Automate Google Cloud Identity
HumDay reads Google Cloud Identity’s own published API description and derives 35 operations from it. Describe the outcome you want in plain words — you get a program that is written, proven on real data, and run for you.
What Google Cloud Identity is
API for provisioning and managing identity resources.
API host: cloudidentity.googleapis.com
What HumDay can do in Google Cloud Identity
16 documented operations change something in Google Cloud Identity.
- POSTSends a UserInvitation to email.
/v1beta1/{name}:send - POSTCreates an InboundSsoAssignment for users and devices in a Customer under a given Group or OrgUnit.
/v1beta1/inboundSsoAssignments - POSTCreates a device. Only company-owned device may be created. Note: This method is available only to customers who have one of the following SKUs: Enterprise Standard, Enterprise Pl…
/v1beta1/devices - POSTCreates an InboundSamlSsoProfile for a customer.
/v1beta1/inboundSamlSsoProfiles - POSTAdds an IdpCredential.
/v1beta1/{parent}/idpCredentials:add - POSTCreates a Group.
/v1beta1/groups - POSTMove an OrgMembership to a new OrgUnit.
/v1beta1/{name}:move - POSTWipes the user's account on a device.
/v1beta1/{name}:wipe - POSTBlocks device from accessing user data
/v1beta1/{name}:block - POSTCancels a UserInvitation that was already sent.
/v1beta1/{name}:cancel - POSTApproves device to access user data.
/v1beta1/{name}:approve - POSTCancels an unfinished user account wipe.
/v1beta1/{name}:cancelWipe - POSTCreates a Membership.
/v1beta1/{parent}/memberships - DELETEDeletes an InboundSsoAssignment.
/v1beta1/{name} - PATCHUpdates an InboundSsoAssignment.
/v1beta1/{name} - POSTModifies the MembershipRoles of a Membership.
/v1beta1/{name}:modifyMembershipRoles
What HumDay can read from Google Cloud Identity
These are the operations a schedule or a trigger can watch.
- GETSearches for Group resources matching a specified query.
/v1beta1/groups:search - GETVerifies whether a user account is eligible to receive a UserInvitation (is an unmanaged account).
/v1beta1/{name}:isInvitableUser - GETRetrieves a list of UserInvitation resources.
/v1beta1/{parent}/userinvitations - GETLists the Group resources under a customer or namespace.
/v1beta1/groups - GETLists the InboundSsoAssignments for a Customer.
/v1beta1/inboundSsoAssignments - GETLists InboundSamlSsoProfiles for a customer.
/v1beta1/inboundSamlSsoProfiles - GETList OrgMembership resources in an OrgUnit treated as 'parent'.
/v1beta1/{parent}/memberships - GETReturns a list of IdpCredentials in an InboundSamlSsoProfile.
/v1beta1/{parent}/idpCredentials - GETLists/Searches devices.
/v1beta1/devices - GETLooks up the resource name of a Group by its EntityKey.
/v1beta1/groups:lookup - GETSearch transitive groups of a member.
/v1beta1/{parent}/memberships:searchTransitiveGroups - GETGets an InboundSsoAssignment.
/v1beta1/{name} - GETSearch transitive memberships of a group.
/v1beta1/{parent}/memberships:searchTransitiveMemberships - GETLooks up resource names of the DeviceUsers associated with the caller's credentials, as well as the properties provided in the request.
/v1beta1/{parent}:lookup - GETLists/Searches DeviceUsers.
/v1beta1/{parent}/deviceUsers - GETLooks up the resource name of a Membership by its EntityKey.
/v1beta1/{parent}/memberships:lookup - GETGet a membership graph of just a member or both a member and a group.
/v1beta1/{parent}/memberships:getMembershipGraph - GETSearches direct groups of a member.
/v1beta1/{parent}/memberships:searchDirectGroups - GETCheck a potential member for membership in a group.
/v1beta1/{parent}/memberships:checkTransitiveMembership
How automating Google Cloud Identity works
- Describe the outcome. Say what you want to happen, in your own words. No node graphs, no field mapping.
- Approve the contract. HumDay writes down exactly what it will do, what it will touch, and what it will never do. You approve it before anything is built.
- See it proven. The program runs and shows you the result before it is allowed near your live Google Cloud Identity account.
- Grant access, then go live. You approve the specific Google Cloud Identity operations it may use — and only those.
Automate Google Cloud Identity with these
- Gmail79 operations
- Google+9 operations
- Google Abusive Experience Report2 operations
- Google Accelerated Mobile Pages (AMP) URL1 operations
- Google Access Approval7 operations
- Google Access Context Manager9 operations
- Google ACME DNS2 operations
- Google Ad Exchange Buyer38 operations
- Google Ad Exchange Buyer II50 operations
- Google Ad Experience Report2 operations
- Google Admin SDK122 operations
- Google AdMob7 operations
Categories
Questions about Google Cloud Identity automation
- Can HumDay connect to Google Cloud Identity?
- Yes. HumDay reads Google Cloud Identity's own published API description and derives the operations from it, so there is no hand-built connector to wait for. 35 operations are documented.
- Do I need to write code to automate Google Cloud Identity?
- No. You describe the outcome you want in plain words. HumDay agrees a contract with you, writes the program, and shows you a test run before anything touches your Google Cloud Identity account.
- What can HumDay do in Google Cloud Identity?
- 16 of the 35 documented operations change something in Google Cloud Identity, and 19 read from it. HumDay only ever uses the specific operations your approved contract needs.
- Is my Google Cloud Identity account safe?
- Your credentials are stored encrypted and are never shown in chat, code, or logs. Every run is limited to the operations you explicitly approved, and anything that writes to Google Cloud Identity is held behind that approval.
Where this came from
The operations above are read from a published API description for Google Cloud Identity at cloudidentity.googleapis.com/$discovery/rest?version=v1beta1. Descriptions are the provider’s own words, not ours. Last published 2023-04-21.