You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GSuite API技术问询:获取已授权第三方应用及授权用户等信息

How to Get Granular Third-Party App Authorization Data for Your Team

Got it, let's figure out how to get that detailed third-party app authorization data you need—since the CustomerUsageReports API only gives aggregated counts (like your Slack example showing 15 users), it won't cut it for per-user mappings or permission details. Here's the step-by-step solution using Google's Admin SDK:

1. Fetch Per-User Authorized Apps with the Directory API

The Directory API's oauthAuthorizedApps.list endpoint is your go-to here. It lets you pull every third-party app a specific user has authorized. You'll just need to loop through all users in your domain to collect this data across your team.

Quick Pseudocode Example (Python)

from googleapiclient.discovery import build

# Set up the Directory API client (make sure you have valid credentials)
directory_service = build('admin', 'directory_v1', credentials=your_service_account_creds)

# Grab all users in your domain (add pagination if you have a large team)
domain_users = directory_service.users().list(domain='your-company.com', maxResults=500).execute()

# Loop through each user to get their authorized apps
for user in domain_users.get('users', []):
    user_email = user['primaryEmail']
    user_apps = directory_service.oauthAuthorizedApps().list(userKey=user_email).execute()
    
    for app in user_apps.get('items', []):
        print(f"User: {user_email}")
        print(f"App Name: {app['displayName']}")
        print(f"Client ID: {app['clientId']}")
        # We'll pull permission scopes next

2. Get Exact Permission Scopes for Each App

Every entry from the oauthAuthorizedApps.list response includes a scopes field that lists all the specific permissions the user granted to the app. These are URL strings (like https://www.googleapis.com/auth/gmail.readonly or https://www.googleapis.com/auth/calendar.events) that map directly to actions the app can take.

Example Scope Data from a Response

{
  "displayName": "Slack",
  "clientId": "<censored>.apps.googleusercontent.com",
  "scopes": [
    "https://www.googleapis.com/auth/userinfo.email",
    "https://www.googleapis.com/auth/calendar.readonly",
    "https://www.googleapis.com/auth/gmail.readonly"
  ],
  "creationTime": "2023-01-15T10:30:00Z"
}

You can either parse these URLs directly (the path usually tells you the permission, like /auth/gmail.readonly = read-only Gmail access) or cross-reference them with Google's published scope docs for more human-friendly labels.

3. Aggregate Data for Full Visibility

Once you have all the per-user data, you can aggregate it to:

  • List every unique authorized app across your domain
  • Count how many users have authorized each app (to cross-check with your CustomerUsageReports data)
  • Compile all permissions each app has been granted across your team

Key Requirements & Tips

  • Permissions: Your service account needs the OAuth Authorized Apps Viewer role in your Google Admin console, and you must have the Admin SDK Directory API enabled in your Google Cloud project.
  • Pagination: If you have a large team, implement pagination when fetching users and apps to avoid hitting rate limits.
  • Filtering: Use the scopes field to filter apps by specific permissions (e.g., find all apps with access to read emails or modify calendars).

Pro Tip: If you want a high-level audit of domain-wide app permissions, you can use CustomerUsageReports with the parameter parameters=oauth_apps—but this still won't give per-user mappings, so combining it with the Directory API is the only way to get full details.

内容的提问来源于stack exchange,提问作者Dieter

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:42:53