Sign in with a Google account or a Google Workspace domain.
My Wiki) and click Create.My Wiki) and a User support email. Click Next.My Wiki).Important
If you want any Google account authorized by the configuration above to be able to login, you need to enable Registration option on the Google strategy you created. Otherwise, only existing accounts with an email address that match the Google account will be allowed to login.
Tip
To obtain the Authorization Callback URL, you must first click Apply on the newly added strategy (It won't be active until you check the Enabled checkbox). The endpoint URL will then be displayed at the bottom of the page under the Configuration Reference section.
| Property | Description | Default Value |
|---|---|---|
| Client ID | From the OAuth 2.0 Client ID created in the Google Cloud console. | |
| Client Secret | From the same OAuth 2.0 Client ID. | |
| Restrict to Workspace Domain | A Workspace domain, e.g. example.com. Only accounts on it may sign in — checked here as well as asked for, since the parameter alone is a hint to Google rather than a guarantee. | |
| Accept Unverified Addresses | Off by default. A Google account whose address is unverified proves nothing about the mailbox, and an account here is matched on the address. | |
| Map Groups | Put the user in the wiki groups their Google Workspace groups name, on every login. Only groups that already exist here are matched — nothing is created. Workspace only, and it needs the Cloud Identity API enabled on the Google Cloud project this OAuth client belongs to. | |
| Match Groups By | Which of the two things a Workspace group has is matched against the names of the groups here — the address, [email protected], or the display name, Engineering. The address is unique and survives a rename; the display name reads better, but two groups may share one and then both match. | Group address |
| Unassign from groups no longer present in Workspace | Off adds what Workspace names and takes nothing away, so a membership granted here survives. On makes Workspace the authority instead, and a group somebody is removed from there is taken away here — bar the groups this strategy auto-enrolls into, which are granted here to everyone it lets in. |