platform
- https://www.googleapis.com/auth/admin.directory.device.chromeos
- https://www.googleapis.com/auth/admin.directory.customer
- https://www.googleapis.com/auth/admin.directory.domain
- https://www.googleapis.com/auth/admin.directory.domain.readonly
- https://apps-apis.google.com/a/feeds/groups/
- https://www.googleapis.com/auth/admin.directory.group
- https://www.googleapis.com/auth/admin.directory.group.member
- https://www.googleapis.com/auth/admin.directory.device.mobile
- https://www.googleapis.com/auth/admin.directory.device.mobile.action
- https://apps-apis.google.com/a/feeds/policies/
- https://www.googleapis.com/auth/admin.directory.orgunit
- https://www.googleapis.com/auth/admin.directory.orgunit.readonly
- https://www.googleapis.com/auth/admin.directory.rolemanagement
- https://apps-apis.google.com/a/feeds/calendar/resource/
- https://www.googleapis.com/auth/admin.directory.resource.calendar
- https://www.googleapis.com/auth/admin.directory.userschema
- https://www.googleapis.com/auth/admin.reports.audit.readonly