Skip to main content
Connector guides

Connect Google Workspace

Google Workspace is the identity layer for the businesses that run on it — every user account, every group, every managed Chromebook and every mailbox setting lives there. StackJack connects to it…

Written By Christopher Scaminaci

Last updated 6 days ago

Google Workspace is the identity layer for the businesses that run on it — every user account, every group, every managed Chromebook and every mailbox setting lives there. StackJack connects to it through Google's official administration APIs, so your AI can answer questions about a customer's Workspace domain and make changes to it without anyone opening the Admin console.

Connecting Google Workspace gives your AI a set of gws_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Look up users, list who belongs to a group, and check whether someone has access
  • Create, suspend, restore and delete user accounts, and move people between organizational units
  • Manage groups, group aliases, membership and posting policy, including nested groups
  • Build and reorganize the organizational unit tree that policy is applied to
  • Manage enrolled Chromebooks and mobile devices, including remote commands and wipes
  • Audit who holds administrator roles, and who granted them
  • Investigate account security — the third-party apps a person has authorized, their app passwords, and their 2-step verification state
  • Read the audit log and the usage reports behind questions like "who has not signed in for months?"
  • Manage mail domains, domain aliases, meeting rooms, licence assignments and shared drives
  • Work with Vault matters, legal holds and exports, and with managed-Chrome policy
  • Administer an individual mailbox's settings — forwarding, delegates, filters, send-as addresses, vacation replies, IMAP and POP, and S/MIME or client-side-encryption certificates

Grant one or more of the optional permission groups in step 5 and the same connection also reaches:

  • Reseller and Cloud Channel — the subscriptions, customers, entitlements, offers and billing surfaces you sell Google Workspace through, if you are a Google partner
  • Cloud Identity — dynamic and security groups, device and device-user inventory, SAML and OIDC single sign-on profiles, and organization policies
  • Chrome Management — browser and ChromeOS telemetry, installed-app and extension inventory, managed Chrome profiles and security-insight reports
  • Mail content — reading, searching, sending, importing and labelling a named person's mail, and downloading its attachments
  • Drive files — a named person's files and folders, sharing and permissions, comments and revisions, and downloading or exporting file contents
  • Calendar — a named person's calendars, events, sharing rules and free/busy lookups
  • Contacts — a named person's contacts and contact groups, plus Workspace directory search
  • Tasks, Chat, Meet and Keep — task lists and tasks; Chat spaces, membership, messages, reactions and pins; meeting spaces, conference records, participants, recordings and transcripts; and Keep notes with their sharing and attachments

That mailbox-settings group is worth calling out for security work. Four of those reads together answer "has this mailbox been tampered with?" — auto-forwarding, registered forwarding addresses, filters, and delegates. They are the four places an intruder sets up to keep reading someone's mail after the password has been changed, they are all available on the Free tier, and checking them by hand across a domain is exactly the tedious work an AI assistant is good at.

The full inventory, with the plan each tool needs, is in the tool reference.

What you will need

  • A Google Cloud project you are willing to use for automation
  • A super-administrator account in the Workspace domain
  • About fifteen minutes, split across two different Google consoles

The setup is a little longer than most connectors because Google deliberately separates the two halves: you create the automation identity in one console, then authorize it in the other. Both halves are required, and a connector that has only the first will save successfully and then fail every request.

How the connection works

Rather than storing an administrator's password, StackJack uses a service account with domain-wide delegation. A service account is a non-human identity you create in Google Cloud. Domain-wide delegation is the permission, granted separately in the Admin console, that lets that identity act as one of your administrators.

Two consequences are worth knowing up front:

  • StackJack acts as a person. You nominate a super-administrator for it to act as, and that person is who appears as the actor in your Google audit log. Their password is never used and nothing is ever sent to them. A dedicated automation admin who will not be offboarded is the tidiest choice.
  • Access is granted in groups, and each group is all or nothing. Google matches the granted permissions exactly. Step 5 gives you one required block and several optional ones; if an entry is missing from a block, every tool that block unlocks fails with the same error, not just the ones needing it — while the other blocks carry on working. This is the single most common reason a setup does not work.
  • You can come back and add a group later. Nothing already working breaks when you paste another block, and nothing needs re-entering in StackJack. Start with the required block and add what you need.

Setup

1. Create a Google Cloud project

Sign in to the Google Cloud console with an account in the same organization as the Workspace domain, and create a project — or pick an existing one you are happy to use for automation.

2. Enable the APIs

In APIs & Services → Library, enable each of these. They cover the core administration tools every connection gets:

Admin SDK API · Gmail API · Google Drive API · Google Vault API · Google Workspace Alert Center API · Chrome Policy API · Enterprise License Manager API · Groups Settings API · Data Transfer API

Enable these ten as well if you want any of the optional permission groups from step 5:

Google Workspace Reseller API · Cloud Channel API · Cloud Identity API · Chrome Management API · Google Calendar API · People API · Google Tasks API · Google Chat API · Google Meet API · Google Keep API

The mail-content and Drive-file tools need nothing extra here — they use the Gmail API and Google Drive API already in the first list.

Enable everything you might want now even if you only plan to use some. An API you skipped returns an error that reads like a permissions problem, and tracking that back to a switch you never flipped is a frustrating half hour.

3. Create a service account and download its key

In APIs & Services → Credentials, choose Create Credentials → Service account and give it a name that identifies StackJack.

Open the new service account, go to its Keys tab, and choose Add Key → Create new key → JSON. The file downloads once and cannot be downloaded again — treat it like a password.

4. Copy the numeric Client ID

Still on the service account, open the Details tab and copy the Client ID — the long number, not the email address.

This trips up more setups than anything else. The next step asks for the number; pasting the email there produces a connector that saves cleanly and then fails every call with an error that says nothing about which value was wrong.

5. Authorize it in the Admin console

In the Google Admin console, go to Security → Access and data control → API controls → Domain-wide delegation and choose Add new.

Paste the numeric Client ID from step 4, then paste the whole required list below into the OAuth scopes box in one go:

https://www.googleapis.com/auth/admin.directory.user,
https://www.googleapis.com/auth/admin.directory.user.alias,
https://www.googleapis.com/auth/admin.directory.user.security,
https://www.googleapis.com/auth/admin.directory.userschema,
https://www.googleapis.com/auth/admin.directory.group,
https://www.googleapis.com/auth/admin.directory.group.member,
https://www.googleapis.com/auth/admin.directory.orgunit,
https://www.googleapis.com/auth/admin.directory.device.chromeos,
https://www.googleapis.com/auth/admin.directory.device.mobile,
https://www.googleapis.com/auth/admin.directory.device.mobile.action,
https://www.googleapis.com/auth/admin.directory.domain,
https://www.googleapis.com/auth/admin.directory.rolemanagement,
https://www.googleapis.com/auth/admin.directory.resource.calendar,
https://www.googleapis.com/auth/admin.directory.customer,
https://www.googleapis.com/auth/admin.reports.audit.readonly,
https://www.googleapis.com/auth/admin.reports.usage.readonly,
https://www.googleapis.com/auth/apps.groups.settings,
https://www.googleapis.com/auth/apps.licensing,
https://www.googleapis.com/auth/apps.alerts,
https://www.googleapis.com/auth/admin.datatransfer,
https://www.googleapis.com/auth/ediscovery,
https://www.googleapis.com/auth/chrome.management.policy,
https://www.googleapis.com/auth/gmail.settings.basic,
https://www.googleapis.com/auth/gmail.settings.sharing,
https://www.googleapis.com/auth/drive

Paste that list complete. Trimming it to only what you think you need is the mistake this page warns about twice, because the failure it causes looks like a broken credential rather than a missing permission.

Optional scope groups

Everything above is required. Each block below is optional and unlocks one more family of tools. Paste a block into the same OAuth scopes box only if you want those tools — and paste it whole, because Google grants each block all or nothing. Leaving a block out costs you nothing else; the tools it would have unlocked simply report that the permission was not granted.

Adding a block later is a change in the Admin console only. Nothing in StackJack needs re-entering, and nothing already working stops.

Reseller and Cloud Channel — the subscriptions, customers, entitlements, offers and billing surfaces a Google partner sells through. See the If you are a Google reseller section further down this page; on a connection that is not a reseller's, this block grants nothing usable.

https://www.googleapis.com/auth/apps.order,
https://www.googleapis.com/auth/apps.reports.usage.readonly

Cloud Identity — dynamic and security groups, device and device-user inventory, SAML and OIDC single sign-on profiles, organization policies, and user invitations.

https://www.googleapis.com/auth/cloud-identity.groups,
https://www.googleapis.com/auth/cloud-identity.devices,
https://www.googleapis.com/auth/cloud-identity.devices.lookup,
https://www.googleapis.com/auth/cloud-identity.inboundsso,
https://www.googleapis.com/auth/cloud-identity.policies,
https://www.googleapis.com/auth/cloud-identity.allowlisteddomains,
https://www.googleapis.com/auth/cloud-identity.userinvitations

Chrome Management — browser and ChromeOS telemetry, installed-app and extension inventory, managed Chrome profiles, security-insight reports, and the connector configurations that feed Chrome security events to a third-party tool.

https://www.googleapis.com/auth/chrome.management.reports.readonly,
https://www.googleapis.com/auth/chrome.management.telemetry.readonly,
https://www.googleapis.com/auth/chrome.management.appdetails.readonly,
https://www.googleapis.com/auth/chrome.management.profiles,
https://www.googleapis.com/auth/chrome.management.securityinsights,
https://www.googleapis.com/auth/chrome.management.connectors

Mail content — reading, searching, sending, importing and labelling a named person's mail, and downloading its attachments. This is the one block that reaches your customers' actual email. Grant it deliberately, and read the note at the end of this page first.

https://mail.google.com/

Calendar — a named person's calendars, events, sharing rules and free/busy lookups.

https://www.googleapis.com/auth/calendar

People and contacts — a named person's contacts and contact groups, plus Workspace directory search.

https://www.googleapis.com/auth/contacts,
https://www.googleapis.com/auth/contacts.other.readonly,
https://www.googleapis.com/auth/directory.readonly

Tasks — a named person's task lists and tasks.

https://www.googleapis.com/auth/tasks

Google Chat — spaces, membership, messages, reactions and pins, plus each person's own Chat state. The three admin entries at the end are what let space and message search run across the domain.

https://www.googleapis.com/auth/chat.spaces,
https://www.googleapis.com/auth/chat.memberships,
https://www.googleapis.com/auth/chat.messages,
https://www.googleapis.com/auth/chat.messages.reactions,
https://www.googleapis.com/auth/chat.customemojis,
https://www.googleapis.com/auth/chat.users.readstate,
https://www.googleapis.com/auth/chat.users.spacesettings,
https://www.googleapis.com/auth/chat.users.availability,
https://www.googleapis.com/auth/chat.users.sections,
https://www.googleapis.com/auth/chat.spaces.pins,
https://www.googleapis.com/auth/chat.delete,
https://www.googleapis.com/auth/chat.admin.spaces,
https://www.googleapis.com/auth/chat.admin.memberships,
https://www.googleapis.com/auth/chat.admin.delete

Google Meet — meeting spaces, conference records, participants, recordings and transcripts.

https://www.googleapis.com/auth/meetings.space.created,
https://www.googleapis.com/auth/meetings.space.readonly,
https://www.googleapis.com/auth/meetings.space.settings

Google Keep — a named person's notes, their sharing and their attachments. Google restricts the Keep API to Workspace administrators.

https://www.googleapis.com/auth/keep

Drive apps — one tool, gws_list_drive_apps, which lists the third-party apps a person has connected to their own Drive. Google accepts a single scope on that one route and it is not in the required list, which is why it has a block of its own. Everything else about Drive, including reading one connected app by its ID, works without this.

https://www.googleapis.com/auth/drive.apps.readonly

Drive files needs no block. Access to Drive is already in the required list at the top of this step, so the file tools — including downloading and exporting file contents — work on any connection without anything being added here. The Drive apps block just above is the one exception, and it covers a single tool.

6. Enter the details in StackJack

Open the downloaded JSON key file in a text editor and copy two values out of it:

StackJack fieldValue from the key file
Service Account Emailclient_email — it ends in .iam.gserviceaccount.com
Private Keyprivate_key — the whole block, including the BEGIN and END lines
Admin Email to Impersonate(not in the file) the super-administrator StackJack should act as
Customer ID(optional) leave blank unless Google support has told you otherwise
Cloud Channel account ID(optional) only for resellers using Cloud Channel — the account number from your Partner Sales Console

The private key is a long, multi-line block. If you copy it straight out of the JSON file, the line breaks appear as the two characters \n — paste it that way anyway, StackJack handles it.

Google's endpoints are global and fixed, so there is no URL to enter.

If you are a Google reseller

Skip this section unless you resell Google Workspace.

A reseller connection is an ordinary connection with one difference: the service account lives in your own Workspace, and the administrator you nominate in step 6 is an administrator of your reseller Workspace who has access to the Partner Sales Console. A customer's own super-administrator will not do — Google refuses the reseller permissions for them, and the failure looks exactly like a missing scope.

Set one up like this:

  1. Follow the setup above in your own Workspace domain, not a customer's.
  2. In step 5, paste the Reseller and Cloud Channel block alongside the required list.
  3. In step 6, fill in the Cloud Channel account ID field with the account number shown in your Partner Sales Console. Google publishes that number nowhere an integration can read it, so the Cloud Channel tools stop and tell you rather than guessing. The Reseller tools do not need it.

Reaching a resold customer

Once that connection exists, the customer-scoped administration tools take an optional customerId — your resold customer's numeric Google customer ID. Pass it and the tool acts on that customer's domain for that one call; leave it out and the tool acts on your own domain. That covers users, groups, org units, devices, domains, roles, custom fields, reports, licences, Chrome policy, alerts, data transfers, calendar resources (meeting rooms and buildings), Cloud Identity and Chrome Management.

Mailboxes and files are the exception, and it is not a small one. Mail, Drive file, calendar, contact, task, chat, meet and keep tools act on one named person's data, and Google will only let a service account act as a person if that service account has been authorized inside that person's own domain. A reseller connection cannot reach them however the customerId is set.

So, for every customer whose mailboxes or files you manage, add a connection per customer (Connectors → Google Workspace → Add connection). Each one is the setup above, run in that customer's Admin console. You can reuse the same service-account key file across them or use a separate one per customer — Google's domain-wide delegation is granted per domain either way.

What your plan includes

TierWhat you get
FreeEvery read tool — users, groups, membership, organizational units, devices, domains, roles, security state, reports, rooms, licences, alerts, Vault and Chrome policy; plus, in whichever optional groups you granted, reading reseller subscriptions and Cloud Channel customers, entitlements and offers, Cloud Identity groups, devices and single sign-on, Chrome Management telemetry and app inventory, mail messages and attachments, Drive files and their sharing, calendars and events, contacts and directory search, tasks, Chat spaces and messages, Meet records and transcripts, and Keep notes
ProEverything in Free, plus every write: creating and deleting accounts, managing groups, devices, roles, policy, licences, holds and shared drives; plus reseller and Cloud Channel subscription, entitlement and repricing changes, Cloud Identity and single sign-on changes, Chrome profile commands, sending and deleting mail, creating and deleting files and permissions, calendar and event changes, contact changes, task changes, Chat space and message changes, Meet space changes, and Keep note changes
BusinessThe Pro tool set with higher monthly usage limits

The access granted in step 5 is read-and-write even on the Free tier. That is deliberate: re-granting delegation later would mean another manual trip to the Admin console when you upgrade. Your StackJack plan is what restricts a Free connection to read-only tools.

Tools that change things

Some tools make changes that are hard or impossible to undo. These require the Pro tier and are marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and grant only what you want an AI to reach:

  • Deleting a user. Google keeps the account restorable for 20 days, then it is gone. Transfer their Drive and Calendar data first — deleting does not reassign it. If the intent is simply to block access, suspending the account is instantly reversible and keeps everything.
  • Deleting a group. Unlike a user, a deleted group has no restore window. Its archived conversations are destroyed, its address starts bouncing, and every permission granted through it disappears — which can silently remove access for everyone who held it that way.
  • Granting super-administrator. This hands an account total control of the domain.
  • Signing a user out everywhere. Every session on every device ends immediately, including phones.
  • Removing someone from a group. Treat this as an access revocation, not a mailing-list edit: they lose the shared drives, calendars and documents the group granted.
  • Wiping a device. For a phone there are two wipes and they are very different: one removes only the work account and its data, the other factory-resets the whole handset including the owner's personal photos and apps. For a Chromebook, deprovisioning cannot be undone through the API — the hardware has to be wiped and re-enrolled by hand.
  • Releasing a legal hold in Vault. Once a hold is released, the data it was preserving can be deleted if nothing else is preserving it. This is a decision for whoever owns the legal obligation, not a tidy-up.
  • Revoking a licence. The person loses the paid service. For the main Workspace licence that means losing access to their own mail and Drive, while the account still exists.
  • Assigning a licence. This one adds rather than removes, but it puts a charge on the customer's next Google bill, so it carries the same marking.
  • Removing a managed network or certificate from Chrome devices. Devices relying on it lose their connection or start showing certificate warnings — and a device that cannot connect cannot be fixed remotely.
  • Deleting a shared drive. By default Google refuses to delete a drive that still contains files. There is an option to override that and delete the contents too; it removes an entire team's documents in one step.
  • Turning on mail forwarding, or adding a forwarding address. Forwarding sends a copy of every incoming message to another address. It is a legitimate feature and it is also the most common way an intruder keeps reading a mailbox after being locked out, so both halves carry the marking. Turning forwarding off uses the same tool, and is the usual response when you find it switched on unexpectedly.
  • Adding a delegate to a mailbox. A delegate can read, search and send as the mailbox owner. Confirm the owner actually asked for it.
  • Creating a mail filter. A filter acts automatically on mail arriving from then on, and it can be set to delete or hide matching messages without telling the owner. Deleting a filter carries the same marking, because its rules cannot be recovered.
  • Adding or verifying a send-as address. If the address is outside the domain, Google immediately emails a verification message to whoever owns it. That cannot be recalled, and running the tool again sends again.
  • Turning on a vacation auto-reply. The text you set is sent automatically to everyone who writes in, including people outside the organization.
  • Disabling a client-side-encryption key pair. Mail already encrypted with that key stops being readable until it is switched back on. Move the user to a different key first.

The optional groups add more of the same kind:

  • Anything that changes a resold customer's subscription or entitlement. Creating, changing, suspending, activating, transferring or cancelling a subscription, and every repricing change, moves money on your Google bill and theirs. Every one of them carries the same marking.
  • Deleting mail, files, calendars, events, contacts, Chat messages, Chat spaces or Keep notes. Where Google's delete skips the trash the removal is permanent, and the tool description says so; where a trash exists, the trash tool is the reversible one to reach for.
  • Sending a message. Sending mail or posting a Chat message reaches a human immediately and cannot be recalled.
  • Anything that emails or notifies people. Calendar event writes can email every attendee; the tools default that off, and say so when a non-default value turns it back on. Sharing a file, a calendar or a Keep note grants someone access — treat those as access grants, not tidy-ups.
  • Ending an active Meet conference. Everyone in the meeting is disconnected at once.

You will also notice pairs of tools that look similar — one named Replace and one named Update Fields. The Replace variants overwrite the entire record, clearing anything not included, which is why they are marked as changing things. The Update Fields variants change only what you name and leave the rest alone. For everyday edits, the Update Fields tool is the one you want.

See the generated Google Workspace tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Troubleshooting

"Google refused the delegation" / unauthorized_client Almost always step 4 or step 5. Either the domain-wide delegation entry has the service account's email address instead of its numeric Client ID, or the permission list is incomplete. Re-open Security → Access and data control → API controls → Domain-wide delegation, check the Client ID matches the number on the service account's Details tab, and re-paste the whole list from step 5.

One area fails and everything else works That is the per-group grant doing its job: the block covering that area is missing or incomplete. The error message names the group and the exact permissions to paste. Re-paste that block whole — a block granted partially fails the same way as one not granted at all.

"This needs your Cloud Channel account ID" Only the Cloud Channel tools ask for it, and only a reseller has one. Copy the account number from your Partner Sales Console into the Cloud Channel account ID field in step 6. There is nothing to fall back on: Google does not publish that number anywhere an integration can read it.

A reseller connection cannot open a resold customer's mailbox or files Expected. Passing customerId reaches that customer's directory, not their people's data — Google requires the service account to be authorized inside the customer's own domain for that. Add a connection for that customer, following the setup above in their Admin console.

"Google rejected the administrator account" / invalid_grant The address you entered does not exist in the domain, is suspended, or is no longer a super-administrator. Check it in the Admin console and re-enter it in StackJack if it changed.

"The Google API this tool needs is not switched on" Go back to step 2 and enable the API named in the error. This reads like a permissions problem but is not.

"Google accepted the connection but refused this operation" The connection is fine, so this is about reach. Most often the account you nominated is not a full super-administrator and lacks the privilege that area needs. Check its role in the Admin console first.

"Google is rate-limiting requests" Two different limits produce this, and only one is yours to change. If the message mentions your project's quota, you can raise it in the Google Cloud console under IAM & Admin → Quotas. If it mentions your Workspace account, that limit is fixed by Google and cannot be raised — spread bulk work out rather than running wide sweeps back to back. Either way StackJack paces requests and backs off on its own, so no action is usually needed.

Reports look empty or out of date Google's audit and usage data lags behind real time — commonly by hours, and for some reports by up to three days. A report that does not yet show something you know happened is usually too early rather than wrong.

Mail and file contents

This connector can now read mail messages and file contents, and the two are reached differently.

Mail content needs its own permission. Reading, searching or sending someone's mail requires the Mail content block from step 5, which no existing connection has until you paste it. There is no way to reach a message without it, and there is no tool that reads mail across the domain in one call: every mail-content tool names the mailbox owner explicitly and acts as that person.

File content needs nothing added. Access to Drive has been in the required list since this connector shipped, so the file tools — including downloading and exporting a file's contents — work on every existing connection from the moment they appear. If that is more than you want an AI assistant reaching, restrict it in StackJack rather than in Google. Which control does it depends on how the connection is made: for an endpoint's own credentials it is that endpoint's tool selection, and for someone signed in through StackJack it is the tool role on their membership.

Either way, your Google audit log records the administrator you nominated in step 6 as the actor, not StackJack and not the mailbox or file owner. That is how domain-wide delegation works everywhere, and it is why a dedicated automation admin — rather than a real person's account — is worth the five minutes it takes to create.

Several customers

Some MSPs need one Google Workspace connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.

What is not included

One capability is held back on purpose. Google offers a way to permanently destroy a client-side-encryption key pair, which makes every message ever encrypted with it unreadable forever, with no undo and no support path. StackJack does not expose it. Disabling a key pair — which is reversible — is as far as the connector goes; permanent destruction stays a deliberate, human action in the Admin console.

Uploading file contents is not supported. The connector can create a file, a folder or an empty Doc or Sheet, rename it, move it, share it, trash it and read or export what is in it — but it cannot push bytes up. Google requires a different kind of request for that than this connector makes, so a file's contents are set in Drive itself.

Context-Aware Access is out of scope. Its rules live in the Google Cloud organization rather than in Workspace and need a different kind of credential entirely, so no tool here reads or changes them.

Google Workspace tools

gws_ · 652 tools · Free 303 · Pro 349

Users

ToolWhat it does
gws_create_user
Pro · Write
Create a user.
gws_create_user_alias
Pro · Write
Add an alias address to a user.
gws_delete_user
Pro · Destructive
Delete a user account.
gws_delete_user_alias
Pro · Destructive
Remove an alias address from a user.
gws_delete_user_photo
Pro · Destructive
Remove a user's profile photo, reverting them to the default placeholder.
gws_get_user
Free · Read-only
Retrieve one user.
gws_get_user_photo
Free · Read-only
Retrieve a user's profile photo.
gws_list_user_aliases
Free · Read-only
List a user's alias email addresses — additional addresses that deliver to the same mailbox.
gws_list_users
Free · Read-only
List users in the Workspace account.
gws_make_user_admin
Pro · Destructive
Grant or revoke SUPER-ADMINISTRATOR status.
gws_patch_user
Pro · Write
Update named fields on a user, merging rather than replacing — omitted fields are left alone.
gws_sign_out_user
Pro · Destructive
Invalidate EVERY active web and device session for a user, signing them out everywhere at once.
gws_undelete_user
Pro · Write
Restore a user deleted within the last 20 days.
gws_update_user
Pro · Destructive
REPLACE a user's record wholesale.
gws_update_user_photo
Pro · Write
Set a user's profile photo.

Groups

ToolWhat it does
gws_create_group
Pro · Write
Create a group.
gws_create_group_alias
Pro · Write
Add an alias address to a group.
gws_delete_group
Pro · Destructive
Delete a group.
gws_delete_group_alias
Pro · Destructive
Remove an alias address from a group.
gws_get_group
Free · Read-only
Retrieve one group.
gws_list_group_aliases
Free · Read-only
List a group's alias addresses — additional addresses that deliver to the same group.
gws_list_groups
Free · Read-only
List groups.
gws_patch_group
Pro · Write
Update named fields on a group, merging rather than replacing — omitted fields are left alone.
gws_update_group
Pro · Destructive
REPLACE a group's record wholesale.

Group Members

ToolWhat it does
gws_add_group_member
Pro · Write
Add a member to a group.
gws_check_group_membership
Free · Read-only
Answer whether a user is a member of a group, returning {"isMember":true|false}.
gws_get_group_member
Free · Read-only
Retrieve one membership record, carrying the member's role (OWNER, MANAGER or MEMBER), type (USER, GROUP, CUSTOMER or EXTERNAL) and mail delivery preference.
gws_list_group_members
Free · Read-only
List a group's members.
gws_patch_group_member
Pro · Write
Update named fields on a membership, merging rather than replacing.
gws_remove_group_member
Pro · Destructive
Remove a member from a group.
gws_update_group_member
Pro · Destructive
REPLACE a membership record wholesale.

Organizational Units

ToolWhat it does
gws_create_org_unit
Pro · Write
Create an organizational unit.
gws_delete_org_unit
Pro · Destructive
Delete an organizational unit.
gws_get_org_unit
Free · Read-only
Retrieve one organizational unit by its full path, e.g. "/Sales/West".
gws_list_org_units
Free · Read-only
List organizational units.
gws_patch_org_unit
Pro · Write
Update named fields on an organizational unit, merging rather than replacing.
gws_update_org_unit
Pro · Destructive
REPLACE an organizational unit's record wholesale.

ChromeOS Devices

ToolWhat it does
gws_batch_change_chromeos_device_status
Pro · Destructive
Change the enrollment status of a batch of ChromeOS devices.
gws_count_chromeos_devices
Free · Read-only
Count ChromeOS devices without listing them.
gws_get_chromeos_device
Free · Read-only
Retrieve one ChromeOS device by its deviceId.
gws_get_chromeos_device_command
Free · Read-only
Check the outcome of a remote command previously sent with gws_issue_chromeos_device_command.
gws_issue_chromeos_device_command
Pro · Destructive
Send a remote command to one ChromeOS device.
gws_list_chromeos_devices
Free · Read-only
List enrolled ChromeOS devices.
gws_move_chromeos_devices_to_org_unit
Pro · Write
Move up to 50 ChromeOS devices into a different organizational unit in one call.
gws_patch_chromeos_device
Pro · Write
Update named annotation fields on a ChromeOS device, merging rather than replacing.
gws_update_chromeos_device
Pro · Destructive
REPLACE a ChromeOS device's editable record wholesale.

Mobile Devices

ToolWhat it does
gws_delete_mobile_device
Pro · Destructive
Remove a mobile device from management.
gws_get_mobile_device
Free · Read-only
Retrieve one enrolled mobile device by its resourceId.
gws_issue_mobile_device_action
Pro · Destructive
Send a management action to an enrolled mobile device.
gws_list_mobile_devices
Free · Read-only
List enrolled mobile devices.

Domains

ToolWhat it does
gws_create_domain
Pro · Write
Add a secondary domain to the Workspace account.
gws_create_domain_alias
Pro · Write
Add a domain alias, giving every existing mailbox in the parent domain a second address at the alias domain.
gws_delete_domain
Pro · Destructive
Remove a secondary domain from the Workspace account.
gws_delete_domain_alias
Pro · Destructive
Remove a domain alias.
gws_get_domain
Free · Read-only
Retrieve one domain by name, e.g. "example.com".
gws_get_domain_alias
Free · Read-only
Retrieve one domain alias by name, e.g. "example.net".
gws_list_domain_aliases
Free · Read-only
List domain aliases.
gws_list_domains
Free · Read-only
List every domain the Workspace account owns.

Chrome Policy

ToolWhat it does
gws_batch_delete_chrome_group_policies
Pro · Destructive
Remove policy values from one or more groups.
gws_batch_inherit_chrome_org_unit_policies
Pro · Destructive
Reset policies on organizational units so they inherit from their parent again.
gws_batch_modify_chrome_group_policies
Pro · Destructive
Set Chrome policy values on one or more groups.
gws_batch_modify_chrome_org_unit_policies
Pro · Destructive
Set Chrome policy values on one or more organizational units.
gws_define_chrome_certificate
Pro · Write
Add a certificate for managed Chrome devices to trust.
gws_define_chrome_network
Pro · Write
Define a network (Wi-Fi, Ethernet or VPN) that managed Chrome devices can be given.
gws_get_chrome_policy_schema
Free · Read-only
Retrieve one Chrome policy schema by name, e.g. "chrome.users.AllowDinosaurEasterEgg", with its field definitions, legal values, and any notices about settings Google has deprecated.
gws_list_chrome_group_policy_priority
Free · Read-only
Read the priority order of groups for one policy schema — which group's setting wins when a user belongs to several groups that all set it.
gws_list_chrome_policy_schemas
Free · Read-only
List the Chrome policy schemas available to the customer — the vocabulary of every setting that can be managed, with its fields and legal values.
gws_remove_chrome_certificate
Pro · Destructive
Remove a certificate from managed Chrome devices.
gws_remove_chrome_network
Pro · Destructive
Remove a network definition.
gws_reorder_chrome_group_policies
Pro · Write
Change which group's policy wins for a schema when a user belongs to several.
gws_resolve_chrome_policies
Free · Read-only
Read the policies currently in EFFECT for an organizational unit or group, including values inherited from a parent rather than set locally.

Vault

ToolWhat it does
gws_add_vault_held_accounts
Pro · Write
Add accounts to an existing hold, extending preservation to them.
gws_add_vault_matter_permission
Pro · Write
Add an account as a collaborator on a matter.
gws_close_vault_matter
Pro · Write
Close a Vault matter, marking the investigation finished.
gws_count_vault_matter_accounts
Pro · Write
Count the accounts a Vault query would process, without exporting anything.
gws_create_vault_export
Pro · Write
Start an export of search results.
gws_create_vault_held_account
Pro · Write
Add one account to a hold.
gws_create_vault_hold
Pro · Write
Create a legal hold, which starts preserving the covered data and overrides the customer's ordinary retention rules.
gws_create_vault_matter
Pro · Write
Create a Vault matter.
gws_create_vault_saved_query
Pro · Write
Save a search definition in a matter for reuse.
gws_delete_vault_export
Pro · Destructive
Delete an export and the exported files it produced.
gws_delete_vault_held_account
Pro · Destructive
Remove one account from a legal hold.
gws_delete_vault_hold
Pro · Destructive
Release a legal hold.
gws_delete_vault_matter
Pro · Destructive
Delete a Vault matter.
gws_delete_vault_saved_query
Pro · Destructive
Delete a saved query.
gws_get_vault_export
Free · Read-only
Retrieve one export by its exportId — its status, the query it ran, and once complete the Cloud Storage objects holding the results plus their MD5 hashes.
gws_get_vault_hold
Free · Read-only
Retrieve one legal hold by its holdId — the service it covers (MAIL, DRIVE, GROUPS, HANGOUTS_CHAT, VOICE), any query restricting it, and whether it applies to named accounts or a whole organizational unit.
gws_get_vault_matter
Free · Read-only
Retrieve one Vault matter by its matterId — its name, description, state and, with view="FULL", the accounts that can collaborate on it.
gws_get_vault_saved_query
Free · Read-only
Retrieve one saved query by its savedQueryId, with the full query definition — corpus, date range, accounts or org unit, and search terms.
gws_list_vault_exports
Free · Read-only
List the exports in a matter, with each one's status and, once complete, the Cloud Storage location of the files it produced.
gws_list_vault_held_accounts
Free · Read-only
List the accounts covered by one hold.
gws_list_vault_holds
Free · Read-only
List the legal holds in a matter — what each one covers (which service, which accounts or organizational unit) and when it was last updated.
gws_list_vault_matters
Free · Read-only
List Vault matters.
gws_list_vault_saved_queries
Free · Read-only
List the saved queries in a matter — the stored search definitions a team reuses so that repeated searches stay identical.
gws_remove_vault_held_accounts
Pro · Destructive
Remove accounts from a legal hold.
gws_remove_vault_matter_permission
Pro · Destructive
Remove an account's collaborator access to a matter.
gws_reopen_vault_matter
Pro · Write
Reopen a closed Vault matter so work can continue in it.
gws_undelete_vault_matter
Pro · Write
Restore a deleted Vault matter, returning it to the CLOSED state.
gws_update_vault_hold
Pro · Destructive
REPLACE a legal hold wholesale.
gws_update_vault_matter
Pro · Destructive
REPLACE a matter's name and description wholesale.

Licences

ToolWhat it does
gws_create_license_assignment
Pro · Destructive
Assign a licence to a user.
gws_delete_license_assignment
Pro · Destructive
Revoke a user's licence.
gws_get_license_assignment
Free · Read-only
Check whether one specific user holds one specific SKU.
gws_list_license_assignments_for_product
Free · Read-only
List everyone holding a licence for one product, across all of its SKUs.
gws_list_license_assignments_for_sku
Free · Read-only
List everyone holding one specific SKU.
gws_patch_license_assignment
Pro · Write
Move a user to a different SKU, merging rather than replacing.
gws_update_license_assignment
Pro · Destructive
REPLACE a licence assignment wholesale — the route Google provides for moving a user from one SKU to another.

Alert Center

ToolWhat it does
gws_batch_delete_alerts
Pro · Destructive
Soft-delete many alerts at once.
gws_batch_undelete_alerts
Pro · Write
Restore many soft-deleted alerts at once.
gws_create_alert_feedback
Pro · Write
Record feedback on an alert.
gws_delete_alert
Pro · Destructive
Delete one alert.
gws_get_alert
Free · Read-only
Retrieve one alert by its alertId, with its full payload — the affected users, the detection detail, and the timestamps.
gws_get_alert_metadata
Free · Read-only
Read one alert's workflow metadata — its assignee, severity and current status — as distinct from the alert's own detection payload.
gws_get_alert_settings
Free · Read-only
Read the domain's Alert Center notification settings — which alert types raise an email notification and to which addresses.
gws_list_alert_feedback
Free · Read-only
List the feedback recorded against one alert — whether an administrator marked it a real threat, not useful, or a false positive, and when.
gws_list_alerts
Free · Read-only
List security and compliance alerts for the domain.
gws_patch_alert_settings
Pro · Write
Update the domain's Alert Center notification settings — which alert types email a human, and which addresses.
gws_undelete_alert
Pro · Write
Restore a soft-deleted alert, putting it back in the default list.

Reports

ToolWhat it does
gws_get_customer_usage_report
Free · Read-only
Domain-wide usage figures for a single day — account counts, storage consumed, and per-service activity totals across Gmail, Drive, Calendar, Meet and Classroom.
gws_get_entity_usage_report
Free · Read-only
Usage for non-user entities on a single day.
gws_get_user_usage_report
Free · Read-only
Per-user usage for a single day — last sign-in, whether 2-step verification is enrolled, mailbox and Drive storage used, and per-service activity.
gws_list_audit_activities
Free · Read-only
Read the audit log for one application.

Group Settings

ToolWhat it does
gws_get_group_settings
Free · Read-only
Read a group's policy — who can post, who can join, who can view the member list and the archive, whether messages are moderated, and whether people outside the organization can email it.
gws_patch_group_settings
Pro · Write
Change named group settings, leaving the rest alone.
gws_update_group_settings
Pro · Destructive
REPLACE a group's policy wholesale.

Data Transfer

ToolWhat it does
gws_create_data_transfer
Pro · Write
Start transferring a departing user's application data to another user.
gws_get_data_transfer
Free · Read-only
Retrieve one data transfer by its id, with the per-application status of each part of it.
gws_get_transfer_application
Free · Read-only
Retrieve one transferable application by its numeric applicationId, with the exact transferParams it accepts and the legal values for each — for Drive, for example, the privacy level controlling whether private files move along with shared ones.
gws_list_data_transfers
Free · Read-only
List data transfers, most recent first.
gws_list_transfer_applications
Free · Read-only
List the applications whose data can be transferred between users — typically Drive and Docs, Calendar, and Google+ where still present.

Calendar Resources

ToolWhat it does
gws_create_building
Pro · Write
Create a building.
gws_create_calendar_feature
Pro · Write
Create a resource feature.
gws_create_calendar_resource
Pro · Write
Create a bookable resource.
gws_delete_building
Pro · Destructive
Delete a building.
gws_delete_calendar_feature
Pro · Destructive
Delete a resource feature.
gws_delete_calendar_resource
Pro · Destructive
Delete a bookable resource.
gws_get_building
Free · Read-only
Retrieve one building by its buildingId, including its floor list and postal address.
gws_get_calendar_feature
Free · Read-only
Retrieve one resource feature by name.
gws_get_calendar_resource
Free · Read-only
Retrieve one bookable resource by its resourceId — its name, category, capacity, building and floor, the features it is tagged with, and its resourceEmail.
gws_list_buildings
Free · Read-only
List the buildings defined for the domain, with their floor names, addresses and map coordinates.
gws_list_calendar_features
Free · Read-only
List the resource features defined for the domain — the tags such as "Whiteboard", "Video conferencing" or "Step-free access" that rooms are marked with and that people filter on when booking.
gws_list_calendar_resources
Free · Read-only
List bookable calendar resources — meeting rooms, equipment, and anything else people can book.
gws_patch_building
Pro · Write
Update named fields on a building, merging rather than replacing.
gws_patch_calendar_feature
Pro · Write
Update named fields on a resource feature, merging rather than replacing.
gws_patch_calendar_resource
Pro · Write
Update named fields on a bookable resource, merging rather than replacing.
gws_rename_calendar_feature
Pro · Write
Rename a resource feature, keeping every room tagged with it attached.
gws_update_building
Pro · Destructive
REPLACE a building wholesale.
gws_update_calendar_feature
Pro · Destructive
REPLACE a resource feature wholesale.
gws_update_calendar_resource
Pro · Destructive
REPLACE a bookable resource wholesale.

Custom User Schemas

ToolWhat it does
gws_create_schema
Pro · Write
Create a custom user schema.
gws_delete_schema
Pro · Destructive
Delete a custom user schema.
gws_get_schema
Free · Read-only
Retrieve one custom schema by name or id, with its full field list — each field's type, whether it accepts multiple values, and its read-access setting (ADMINS_AND_SELF keeps a field private to administrators and the user themselves, rather than visible across the directory).
gws_list_schemas
Free · Read-only
List the custom schemas defined for the domain — the extra user fields a customer has added, such as employee number, start date or cost centre.
gws_patch_schema
Pro · Write
Update named properties of a custom schema, merging rather than replacing.
gws_update_schema
Pro · Destructive
REPLACE a custom schema wholesale.

Account Security

ToolWhat it does
gws_delete_user_app_password
Pro · Destructive
Revoke one of a user's application-specific passwords.
gws_delete_user_token
Pro · Destructive
Revoke a third-party application's access to a user's Google account.
gws_generate_user_verification_codes
Pro · Write
Generate a fresh set of 2-step verification backup codes for a user.
gws_get_user_app_password
Free · Read-only
Retrieve one application-specific password record by its codeId — the name the user gave it, when it was created and when it was last used.
gws_get_user_token
Free · Read-only
Retrieve one third-party application grant for a user, keyed by the application's OAuth client id, including the exact scopes it holds and whether it is a native application.
gws_invalidate_user_verification_codes
Pro · Destructive
Invalidate every one of a user's 2-step verification backup codes without issuing new ones.
gws_list_user_app_passwords
Free · Read-only
List a user's application-specific passwords — the single-purpose passwords issued for older clients that cannot complete 2-step verification.
gws_list_user_tokens
Free · Read-only
List the third-party applications a user has granted access to their Google account, with the scopes each was given.
gws_list_user_verification_codes
Free · Read-only
List a user's current 2-step verification backup codes.
gws_turn_off_user_two_step_verification
Pro · Destructive
Turn off 2-step verification for a user, unenrolling them entirely.

Admin Roles

ToolWhat it does
gws_create_role
Pro · Write
Create a custom administrator role.
gws_create_role_assignment
Pro · Destructive
Grant an administrator role to a user.
gws_delete_role
Pro · Destructive
Delete a custom administrator role.
gws_delete_role_assignment
Pro · Destructive
Revoke an administrator role from a user.
gws_get_role
Free · Read-only
Retrieve one administrator role by its numeric roleId, including the full list of privileges it carries.
gws_get_role_assignment
Free · Read-only
Retrieve one role assignment by its id — which role, which user, and the scope it applies to (the whole customer, or a single organizational unit).
gws_list_privileges
Free · Read-only
List every privilege that can be put into a custom administrator role, as a tree of privilege names and the service each belongs to.
gws_list_role_assignments
Free · Read-only
List who holds which administrator roles.
gws_list_roles
Free · Read-only
List the administrator roles defined for the domain, both Google's built-in ones (Super Admin, User Management, Help Desk and the rest) and any custom roles.
gws_patch_role
Pro · Write
Update named fields on a custom administrator role, merging rather than replacing.
gws_update_role
Pro · Destructive
REPLACE an administrator role wholesale.

Customer

ToolWhat it does
gws_get_customer
Free · Read-only
Retrieve the Workspace account's own profile — organization name, postal address, primary domain, alternate contact email, language and the account creation date.
gws_patch_customer
Pro · Write
Update named fields on the customer profile, merging rather than replacing.
gws_update_customer
Pro · Destructive
REPLACE the customer profile wholesale.

Shared Drives

ToolWhat it does
gws_create_shared_drive
Pro · Write
Create a shared drive.
gws_delete_shared_drive
Pro · Destructive
Delete a shared drive.
gws_get_shared_drive
Free · Read-only
Retrieve one shared drive by its driveId — its name, creation time, restrictions and capabilities.
gws_hide_shared_drive
Pro · Write
Hide a shared drive from the impersonated user's own Drive list.
gws_list_shared_drives
Free · Read-only
List shared drives.
gws_patch_shared_drive
Pro · Write
Update a shared drive's name, theme or restrictions, merging rather than replacing.
gws_unhide_shared_drive
Pro · Write
Restore a hidden shared drive to the impersonated user's Drive list.

Gmail Settings

ToolWhat it does
gws_create_gmail_cse_identity
Pro · Write
Configure a send-as address to send client-side-encrypted mail using one of the user's existing CSE key pairs.
gws_create_gmail_cse_keypair
Pro · Write
Upload a client-side encryption key pair for one user.
gws_create_gmail_delegate
Pro · Destructive
Give another user delegated access to one mailbox.
gws_create_gmail_filter
Pro · Destructive
Create a filter in one user's mailbox that acts automatically on matching incoming mail.
gws_create_gmail_forwarding_address
Pro · Destructive
Register a forwarding destination on one user's mailbox.
gws_create_gmail_send_as_alias
Pro · Destructive
Add a send-as alias to one user's mailbox, letting them put that address in the From line.
gws_delete_gmail_cse_identity
Pro · Destructive
Remove a client-side encryption identity from a user, so that address stops sending encrypted mail.
gws_delete_gmail_delegate
Pro · Destructive
Remove a delegate's access to one mailbox.
gws_delete_gmail_filter
Pro · Destructive
Delete a filter from one user's mailbox.
gws_delete_gmail_forwarding_address
Pro · Destructive
Remove a forwarding destination from one user's mailbox.
gws_delete_gmail_send_as_alias
Pro · Destructive
Remove a send-as alias from one user's mailbox.
gws_delete_gmail_smime_info
Pro · Destructive
Delete an S/MIME certificate from one of a user's send-as addresses.
gws_disable_gmail_cse_keypair
Pro · Destructive
Turn off a client-side encryption key pair.
gws_enable_gmail_cse_keypair
Pro · Write
Turn a disabled client-side encryption key pair back on, restoring the user's ability to read the mail encrypted under it.
gws_get_gmail_auto_forwarding
Free · Read-only
Read one user's Gmail auto-forwarding configuration — whether all incoming mail is being forwarded, to which address, and what happens to the original copy.
gws_get_gmail_cse_identity
Free · Read-only
Read one client-side encryption identity belonging to a user, including the id of the key pair it sends with.
gws_get_gmail_cse_keypair
Free · Read-only
Read one client-side encryption key pair belonging to a user — its certificate chain, the addresses it covers, whether it is enabled, and its expiry.
gws_get_gmail_delegate
Free · Read-only
Read one delegate entry on a user's mailbox and its verification status.
gws_get_gmail_filter
Free · Read-only
Read one filter from a user's mailbox — its full criteria (from, to, subject, query, size, attachment tests) and its actions (labels added or removed, forwarding address, whether it marks read or skips the inbox).
gws_get_gmail_forwarding_address
Free · Read-only
Read one forwarding address registered on a user's mailbox and its verification status.
gws_get_gmail_imap_settings
Free · Read-only
Read one user's Gmail IMAP settings — whether IMAP access is enabled, what happens in the mail client when a message is expunged, and any folder size limit.
gws_get_gmail_language_settings
Free · Read-only
Read one user's Gmail display language, as an IETF BCP 47 tag such as "en-GB" or "fr".
gws_get_gmail_pop_settings
Free · Read-only
Read one user's Gmail POP settings — whether POP is enabled, which messages it covers (all mail, or only mail arriving from now on), and what Gmail does with a message after a POP client downloads it.
gws_get_gmail_send_as_alias
Free · Read-only
Read one send-as alias belonging to a user, including its display name, reply-to address, signature HTML, whether it is the default, and its verification status.
gws_get_gmail_smime_info
Free · Read-only
Read one S/MIME certificate attached to a user's send-as address — its issuer chain, validity dates and whether it is the default for signing.
gws_get_gmail_vacation_settings
Free · Read-only
Read one user's Gmail vacation responder — whether the auto-reply is on, its subject and body, the start and end times, and whether it answers only contacts or only people inside the domain.
gws_insert_gmail_smime_info
Pro · Write
Upload an S/MIME certificate for one of a user's send-as addresses.
gws_list_gmail_cse_identities
Free · Read-only
List one user's client-side encryption (CSE) identities — the send-as addresses configured to send encrypted mail, each naming the key pair it uses.
gws_list_gmail_cse_keypairs
Free · Read-only
List one user's client-side encryption key pairs, each with its certificate chain, subject addresses, enablement state and — for a disabled pair — the time after which it could be permanently destroyed.
gws_list_gmail_delegates
Free · Read-only
List everyone who has delegated access to one user's mailbox, with each delegate's verification status.
gws_list_gmail_filters
Free · Read-only
List every filter in one user's mailbox, each with its matching criteria and the actions it takes on a matching message.
gws_list_gmail_forwarding_addresses
Free · Read-only
List the addresses one user has registered as forwarding destinations, each with its verification status.
gws_list_gmail_send_as_aliases
Free · Read-only
List every address one user can send mail AS — their own primary address, any group or alias address they have been given, and any external address they have added and verified.
gws_list_gmail_smime_info
Free · Read-only
List the S/MIME certificates uploaded for one of a user's send-as addresses, with each certificate's issuer, expiry and whether it is the default for signing.
gws_patch_gmail_cse_identity
Pro · Write
Associate a different key pair with an existing client-side encryption identity — the normal way to move a user onto a renewed certificate.
gws_patch_gmail_send_as_alias
Pro · Write
Update selected fields on one of a user's send-as aliases, leaving every field you do not send exactly as it was.
gws_set_default_gmail_smime_info
Pro · Write
Choose which of the certificates already uploaded for a send-as address is used to sign outgoing mail.
gws_update_gmail_auto_forwarding
Pro · Destructive
Replace one user's Gmail auto-forwarding configuration WHOLESALE.
gws_update_gmail_imap_settings
Pro · Destructive
Replace one user's Gmail IMAP settings WHOLESALE.
gws_update_gmail_language_settings
Pro · Destructive
Replace one user's Gmail display language.
gws_update_gmail_pop_settings
Pro · Destructive
Replace one user's Gmail POP settings WHOLESALE — Google's PUT overwrites the whole object, so omitted fields revert to their defaults.
gws_update_gmail_send_as_alias
Pro · Destructive
Replace one of a user's send-as aliases WHOLESALE.
gws_update_gmail_vacation_settings
Pro · Destructive
Replace one user's Gmail vacation responder WHOLESALE, and switch it on or off.
gws_verify_gmail_send_as_alias
Pro · Destructive
Send a verification email for a pending send-as alias.

Reseller

ToolWhat it does
gws_activate_reseller_subscription
Pro · Destructive
Reactivate a resold subscription that the reseller suspended.
gws_change_reseller_subscription_plan
Pro · Destructive
Move a resold subscription onto a different payment plan — flexible to an annual commitment, or between annual monthly and annual yearly payment.
gws_change_reseller_subscription_renewal
Pro · Destructive
Set what happens to a resold annual-commitment subscription when its term ends.
gws_change_reseller_subscription_seats
Pro · Destructive
Change how many seats a resold subscription carries.
gws_create_reseller_customer
Pro · Write
Create a resold customer account under this reseller.
gws_create_reseller_subscription
Pro · Destructive
Order a new subscription for a resold customer, or move them between EDITIONS of a product they already have.
gws_delete_reseller_subscription
Pro · Destructive
Cancel a resold customer's subscription, or transfer it to a direct billing relationship with Google.
gws_get_reseller_customer
Free · Read-only
Get one resold customer's account record — primary domain, postal address, alternate contact email, and the customer id every other tool in this family takes.
gws_get_reseller_notify_details
Free · Read-only
Show which Google Cloud Pub/Sub topic this reseller's subscription-change notifications are published to, if any.
gws_get_reseller_subscription
Free · Read-only
Get one resold subscription — its SKU, its plan, its seat counts, its renewal settings, its status and its trial or commitment dates.
gws_list_reseller_subscriptions
Free · Read-only
List the Google Workspace subscriptions this RESELLER holds for its resold customers — every customer when no filter is given, one customer with customerId, or customers whose primary domain starts with customerNamePrefix.
gws_patch_reseller_customer
Pro · Write
Change some fields of a resold customer's record, merging rather than replacing — the right tool for a new postal address, a new contact name or a new alternate email.
gws_register_reseller_notify
Pro · Write
Start publishing this reseller's subscription-change notifications to a Google Cloud Pub/Sub topic.
gws_start_reseller_subscription_paid_service
Pro · Destructive
End a resold subscription's 30-day free trial immediately and start the paid service.
gws_suspend_reseller_subscription
Pro · Destructive
Suspend a resold subscription.
gws_unregister_reseller_notify
Pro · Destructive
Stop publishing this reseller's subscription-change notifications.
gws_update_reseller_customer
Pro · Destructive
REPLACE a resold customer's record wholesale.

Cloud Channel

ToolWhat it does
gws_activate_channel_entitlement
Pro · Destructive
Reactivate an entitlement the RESELLER suspended.
gws_cancel_channel_entitlement
Pro · Destructive
Cancel an entitlement.
gws_change_channel_entitlement_offer
Pro · Destructive
Move an entitlement to a different offer — a different edition, plan or price.
gws_change_channel_entitlement_parameters
Pro · Destructive
Change an entitlement's parameters — in practice, the seat count.
gws_change_channel_entitlement_renewal
Pro · Destructive
Change what happens when a commitment entitlement reaches the end of its term.
gws_check_channel_cloud_identity_accounts
Free · Read-only
Check whether a domain already has a Cloud Identity account, before you try to create a Cloud Channel customer for it.
gws_create_channel_customer
Pro · Write
Create a Cloud Channel customer under this reseller.
gws_create_channel_customer_repricing_config
Pro · Destructive
Set a repricing adjustment for one customer.
gws_create_channel_entitlement
Pro · Destructive
Sell a customer a subscription.
gws_create_channel_partner_customer
Pro · Write
Create a customer under one of this account's sub-resellers.
gws_create_channel_partner_link
Pro · Write
Invite a sub-reseller to sell under this reseller account.
gws_create_channel_partner_repricing_config
Pro · Destructive
Set a repricing adjustment for one sub-reseller.
gws_delete_channel_customer
Pro · Destructive
Delete a Cloud Channel customer from this reseller's account.
gws_delete_channel_customer_repricing_config
Pro · Destructive
Delete a customer repricing config.
gws_delete_channel_partner_customer
Pro · Destructive
Delete a sub-reseller's customer from this Cloud Channel account.
gws_delete_channel_partner_repricing_config
Pro · Destructive
Delete a sub-reseller repricing config.
gws_fetch_channel_report_results
Free · Read-only
Read the rows of a finished report job.
gws_get_channel_customer
Free · Read-only
Get one Cloud Channel customer's record — organisation name, domain, Cloud Identity id, primary contact, language and the correlation id.
gws_get_channel_customer_repricing_config
Free · Read-only
Get one customer repricing config — its SKU group, its adjustment, the base it applies to and the invoice month it takes effect in.
gws_get_channel_entitlement
Free · Read-only
Get one entitlement — its offer, its parameters including the seat count, its commitment and renewal settings, its provisioning state and its suspension reasons if any.
gws_get_channel_operation
Free · Read-only
Poll one Cloud Channel long-running operation.
gws_get_channel_partner_customer
Free · Read-only
Get one sub-reseller's customer record — the same fields as gws_get_channel_customer, addressed under the channel partner link that owns it.
gws_get_channel_partner_link
Free · Read-only
Get one channel partner link — the sub-reseller's Cloud Identity id, its public identity, its link state and the invite link if it has not accepted yet.
gws_get_channel_partner_repricing_config
Free · Read-only
Get one sub-reseller repricing config — its SKU group, its adjustment, the base it applies to and the invoice month it takes effect in.
gws_import_channel_customer
Pro · Write
Claim an existing Cloud Identity or Workspace customer into this reseller's Cloud Channel account.
gws_import_channel_partner_customer
Pro · Write
Claim an existing Cloud Identity or Workspace customer into one of this account's sub-resellers.
gws_list_channel_billable_skus
Free · Read-only
List the billable SKUs inside one SKU group — exactly which SKUs a repricing config written against that group will move the price of.
gws_list_channel_customer_repricing_configs
Free · Read-only
List the repricing configs in force for one customer — the per-SKU-group adjustments this reseller applies on top of Google's price, month by month.
gws_list_channel_customers
Free · Read-only
List the customers this reseller bills through Cloud Channel — the book of business.
gws_list_channel_entitlement_changes
Free · Read-only
List the history of changes to one entitlement — who changed what, when, and why.
gws_list_channel_entitlements
Free · Read-only
List one customer's entitlements — everything this reseller currently bills them for, with each one's offer, provisioned seats, state and commitment.
gws_list_channel_offers
Free · Read-only
List the offers this reseller can sell — the price list, with each offer's plan, its price by SKU and its constraints.
gws_list_channel_operations
Free · Read-only
List the Cloud Channel long-running operations visible to this connection — the way to find an operation whose name was lost, or to see what is still in flight.
gws_list_channel_partner_customers
Free · Read-only
List the customers belonging to ONE sub-reseller, rather than to this reseller directly.
gws_list_channel_partner_links
Free · Read-only
List the channel partner links under this reseller — the sub-resellers, or 'distributors below you', that sell on this account's behalf.
gws_list_channel_partner_repricing_configs
Free · Read-only
List the repricing configs in force for one sub-reseller — the adjustments applied to what THEY are charged, as distinct from what their customers are charged.
gws_list_channel_product_skus
Free · Read-only
List the SKUs inside one product — the specific editions a customer can be sold.
gws_list_channel_products
Free · Read-only
List the products this reseller can sell — the top of the catalog, above SKUs and offers.
gws_list_channel_purchasable_offers
Free · Read-only
List the offers this specific customer could be sold, or moved to.
gws_list_channel_purchasable_skus
Free · Read-only
List the SKUs this specific customer could be sold, or moved to — one level above gws_list_channel_purchasable_offers.
gws_list_channel_reports
Free · Read-only
List the Cloud Channel reports this reseller can run, with each report's columns.
gws_list_channel_sku_groups
Free · Read-only
List the SKU groups available to this reseller — the named buckets of SKUs that repricing configs are written against.
gws_list_channel_subscribers
Free · Read-only
List the service accounts registered to receive this reseller's Cloud Channel Pub/Sub notifications — entitlement changes, customer events and the rest.
gws_list_channel_transferable_offers
Free · Read-only
List the offers this reseller could sell to a customer who is currently buying from Google direct or from another reseller — the price list for a transfer that has not happened yet.
gws_list_channel_transferable_skus
Free · Read-only
List the SKUs a customer currently holds elsewhere that could transfer to this reseller, with the transfer eligibility of each.
gws_lookup_channel_entitlement_offer
Free · Read-only
Get the offer an entitlement is currently on, with its price and plan — the answer to 'what is this customer actually paying, and on what terms'.
gws_patch_channel_customer
Pro · Write
Change some fields of a Cloud Channel customer's record, merging rather than replacing — the right tool for a new organisation name, postal address, primary contact or language.
gws_patch_channel_customer_repricing_config
Pro · Write
Replace an existing customer repricing config.
gws_patch_channel_partner_customer
Pro · Write
Change some fields of a sub-reseller's customer record, merging rather than replacing.
gws_patch_channel_partner_link
Pro · Write
Change a channel partner link's state — chiefly to suspend a sub-reseller or to reinstate one.
gws_patch_channel_partner_repricing_config
Pro · Write
Replace an existing sub-reseller repricing config.
gws_provision_channel_cloud_identity
Pro · Destructive
Create the Cloud Identity account for a Cloud Channel customer who does not have one.
gws_query_channel_eligible_billing_accounts
Free · Read-only
List the billing accounts a customer's purchase of given SKUs could be charged to.
gws_register_channel_subscriber
Pro · Write
Start publishing this reseller's Cloud Channel notifications to a service account's Pub/Sub topic.
gws_run_channel_report
Pro · Write
Start one of this reseller's Cloud Channel reports.
gws_start_channel_entitlement_paid_service
Pro · Destructive
End a trial early and start charging for it.
gws_suspend_channel_entitlement
Pro · Destructive
Suspend an entitlement.
gws_transfer_channel_entitlements
Pro · Destructive
Transfer a customer's existing entitlements to THIS reseller — from Google direct, or from another reseller.
gws_transfer_channel_entitlements_to_google
Pro · Destructive
Hand a customer's entitlements back to Google direct billing.
gws_unregister_channel_subscriber
Pro · Destructive
Stop publishing this reseller's Cloud Channel notifications to a service account.

Cloud Identity

ToolWhat it does
gws_add_identity_saml_idp_credential
Pro · Destructive
Attach an identity provider's signing certificate to a SAML profile.
gws_approve_identity_device_user
Pro · Write
Approve a device user so the account can synchronise work data on that device.
gws_block_identity_device_user
Pro · Destructive
Block a device user so the account can no longer synchronise work data on that device.
gws_cancel_identity_device_user_wipe
Pro · Write
Call back a pending work-data wipe for one account on a device.
gws_cancel_identity_device_wipe
Pro · Write
Call back a pending device wipe.
gws_cancel_identity_user_invitation
Pro · Destructive
Withdraw an invitation that has been sent but not yet accepted.
gws_check_identity_transitive_membership
Free · Read-only
Ask whether someone is a member of a group at any depth, counting nested groups.
gws_check_identity_user_invitable
Free · Read-only
Ask whether an address can be sent a transfer invitation — true only when an unmanaged personal Google account exists at it on one of this organisation's domains.
gws_create_identity_allowlisted_domain
Pro · Write
Allow this organisation's Cloud Identity groups to include members from one more domain.
gws_create_identity_device
Pro · Write
Register a company-owned device in the Cloud Identity inventory before anyone signs in on it.
gws_create_identity_group
Pro · Write
Create a Cloud Identity group.
gws_create_identity_membership
Pro · Write
Add a member to a Cloud Identity group.
gws_create_identity_oidc_sso_profile
Pro · Destructive
Create an inbound OIDC single sign-on profile.
gws_create_identity_policy
Pro · Destructive
Create a Cloud Identity policy.
gws_create_identity_saml_sso_profile
Pro · Destructive
Create an inbound SAML single sign-on profile.
gws_create_identity_sso_assignment
Pro · Destructive
Point an org unit or a group at a single sign-on profile.
gws_delete_identity_allowlisted_domain
Pro · Destructive
Remove a domain from the allowlist.
gws_delete_identity_device
Pro · Destructive
Delete a device record.
gws_delete_identity_device_user
Pro · Destructive
Delete a device user record — the account's whole association with that device, including its approval state and sync history.
gws_delete_identity_group
Pro · Destructive
Delete a Cloud Identity group.
gws_delete_identity_membership
Pro · Destructive
Remove a member from a Cloud Identity group.
gws_delete_identity_oidc_sso_profile
Pro · Destructive
Delete an inbound OIDC single sign-on profile.
gws_delete_identity_policy
Pro · Destructive
Delete a Cloud Identity policy.
gws_delete_identity_saml_idp_credential
Pro · Destructive
Remove an identity provider's signing certificate from a SAML profile.
gws_delete_identity_saml_sso_profile
Pro · Destructive
Delete an inbound SAML single sign-on profile.
gws_delete_identity_sso_assignment
Pro · Destructive
Delete an inbound SSO assignment.
gws_get_identity_allowlisted_domain
Free · Read-only
Get one allowlisted domain by its Cloud Identity id.
gws_get_identity_device
Free · Read-only
Get one device — make, model, serial, operating system, encryption and compliance state, and when it last synchronised.
gws_get_identity_device_client_state
Free · Read-only
Get one partner's client state for a device user — the compliance signals that partner reports, which Context-Aware Access rules can require.
gws_get_identity_device_user
Free · Read-only
Get one device user — which account it is, whether it is approved or blocked, its compliance state and when it last synchronised.
gws_get_identity_group
Free · Read-only
Get one Cloud Identity group by its id — display name, description, group key, labels, parent customer and any dynamic-group metadata.
gws_get_identity_group_security_settings
Free · Read-only
Read a group's security settings — today that is the member restriction, the rule deciding which kinds of member the group will accept.
gws_get_identity_membership
Free · Read-only
Get one membership — who the member is, which roles they hold in the group (MEMBER, MANAGER or OWNER) and any expiry on those roles.
gws_get_identity_membership_graph
Free · Read-only
Return the PATHS by which a member reaches a group, not just whether they do — the answer to "which nested group is giving this person access".
gws_get_identity_oidc_sso_profile
Free · Read-only
Get one inbound OIDC single sign-on profile — the identity provider Google redirects sign-in to, and the settings that make the redirect work.
gws_get_identity_policy
Free · Read-only
Get one Cloud Identity policy — the setting it configures, the org unit or group it applies to, and whether it is a SYSTEM policy set by Google or an ADMIN policy set by this organisation.
gws_get_identity_saml_idp_credential
Free · Read-only
Get one identity-provider signing certificate attached to a SAML profile — its resource name, the size in bits of its RSA or DSA public key, and when it was last updated.
gws_get_identity_saml_sso_profile
Free · Read-only
Get one inbound SAML single sign-on profile — the identity provider's entity id, sign-in and sign-out URLs, and the service-provider details Google publishes back.
gws_get_identity_sso_assignment
Free · Read-only
Get one inbound SSO assignment — which org unit or group it targets, which sign-in mode it applies, and its rank against other assignments.
gws_get_identity_user_invitation
Free · Read-only
Get one user invitation and its current state.
gws_list_identity_allowlisted_domains
Free · Read-only
List the domains this organisation allows its Cloud Identity groups to include members from.
gws_list_identity_device_client_states
Free · Read-only
List the client states recorded against a device user — one per third-party partner reporting on that device, the signals Context-Aware Access rules read.
gws_list_identity_device_users
Free · Read-only
List the users recorded on one device — each is a person's work account on that machine, with its own approval, block and wipe state.
gws_list_identity_devices
Free · Read-only
List the devices Cloud Identity knows about — company-owned inventory and personal devices with work data on them.
gws_list_identity_groups
Free · Read-only
List the Cloud Identity groups under one customer.
gws_list_identity_memberships
Free · Read-only
List the DIRECT memberships of one group — the members added to it, not the people who reach it through a nested group.
gws_list_identity_oidc_sso_profiles
Free · Read-only
List the inbound OIDC single sign-on profiles configured for this organisation.
gws_list_identity_policies
Free · Read-only
List the Cloud Identity policies in force — the settings that decide what each Google service does for a given org unit or group, including the two-step verification and security settings an audit asks about.
gws_list_identity_saml_idp_credentials
Free · Read-only
List the identity-provider signing certificates attached to one SAML profile.
gws_list_identity_saml_sso_profiles
Free · Read-only
List the inbound SAML single sign-on profiles configured for this organisation.
gws_list_identity_sso_assignments
Free · Read-only
List the inbound SSO assignments — which org units and groups are sent to which single sign-on profile, and in what order.
gws_list_identity_user_invitations
Free · Read-only
List the invitations sent to unmanaged accounts — people who already signed up for a personal Google account on one of this organisation's domains and have been asked to hand it over.
gws_lookup_identity_device_users
Free · Read-only
Find a device user's resource name from an identifier the device itself reports, rather than from a Cloud Identity id.
gws_lookup_identity_group
Free · Read-only
Turn a group's email address into the group id every other tool in this family takes.
gws_lookup_identity_membership
Free · Read-only
Turn a member's email address into the membership id the other membership tools take.
gws_modify_identity_membership_roles
Pro · Destructive
Add, remove or update the roles a member holds in a group.
gws_patch_identity_group
Pro · Write
Change some fields of a Cloud Identity group, merging rather than replacing — no field you leave out is touched.
gws_patch_identity_oidc_sso_profile
Pro · Write
Change some fields of an inbound OIDC single sign-on profile, merging rather than replacing — no field you leave out is touched.
gws_patch_identity_policy
Pro · Write
Change some fields of a Cloud Identity policy, merging rather than replacing — no field you leave out is touched.
gws_patch_identity_saml_sso_profile
Pro · Write
Change some fields of an inbound SAML single sign-on profile, merging rather than replacing — no field you leave out is touched.
gws_patch_identity_sso_assignment
Pro · Write
Change some fields of an inbound SSO assignment, merging rather than replacing — no field you leave out is touched.
gws_search_identity_direct_groups
Free · Read-only
List the groups a member belongs to DIRECTLY, across every group in the organisation.
gws_search_identity_groups
Free · Read-only
Search Cloud Identity groups with a Common Expression Language query.
gws_search_identity_transitive_groups
Free · Read-only
List every group a member ends up in, counting nested groups — the complete answer to "what does this person get through group membership".
gws_search_identity_transitive_memberships
Free · Read-only
List everyone who ends up in one group, counting nested groups — the membership list an access review needs, where gws_list_identity_memberships gives only the members added directly.
gws_send_identity_user_invitation
Pro · Destructive
Send a transfer invitation to an unmanaged personal Google account.
gws_update_identity_group_security_settings
Pro · Destructive
Replace a group's member restriction.
gws_wipe_identity_device
Pro · Destructive
Factory-reset a device remotely.
gws_wipe_identity_device_user
Pro · Destructive
Erase one account's work data from a device, leaving the rest of the machine alone.

Chrome Management

ToolWhat it does
gws_count_chrome_active_devices
Free · Read-only
Count how many ChromeOS devices were ACTIVE over each of Google's set time frames, ending at the date given.
gws_count_chrome_app_requests
Free · Read-only
Summarise the extension install requests users have raised, counted per extension with how many people asked for it and when it was last requested.
gws_count_chrome_browsers_needing_attention
Free · Read-only
Count the managed Chrome BROWSERS that need looking at, split into three groups: recently enrolled, carrying policy still to be synced, and showing no recent activity.
gws_count_chrome_crash_events
Free · Read-only
Count the times Chrome crashed, grouped so the result reads as a trend rather than a list of incidents.
gws_count_chrome_devices_needing_attention
Free · Read-only
Count the ChromeOS DEVICES that need looking at: those that have not synced policy or seen user activity in the past 28 days, those running an out-of-date Chrome, and those that are not compliant.
gws_count_chrome_devices_per_boot_type
Free · Read-only
Count ChromeOS devices grouped by how they boot, as of the date given.
gws_count_chrome_devices_per_release_channel
Free · Read-only
Count ChromeOS devices grouped by the Chrome release channel each one is on, as of the date given — how much of the fleet is on stable and how much is ahead of it.
gws_count_chrome_devices_reaching_auto_expiration
Free · Read-only
Count the ChromeOS devices whose automatic-update expiration falls in each month of a window, grouped by expiry date and model — the report that answers which hardware stops receiving Chrome updates and when, so it can be budgeted for.
gws_count_chrome_hardware_fleet_devices
Free · Read-only
Count ChromeOS devices by hardware specification — how many of each model, processor, memory size and storage size are in the fleet.
gws_count_chrome_installed_apps
Free · Read-only
Count the apps and extensions installed across the fleet, one row per app with its total install count, how many permissions it asks for and its risk score.
gws_count_chrome_print_jobs_by_printer
Free · Read-only
Summarise printing per PRINTER: for each one, how many jobs it ran, how many devices sent to it and how many people used it.
gws_count_chrome_print_jobs_by_user
Free · Read-only
Summarise printing per PERSON: for each one, how many jobs they ran, how many printers they used and from how many devices.
gws_count_chrome_profile_versions
Free · Read-only
Count the managed Chrome PROFILES running each Chrome version — the update picture for signed-in profiles rather than for devices.
gws_count_chrome_versions
Free · Read-only
Count how many of each installed Chrome version are in the fleet — the report that shows how far behind the estate is running.
gws_create_chrome_connector_config
Pro · Write
Create a Chrome Enterprise connector config, so managed Chrome starts streaming security events to an external system.
gws_create_chrome_profile_command
Pro · Destructive
Send a remote command to one managed Chrome browser profile.
gws_create_chrome_telemetry_notification_config
Pro · Write
Create a telemetry notification config, so matching ChromeOS telemetry is published to a Google Cloud Pub/Sub topic as it arrives.
gws_delete_chrome_connector_config
Pro · Destructive
Delete a Chrome Enterprise connector config.
gws_delete_chrome_profile
Pro · Destructive
Delete the data Google has collected from one managed Chrome browser profile.
gws_delete_chrome_telemetry_notification_config
Pro · Destructive
Delete a telemetry notification config.
gws_disable_chrome_security_insights
Pro · Destructive
Switch Chrome security insights off for the whole customer.
gws_enable_chrome_security_insights
Pro · Write
Switch Chrome security insights on for this customer.
gws_find_chrome_installed_app_devices
Free · Read-only
List the managed Chrome browser DEVICES that have a given app installed — the report that answers "where is this extension running".
gws_find_chrome_installed_app_profiles
Free · Read-only
List the managed Chrome PROFILES that have a given app installed — the report that answers "who is running this extension".
gws_get_chrome_android_app
Free · Read-only
Get the details Google holds for one Android app — its name, publisher, permissions and store listing.
gws_get_chrome_app
Free · Read-only
Get the details Google holds for one Chrome extension or app — its name, publisher, permissions and store listing.
gws_get_chrome_connector_config
Free · Read-only
Get one Chrome Enterprise connector config by its id, including its delivery status and the moment of its most recent failure.
gws_get_chrome_profile
Free · Read-only
Get one managed Chrome browser profile by its permanent id.
gws_get_chrome_profile_command
Free · Read-only
Get one remote command sent to a managed Chrome browser profile, including whether the browser has carried it out.
gws_get_chrome_security_insights_status
Free · Read-only
Report whether Chrome security insights are switched on for this customer.
gws_get_chrome_telemetry_device
Free · Read-only
Get the hardware and health telemetry one ChromeOS device has reported.
gws_get_chrome_telemetry_user
Free · Read-only
Get the telemetry recorded against one person — the devices they used and the activity, audio, bandwidth, peripheral and app reports from each.
gws_get_chrome_web_app
Free · Read-only
Get the details Google holds for one progressive web app.
gws_list_chrome_connector_configs
Free · Read-only
List the Chrome Enterprise connector configs — the destinations managed Chrome streams security events to, such as a CrowdStrike, Splunk, Google SecOps or Palo Alto Networks endpoint.
gws_list_chrome_devices_requesting_extension
Free · Read-only
List the managed Chrome browser devices whose users have asked to install one particular extension.
gws_list_chrome_print_jobs
Free · Read-only
List individual print jobs, one row each with its title, state, page count, colour and duplex mode, printer and the person who sent it.
gws_list_chrome_profile_commands
Free · Read-only
List the remote commands sent to one managed Chrome browser profile, with each command's state — PENDING, EXPIRED or EXECUTED_BY_CLIENT — and its result.
gws_list_chrome_profiles
Free · Read-only
List the managed Chrome browser profiles — one row per signed-in profile, with its owner, platform, Chrome version, policy count, extension count and when it last reported in.
gws_list_chrome_telemetry_devices
Free · Read-only
List the hardware and health telemetry ChromeOS devices have reported.
gws_list_chrome_telemetry_events
Free · Read-only
List the telemetry events ChromeOS devices have raised — crashes, app installs and launches, network and VPN state changes, display and USB peripheral changes.
gws_list_chrome_telemetry_notification_configs
Free · Read-only
List the telemetry notification configs — the Google Cloud Pub/Sub topics matching telemetry is published to, and the filter each one applies.
gws_list_chrome_telemetry_users
Free · Read-only
List the telemetry recorded against people in this organisation — for each, the devices they used and the activity, audio, bandwidth, peripheral and app reports from those devices.
gws_list_chrome_users_requesting_extension
Free · Read-only
List the people who have asked to install one particular extension.
gws_move_chrome_third_party_profile_user
Pro · Write
Move a third-party Chrome profile user into another organizational unit.
gws_patch_chrome_connector_config
Pro · Write
Change fields on an existing Chrome Enterprise connector config.
gws_query_chrome_content_transfer_breakdowns
Free · Read-only
Break the content-transfer totals down by one dimension, so you can see WHO moved the most data or WHICH sites it went to.
gws_query_chrome_content_transfers
Free · Read-only
Get a high-level summary of the content managed Chrome moved — uploads, downloads and prints, including the ones a data-loss rule flagged as sensitive.
gws_query_chrome_url_visit_breakdowns
Free · Read-only
Break the risky-URL totals down by one dimension, so you can see WHICH people or WHICH domains account for them.
gws_query_chrome_url_visits
Free · Read-only
Get a high-level summary of the suspicious URLs people reached in managed Chrome, counted by risk level.

Gmail content

ToolWhat it does
gws_batch_delete_gmail_messages
Pro · Destructive
PERMANENTLY delete up to 1000 messages.
gws_batch_modify_gmail_messages
Pro · Write
Add or remove labels on up to 1000 messages at once.
gws_create_gmail_draft
Pro · Write
Save a new unsent draft in one person's mailbox.
gws_create_gmail_label
Pro · Write
Create a label in one person's mailbox.
gws_delete_gmail_draft
Pro · Destructive
Delete an unsent draft.
gws_delete_gmail_label
Pro · Destructive
Delete a label.
gws_delete_gmail_message
Pro · Destructive
PERMANENTLY delete one message.
gws_delete_gmail_thread
Pro · Destructive
PERMANENTLY delete a conversation and EVERY message in it.
gws_download_gmail_attachment
Free · Read-only
Download one attachment and get back a temporary link to it.
gws_get_gmail_draft
Free · Read-only
Read one unsent draft.
gws_get_gmail_label
Free · Read-only
Get one label, including its colour, its visibility settings and how many messages and threads carry it.
gws_get_gmail_message
Free · Read-only
Read one message.
gws_get_gmail_profile
Free · Read-only
Get one person's mailbox summary — their Gmail address, how many messages and threads it holds, and its current historyId.
gws_get_gmail_thread
Free · Read-only
Read a whole conversation — every message in it, in order.
gws_import_gmail_message
Pro · Write
Import a message into one person's mailbox as if it had ARRIVED there.
gws_insert_gmail_message
Pro · Write
File a message directly into one person's mailbox WITHOUT sending it.
gws_list_gmail_drafts
Free · Read-only
List one person's unsent drafts.
gws_list_gmail_history
Free · Read-only
List what changed in one person's mailbox since a known point — messages added or deleted, labels applied or removed.
gws_list_gmail_labels
Free · Read-only
List every label in one person's mailbox, system and user-created alike.
gws_list_gmail_messages
Free · Read-only
Search one person's messages.
gws_list_gmail_threads
Free · Read-only
Search one person's conversations.
gws_modify_gmail_message
Pro · Write
Add or remove labels on one message.
gws_modify_gmail_thread
Pro · Write
Add or remove labels on EVERY message in a conversation.
gws_patch_gmail_label
Pro · Write
Change some fields of a label and leave the rest as they are.
gws_send_gmail_draft
Pro · Destructive
Send an existing draft.
gws_send_gmail_message
Pro · Destructive
Send an email as one person.
gws_trash_gmail_message
Pro · Write
Move a message to Trash.
gws_trash_gmail_thread
Pro · Write
Move a whole conversation to Trash.
gws_untrash_gmail_message
Pro · Write
Take a message out of Trash and put it back where it was.
gws_untrash_gmail_thread
Pro · Write
Take a whole conversation out of Trash.
gws_update_gmail_draft
Pro · Destructive
Replace an unsent draft with a new message.
gws_update_gmail_label
Pro · Destructive
Replace a label wholesale.

Drive files

ToolWhat it does
gws_approve_drive_approval
Pro · Destructive
Sign off on a file, as the named person.
gws_cancel_drive_approval
Pro · Destructive
Call off an approval on a file, for every reviewer at once.
gws_comment_drive_approval
Pro · Write
Add a comment to an approval WITHOUT deciding it, as the named person.
gws_copy_drive_file
Pro · Write
Copy a file.
gws_create_drive_comment
Pro · Write
Add a comment to a file, as the named file owner — it appears under their name and everyone who can see the file can read it.
gws_create_drive_file
Pro · Write
Create a folder, or an empty Google Doc, Sheet or Slides file, in one person's Drive.
gws_create_drive_permission
Pro · Destructive
GRANT someone access to a file or folder.
gws_create_drive_reply
Pro · Write
Reply to a comment on a file, as the named file owner.
gws_decline_drive_approval
Pro · Destructive
Refuse to sign off on a file, as the named person.
gws_delete_drive_comment
Pro · Destructive
Delete a comment AND every reply on it.
gws_delete_drive_file
Pro · Destructive
PERMANENTLY delete a file or folder.
gws_delete_drive_permission
Pro · Destructive
REVOKE someone's access to a file or folder.
gws_delete_drive_reply
Pro · Destructive
Delete one reply on a comment.
gws_delete_drive_revision
Pro · Destructive
PERMANENTLY delete one saved version of a file.
gws_download_drive_file
Free · Read-only
Download one ORDINARY file and get back a temporary link to it.
gws_empty_drive_trash
Pro · Destructive
PERMANENTLY delete EVERYTHING in one person's Drive trash.
gws_export_drive_file
Free · Read-only
Convert a GOOGLE DOC, SHEET, SLIDES or DRAWING to another format and get back a temporary link to the result.
gws_generate_drive_file_ids
Free · Read-only
Reserve file ids ahead of time for one person's Drive.
gws_get_drive_about
Free · Read-only
Get one person's Drive account summary — their storage quota and how much of it is used, the maximum upload size, and the conversion maps that say which file types can be turned into which.
gws_get_drive_access_proposal
Free · Read-only
Read one request for access to a file — who asked, what role they want and what they said.
gws_get_drive_app
Free · Read-only
Read one installed Drive app — what it is called, what file types it opens and creates, and its icons.
gws_get_drive_approval
Free · Read-only
Read one approval on a file, with each reviewer's decision and the messages recorded against it.
gws_get_drive_changes_start_token
Free · Read-only
Get the token a Drive change feed starts from for one person.
gws_get_drive_comment
Free · Read-only
Read one comment on a file, with its replies.
gws_get_drive_file
Free · Read-only
Read one file's DETAILS — its name, type, size, owners, parent folders, timestamps and whether it is in the trash.
gws_get_drive_operation
Free · Read-only
Check the state of a long-running Drive operation.
gws_get_drive_permission
Free · Read-only
Read one sharing entry on a file — who it is for, what they can do, and when it expires.
gws_get_drive_reply
Free · Read-only
Read one reply on a comment.
gws_get_drive_revision
Free · Read-only
Read one saved version of a file — when it was made, by whom, its size and whether it is pinned.
gws_list_drive_access_proposals
Free · Read-only
List the outstanding requests for access to one file — who asked, what they asked for and any message they sent.
gws_list_drive_approvals
Free · Read-only
List the approvals on one file — who was asked to sign off, what each of them decided, when it is due and whether the file is locked while it runs.
gws_list_drive_apps
Free · Read-only
List the third-party apps one person has installed in Drive — what can open or create files in their account.
gws_list_drive_changes
Free · Read-only
List what changed in one person's Drive since a known point — files added, edited, moved, trashed or removed.
gws_list_drive_comments
Free · Read-only
List the comments on one file — who wrote each one, when, what it says, whether it is resolved, and the text it is anchored to.
gws_list_drive_file_labels
Free · Read-only
List the labels applied to one file — the organisation's classification and metadata tags, with the values set on this file.
gws_list_drive_files
Free · Read-only
Search one person's Drive.
gws_list_drive_permissions
Free · Read-only
List who can reach one file or folder, and what each of them can do.
gws_list_drive_replies
Free · Read-only
List the replies on one comment.
gws_list_drive_revisions
Free · Read-only
List the saved versions of one file — who changed it and when.
gws_modify_drive_file_labels
Pro · Write
Add, change or take off the labels on one file.
gws_patch_drive_comment
Pro · Write
Change the text of one comment.
gws_patch_drive_file
Pro · Write
Change a file's details — rename it, star it, change its description, or move it to the trash with {"trashed": true}.
gws_patch_drive_permission
Pro · Write
Change an existing sharing entry — usually to raise or lower what someone can do, or to set or clear an expiry.
gws_patch_drive_reply
Pro · Write
Change the text of one reply.
gws_patch_drive_revision
Pro · Write
Change a saved version's settings — pin it with {"keepForever": true} so Drive's automatic clean-up cannot remove it, or publish it.
gws_reassign_drive_approval
Pro · Destructive
Change who is being asked to sign off on a file.
gws_resolve_drive_access_proposal
Pro · Destructive
Settle somebody's request for access to a file.
gws_start_drive_approval
Pro · Destructive
Ask people to sign off on a file.

Calendar

ToolWhat it does
gws_clear_calendar
Pro · Destructive
Delete EVERY event on the named person's primary calendar.
gws_create_calendar
Pro · Write
Create a new secondary calendar owned by the named person.
gws_create_calendar_acl_rule
Pro · Destructive
Share a calendar with someone.
gws_create_calendar_event
Pro · Destructive
Create an event on a calendar.
gws_create_calendar_list_entry
Pro · Write
Add an existing calendar to one person's calendar list.
gws_delete_calendar
Pro · Destructive
Delete a secondary calendar.
gws_delete_calendar_acl_rule
Pro · Destructive
Remove a calendar sharing rule.
gws_delete_calendar_event
Pro · Destructive
Delete an event.
gws_delete_calendar_list_entry
Pro · Write
Remove a calendar from one person's calendar list.
gws_get_calendar
Free · Read-only
Read a calendar's own metadata — its title, description, location and time zone.
gws_get_calendar_acl_rule
Free · Read-only
Read one calendar sharing rule.
gws_get_calendar_colors
Free · Read-only
Read the palette behind every colorId in Calendar — the numbered background and foreground values, for calendars and for events separately.
gws_get_calendar_event
Free · Read-only
Read one event in full — its times, attendees and their responses, organizer, conferencing details, reminders and recurrence rule.
gws_get_calendar_list_entry
Free · Read-only
Read one entry from a person's calendar list.
gws_get_calendar_setting
Free · Read-only
Read one of a person's Calendar preferences by id.
gws_import_calendar_event
Pro · Write
File a private copy of an event that already exists somewhere else — the migration tool.
gws_list_calendar_acl_rules
Free · Read-only
List who a calendar is shared with and at what access role.
gws_list_calendar_event_instances
Free · Read-only
List the separate occurrences of one recurring event, including the ones that were moved or cancelled on their own.
gws_list_calendar_events
Free · Read-only
List the events on a calendar.
gws_list_calendar_list
Free · Read-only
List the calendars in one person's own calendar list — the ones they own and the ones they subscribe to.
gws_list_calendar_settings
Free · Read-only
List one person's own Calendar preferences — their time zone, which day their week starts on, their default event length, their working-hours and notification choices.
gws_move_calendar_event
Pro · Destructive
Move an event to another calendar, which CHANGES ITS ORGANIZER.
gws_patch_calendar
Pro · Write
Change some of a calendar's own details, leaving the rest alone.
gws_patch_calendar_acl_rule
Pro · Write
Change some fields of a calendar sharing rule, leaving the rest alone.
gws_patch_calendar_event
Pro · Write
Change some fields of an event, leaving the rest alone.
gws_patch_calendar_list_entry
Pro · Write
Change some of one person's display settings for a calendar, leaving the rest alone.
gws_query_calendar_free_busy
Free · Read-only
Ask when a set of calendars is busy over one window.
gws_quick_add_calendar_event
Pro · Destructive
Create an event from a plain sentence, which Google parses for the title, date and time — for example "Lunch with Sam Tuesday 1pm".
gws_transfer_calendar_ownership
Pro · Destructive
Hand a secondary calendar to a different person in the same organization.
gws_update_calendar
Pro · Destructive
Replace a calendar's own details wholesale.
gws_update_calendar_acl_rule
Pro · Destructive
Replace a calendar sharing rule wholesale.
gws_update_calendar_event
Pro · Destructive
Replace an event wholesale.
gws_update_calendar_list_entry
Pro · Destructive
Replace one person's display settings for a calendar wholesale.

People

ToolWhat it does
gws_batch_create_contacts
Pro · Write
Add several contacts to one person's address book in one call.
gws_batch_delete_contacts
Pro · Destructive
Delete several contacts from one person's address book in one call.
gws_batch_get_contact_groups
Free · Read-only
Read several contact groups in one call.
gws_batch_get_people
Free · Read-only
Read several people in one call.
gws_batch_update_contacts
Pro · Write
Change several contacts in one call.
gws_copy_other_contact_to_my_contacts
Pro · Write
Copy one of the other contacts Google collected into the named person's myContacts group, making it a real saved contact.
gws_create_contact
Pro · Write
Add a contact to one person's address book.
gws_create_contact_group
Pro · Write
Create a contact group for one person to file contacts under.
gws_delete_contact
Pro · Destructive
Delete a contact from one person's address book.
gws_delete_contact_group
Pro · Destructive
Delete a contact group.
gws_delete_contact_photo
Pro · Destructive
Remove a contact's photo.
gws_get_contact_group
Free · Read-only
Read one contact group, and optionally the people in it.
gws_get_person
Free · Read-only
Read one person: a saved contact, a colleague's directory profile, or the named person themselves.
gws_list_contact_groups
Free · Read-only
List the contact groups one person files their contacts under, including the groups Google provides such as myContacts and starred.
gws_list_contacts
Free · Read-only
List the saved contacts in one person's address book.
gws_list_directory_people
Free · Read-only
List everybody in the company directory — colleagues' profiles and the domain's shared contacts — as seen by the named person.
gws_list_other_contacts
Free · Read-only
List the other contacts Google collected for one person from their mail and calendar, without them ever saving anybody.
gws_modify_contact_group_members
Pro · Write
Add people to a contact group, take them out of it, or both in one call.
gws_patch_contact
Pro · Write
Change named fields of a contact, leaving every other field alone.
gws_search_contacts
Free · Read-only
Search one person's saved contacts by name, nickname, email address, phone number or organization.
gws_search_directory_people
Free · Read-only
Search the company directory, as seen by the named person — the fastest way to find one colleague by name or address.
gws_search_other_contacts
Free · Read-only
Search the other contacts Google collected for one person, by name, email address or phone number.
gws_update_contact_group
Pro · Destructive
Replace a contact group's details.
gws_update_contact_photo
Pro · Write
Set a contact's photo.

Tasks

ToolWhat it does
gws_clear_completed_tasks
Pro · Write
Hide every completed task in a list.
gws_create_task
Pro · Write
Add a task to a list.
gws_create_task_list
Pro · Write
Create a new, empty task list for one person.
gws_delete_task
Pro · Destructive
Permanently delete one task.
gws_delete_task_list
Pro · Destructive
Permanently delete a task list and every task in it.
gws_get_task
Free · Read-only
Read one task in full — its title, notes, due date, status, where it sits under a parent, and whether it was assigned from a Google Doc or a Chat space.
gws_get_task_list
Free · Read-only
Read one task list's own details — its title and when it last changed.
gws_list_task_lists
Free · Read-only
List one person's task lists.
gws_list_tasks
Free · Read-only
List the tasks in one task list.
gws_move_task
Pro · Write
Move a task: to a different position among its siblings, under a different parent task, or into a different task list.
gws_patch_task
Pro · Write
Change only the fields you send on a task, leaving everything else as it is.
gws_patch_task_list
Pro · Write
Change only the fields you send on a task list, leaving everything else as it is.
gws_update_task
Pro · Destructive
Replace a task wholesale.
gws_update_task_list
Pro · Destructive
Replace a task list's details wholesale.

Chat

ToolWhat it does
gws_add_chat_reaction
Pro · Write
React to a Chat message as the named person.
gws_add_chat_space_member
Pro · Destructive
Add a person or a Google Group to a Chat space.
gws_create_chat_custom_emoji
Pro · Write
Publish a custom emoji for the organization.
gws_create_chat_section
Pro · Write
Add a section to the named person's Chat sidebar.
gws_create_chat_space
Pro · Write
Create a Chat space with the named person as its first and only member.
gws_delete_chat_custom_emoji
Pro · Destructive
Delete a custom emoji from the organization.
gws_delete_chat_message
Pro · Destructive
Delete a Chat message.
gws_delete_chat_section
Pro · Destructive
Delete a section from the named person's Chat sidebar.
gws_delete_chat_space
Pro · Destructive
Delete a Chat space.
gws_download_chat_attachment
Free · Read-only
Download a Chat attachment and get back a temporary link to it.
gws_find_chat_direct_message
Free · Read-only
Find the existing direct-message space between the named person and one other user.
gws_find_chat_group_chats
Free · Read-only
Find the group chats the named person shares with a given set of people.
gws_get_chat_availability
Free · Read-only
Read one person's Chat availability — whether they are shown as ACTIVE, IDLE, AWAY or DO_NOT_DISTURB, their custom status, and when a Do Not Disturb period expires.
gws_get_chat_custom_emoji
Free · Read-only
Read one custom emoji — its name, its uid, who made it and a temporary image link that is good for at least ten minutes.
gws_get_chat_message
Free · Read-only
Read one Chat message — its text, sender, thread, attachments and reactions.
gws_get_chat_space
Free · Read-only
Read one Chat space — its display name, type, description, history setting, access settings and permission settings.
gws_get_chat_space_event
Free · Read-only
Read one space event and the resource it carries — the message that was posted, the membership that changed, the reaction that was added.
gws_get_chat_space_member
Free · Read-only
Read one membership — the person or group, their role in the space, whether they have joined or only been invited, and whether they are internal or external to the organization.
gws_get_chat_space_notification_setting
Free · Read-only
Read how loudly one Chat space notifies the named person — its notification setting (ALL, MAIN_CONVERSATIONS, FOR_YOU or OFF) and whether they have muted it.
gws_get_chat_space_read_state
Free · Read-only
Read how far the named person has read in one Chat space — the timestamp their unread mark sits at.
gws_get_chat_thread_read_state
Free · Read-only
Read how far the named person has read in one Chat THREAD — the reply-level counterpart of gws_get_chat_space_read_state, which covers only a space's top-level conversation.
gws_list_chat_custom_emojis
Free · Read-only
List the custom emojis the organization has published.
gws_list_chat_message_pins
Free · Read-only
List the messages pinned to the top of a Chat space.
gws_list_chat_messages
Free · Read-only
List the messages in one Chat space, oldest first unless told otherwise.
gws_list_chat_reactions
Free · Read-only
List the reactions on one Chat message and who left them.
gws_list_chat_section_items
Free · Read-only
List what is filed in one section of the named person's Chat sidebar.
gws_list_chat_sections
Free · Read-only
List the sections the named person's Chat sidebar is filed into, custom and built-in.
gws_list_chat_space_events
Free · Read-only
List what has happened in a Chat space — messages, memberships, reactions and space changes — for the last 28 days.
gws_list_chat_space_members
Free · Read-only
List who is in a Chat space.
gws_list_chat_spaces
Free · Read-only
List the Chat spaces one person belongs to — named spaces, group chats and direct messages.
gws_mark_chat_active
Pro · Write
Show the named person as ACTIVE in Chat.
gws_mark_chat_away
Pro · Write
Show the named person as AWAY in Chat.
gws_mark_chat_do_not_disturb
Pro · Write
Put the named person into DO NOT DISTURB in Chat, which SUPPRESSES THEIR NOTIFICATIONS until it expires.
gws_move_chat_section_item
Pro · Write
Move one filed space from one section of the named person's Chat sidebar into another.
gws_patch_chat_availability
Pro · Write
Set or clear the named person's Chat CUSTOM STATUS — the short line and emoji their colleagues see beside their name.
gws_patch_chat_message
Pro · Write
Change named fields of a Chat message, leaving every field the mask does not list alone.
gws_patch_chat_section
Pro · Write
Rename a section in the named person's Chat sidebar.
gws_patch_chat_space
Pro · Write
Change named fields of a Chat space, leaving every field the mask does not list alone.
gws_patch_chat_space_member
Pro · Write
Change a member's ROLE in a Chat space — the only field Google allows this call to write.
gws_patch_chat_space_notification_setting
Pro · Write
Change how loudly one Chat space notifies the named person.
gws_patch_chat_space_read_state
Pro · Write
Mark a Chat space read or unread for the named person, by moving their last-read timestamp.
gws_pin_chat_message
Pro · Write
Pin a message to the top of its Chat space, where everyone in the space sees it.
gws_position_chat_section
Pro · Write
Move a section up or down the named person's Chat sidebar.
gws_remove_chat_reaction
Pro · Write
Take back a reaction on a Chat message.
gws_remove_chat_space_member
Pro · Destructive
Remove someone from a Chat space.
gws_search_chat_messages
Free · Read-only
Search Chat messages by keyword across the spaces the named person can see.
gws_search_chat_spaces
Free · Read-only
Search NAMED Chat spaces, including ones the named person is not a member of.
gws_send_chat_message
Pro · Destructive
Post a message to a Chat space as the named person.
gws_setup_chat_space
Pro · Write
Create a Chat space AND invite people to it in one call.
gws_unpin_chat_message
Pro · Write
Remove a pin from the top of a Chat space.
gws_update_chat_message
Pro · Destructive
Replace the fields of a Chat message WHOLESALE.

Meet

ToolWhat it does
gws_create_meet_space
Pro · Write
Create a Google Meet space owned by one person, and get back its meeting code and join link.
gws_end_meet_active_conference
Pro · Destructive
End the Google Meet call running in a space, right now.
gws_get_meet_conference_record
Free · Read-only
Get one past Google Meet call: when it started, when it ended, which space it was held in, and when Google will delete the record.
gws_get_meet_participant
Free · Read-only
Get one attendee of a past Google Meet call: when they first joined, when they last left, and whether they were signed in, dialled in by phone, or anonymous.
gws_get_meet_participant_session
Free · Read-only
Get one join-and-leave session of one attendee of a past Google Meet call.
gws_get_meet_recording
Free · Read-only
Get one recording of a past Google Meet call: when it started and stopped, its state, and where the MP4 lives in Google Drive.
gws_get_meet_smart_note
Free · Read-only
Get one Gemini smart-notes record for a past Google Meet call: when note-taking started and stopped, its state, and which Google Doc holds the summary.
gws_get_meet_space
Free · Read-only
Get a Google Meet space: its meeting code, its join link, its dial-in numbers, its access and moderation settings, and the conference running in it right now if there is one.
gws_get_meet_transcript
Free · Read-only
Get one transcription session of a past Google Meet call: when it started and stopped, its state, and which Google Doc holds the transcript.
gws_get_meet_transcript_entry
Free · Read-only
Get one speaker turn from a Google Meet transcript: the transcribed text, the participant who said it, the spoken language and its start and end times.
gws_list_meet_conference_records
Free · Read-only
List the past Google Meet calls one person can see, newest first.
gws_list_meet_participant_sessions
Free · Read-only
List one attendee's separate join-and-leave sessions within a past Google Meet call, most recent first.
gws_list_meet_participants
Free · Read-only
List who attended one past Google Meet call, most recent joiner first.
gws_list_meet_recordings
Free · Read-only
List the recordings made during one past Google Meet call, oldest first.
gws_list_meet_smart_notes
Free · Read-only
List the Gemini "take notes for me" summaries generated during one past Google Meet call, oldest first.
gws_list_meet_transcript_entries
Free · Read-only
Read what was said in a past Google Meet call as structured data: one entry per speaker turn, with the text, who said it, the spoken language and start and end times, oldest first.
gws_list_meet_transcripts
Free · Read-only
List the transcription sessions of one past Google Meet call, oldest first.
gws_patch_meet_space
Pro · Write
Change a Google Meet space's settings - who can join without knocking, whether calls in it are automatically recorded, transcribed or summarised, and how moderation behaves.

Keep

ToolWhat it does
gws_create_keep_note
Pro · Write
Create a Google Keep note owned by a named person.
gws_delete_keep_note
Pro · Destructive
PERMANENTLY delete a Google Keep note belonging to a named person.
gws_download_keep_attachment
Free · Read-only
Download the contents of an attachment on a named person's Google Keep note and get back a temporary link to it.
gws_get_keep_note
Free · Read-only
Read one Google Keep note belonging to a named person — its title, its body (either a block of text or a checklist), the people it is shared with, and the attachments hanging off it.
gws_list_keep_notes
Free · Read-only
List the Google Keep notes belonging to one named person.
gws_share_keep_note
Pro · Destructive
GRANT other people or groups access to a named person's Google Keep note.
gws_unshare_keep_note
Pro · Destructive
REVOKE access to a named person's Google Keep note.