GSuite API技术问询:获取已授权第三方应用及授权用户等信息
Got it, let's figure out how to get that detailed third-party app authorization data you need—since the CustomerUsageReports API only gives aggregated counts (like your Slack example showing 15 users), it won't cut it for per-user mappings or permission details. Here's the step-by-step solution using Google's Admin SDK:
1. Fetch Per-User Authorized Apps with the Directory API
The Directory API's oauthAuthorizedApps.list endpoint is your go-to here. It lets you pull every third-party app a specific user has authorized. You'll just need to loop through all users in your domain to collect this data across your team.
Quick Pseudocode Example (Python)
from googleapiclient.discovery import build # Set up the Directory API client (make sure you have valid credentials) directory_service = build('admin', 'directory_v1', credentials=your_service_account_creds) # Grab all users in your domain (add pagination if you have a large team) domain_users = directory_service.users().list(domain='your-company.com', maxResults=500).execute() # Loop through each user to get their authorized apps for user in domain_users.get('users', []): user_email = user['primaryEmail'] user_apps = directory_service.oauthAuthorizedApps().list(userKey=user_email).execute() for app in user_apps.get('items', []): print(f"User: {user_email}") print(f"App Name: {app['displayName']}") print(f"Client ID: {app['clientId']}") # We'll pull permission scopes next
2. Get Exact Permission Scopes for Each App
Every entry from the oauthAuthorizedApps.list response includes a scopes field that lists all the specific permissions the user granted to the app. These are URL strings (like https://www.googleapis.com/auth/gmail.readonly or https://www.googleapis.com/auth/calendar.events) that map directly to actions the app can take.
Example Scope Data from a Response
{ "displayName": "Slack", "clientId": "<censored>.apps.googleusercontent.com", "scopes": [ "https://www.googleapis.com/auth/userinfo.email", "https://www.googleapis.com/auth/calendar.readonly", "https://www.googleapis.com/auth/gmail.readonly" ], "creationTime": "2023-01-15T10:30:00Z" }
You can either parse these URLs directly (the path usually tells you the permission, like /auth/gmail.readonly = read-only Gmail access) or cross-reference them with Google's published scope docs for more human-friendly labels.
3. Aggregate Data for Full Visibility
Once you have all the per-user data, you can aggregate it to:
- List every unique authorized app across your domain
- Count how many users have authorized each app (to cross-check with your
CustomerUsageReportsdata) - Compile all permissions each app has been granted across your team
Key Requirements & Tips
- Permissions: Your service account needs the
OAuth Authorized Apps Viewerrole in your Google Admin console, and you must have theAdmin SDK Directory APIenabled in your Google Cloud project. - Pagination: If you have a large team, implement pagination when fetching users and apps to avoid hitting rate limits.
- Filtering: Use the
scopesfield to filter apps by specific permissions (e.g., find all apps with access to read emails or modify calendars).
Pro Tip: If you want a high-level audit of domain-wide app permissions, you can use
CustomerUsageReportswith the parameterparameters=oauth_apps—but this still won't give per-user mappings, so combining it with the Directory API is the only way to get full details.
内容的提问来源于stack exchange,提问作者Dieter

