
Google Workspace
Use Google Workspace accounts as the Google identity provider for Pomerium-protected applications, with optional Enterprise directory sync for groups.
Overview
Google Workspace is a productivity and identity service. Pomerium can use Google accounts as its identity provider. Pomerium Enterprise directory sync is a separate option for Workspace users and groups.
Using Google Workspace as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.
Google Workspace sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.
How it works
Create a Google Cloud project, configure the consent screen, and create a web OAuth client. Add the exact Pomerium callback. Configure Pomerium with the google provider key, client ID, and client secret.
Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.
Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.
Example
A team creates a web OAuth client in a Google Cloud project for its Workspace domain and registers the exact Pomerium callback URI. Users sign in with Google accounts. Pomerium validates the response and applies route policy.
Considerations
- Google sign-in and Google Workspace directory data are separate concerns. Groups are not a normal custom identity claim.
- Directory sync needs a service account, domain-wide delegation, read-only scopes, and a valid impersonated Workspace user.
- This route does not protect or administer Gmail, Drive, or other Workspace applications.
- Google authenticates the account. The Workspace administrator owns the lifecycle of managed Workspace users and groups.
- A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.
