Skip to main content
See All Integrations

Google Workspace

Use Google Workspace accounts as the Google identity provider for Pomerium-protected applications, with optional Enterprise directory sync for groups.

First-party Pomerium integration guide

Category
Identity Providers

Overview

Google Workspace is a productivity and identity service. Pomerium can use Google accounts as its identity provider. Pomerium Enterprise directory sync is a separate option for Workspace users and groups.

Using Google Workspace as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.

Google Workspace sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.

How it works

Create a Google Cloud project, configure the consent screen, and create a web OAuth client. Add the exact Pomerium callback. Configure Pomerium with the google provider key, client ID, and client secret.

Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.

Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.

Example

A team creates a web OAuth client in a Google Cloud project for its Workspace domain and registers the exact Pomerium callback URI. Users sign in with Google accounts. Pomerium validates the response and applies route policy.

Considerations

  • Google sign-in and Google Workspace directory data are separate concerns. Groups are not a normal custom identity claim.
  • Directory sync needs a service account, domain-wide delegation, read-only scopes, and a valid impersonated Workspace user.
  • This route does not protect or administer Gmail, Drive, or other Workspace applications.
  • Google authenticates the account. The Workspace administrator owns the lifecycle of managed Workspace users and groups.
  • A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.

Sources and official resources

  • Use GitHub as an OAuth 2.0 identity provider for Pomerium-protected applications with a registered callback, client ID, and client secret.

  • Use GitLab.com or GitLab Self-Managed as the identity provider for Pomerium-protected applications through OAuth and OpenID Connect.

  • Connect a compatible OpenID Connect provider to Pomerium with discovery, authorization-code sign-in, identity claims, and route policy.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo