Skip to content
imper.ai

Google Workspace Permissions

For the helpdesk use case, imper.ai requires the following Google Workspace API scopes to build identity verification questions and to reset passwords during remediation. These scopes are authorized through Domain-Wide Delegation by a Google Workspace Super Admin.

This article explains which scopes are required and why they are needed.


Scopes Requested by imper.ai

…/auth/admin.directory.user

Used for:

  • Reading user profiles and resetting a user's password during helpdesk remediation

…/auth/admin.directory.group.readonly

Used for:

  • Reading groups to provide organizational context for verification

…/auth/admin.directory.device.mobile.readonly

Used for:

  • Reading mobile device information used during verification

…/auth/calendar.readonly

Used for:

  • Reading calendar settings and events to generate verification questions

…/auth/calendar.events.readonly

Used for:

  • Reading calendar events to generate verification questions

…/auth/gmail.readonly

Used for:

  • Reading email metadata to generate verification questions

…/auth/userinfo.email

Used for:

  • Viewing the user's email address to identify and link their Google account

…/auth/userinfo.profile

Used for:

  • Accessing basic profile information for user identification

openid

Used for:

  • Authenticating the user