Google Workspace 管理:管理用户和群组 - Openclaw Skills
什么是 Google Workspace 管理?
Google Workspace Admin 技能为 Google Workspace Admin SDK 提供了一个安全的托管网关。通过处理复杂的 OAuth 流程和令牌管理,它允许开发人员和 AI 代理以编程方式管理域名设置、用户帐户和组织结构。此 Openclaw Skills 集成作为 admin.googleapis.com 的专业级代理,自动将必要的身份验证令牌注入到每个请求中。
利用此技能可简化组织管理的生命周期,实现 IT 运营的高级自动化,而无需构建自定义身份验证逻辑。它是扩展管理工作流并确保在 Google 生态系统内的大型用户群中实施一致策略的必备工具。
下载入口:https://github.com/openclaw/skills/tree/main/skills/byungkyu/google-workspace-admin
安装与下载
1. ClawHub CLI
从源直接安装技能的最快方式。
npx clawhub@latest install google-workspace-admin
2. 手动安装
将技能文件夹复制到以下位置之一
全局模式~/.openclaw/skills/
工作区
<project>/skills/
优先级:工作区 > 本地 > 内置
3. 提示词安装
将此提示词复制到 OpenClaw 即可自动安装。
请帮我使用 Clawhub 安装 google-workspace-admin。如果尚未安装 Clawhub,请先安装(npm i -g clawhub)。
Google Workspace 管理 应用场景
- 在 HR 变动期间自动执行域用户的入职和离职流程。
- 根据外部数据库触发器或团队变动同步群组成员身份。
- 管理组织单位层级,以实施特定的安全和访问控制策略。
- 监控域设置并审计管理员角色分配以确保安全合规。
- 跨整个域批量更新用户资料、重置密码或停用帐户。
- 用户获取 Maton API 密钥并在其环境中进行配置,以便与网关进行身份验证。
- 使用控制 API 创建到 Google Workspace Admin 应用程序的连接。
- 用户通过连接管理系统提供的唯一 URL 完成 OAuth 授权过程。
- 管理请求被发送到网关,网关识别正确的连接并将调用代理到原生 Google Admin SDK 端点。
- 网关自动注入活动的 OAuth 令牌,并将来自 Google 的结构化 JSON 响应返回给请求者。
Google Workspace 管理 配置指南
要开始使用此技能,请确保您的环境已配置您的 API 凭据。
# 设置您的 Maton API 密钥
export MATON_API_KEY="YOUR_API_KEY"
# 为 Google Workspace Admin 创建连接
python <<'EOF'
import urllib.request, os, json
data = json.dumps({'app': 'google-workspace-admin'}).encode()
req = urllib.request.Request('https://ctrl.maton.ai/connections', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Google Workspace 管理 数据架构与分类体系
该技能与标准的 Google Workspace Directory API 对象交互。关键资源及其元数据包括:
| 资源 | 描述 | 主要标识符 |
|---|---|---|
| 用户 | 帐户详情、状态和登录元数据 | primaryEmail, id |
| 群组 | 邮件列表和安全组定义 | email, id |
| 组织单位 | 用于策略应用的层级结构 | orgUnitPath |
| 角色 | 管理权限和分配 | roleId |
| 域名 | 已验证的域名设置和别名 | domainName |
name: google-workspace-admin
description: |
Google Workspace Admin SDK integration with managed OAuth. Manage users, groups, organizational units, and domain settings. Use this skill when users want to administer Google Workspace. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).
compatibility: Requires network access and valid Maton API key
metadata:
author: maton
version: "1.0"
clawdbot:
emoji: ??
homepage: "https://maton.ai"
requires:
env:
- MATON_API_KEY
Google Workspace Admin
Access the Google Workspace Admin SDK with managed OAuth authentication. Manage users, groups, organizational units, roles, and domain settings for Google Workspace.
Quick Start
# List users in the domain
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://gateway.maton.ai/google-workspace-admin/admin/directory/v1/users?customer=my_customer&maxResults=10')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Base URL
https://gateway.maton.ai/google-workspace-admin/{native-api-path}
Replace {native-api-path} with the actual Admin SDK API endpoint path. The gateway proxies requests to admin.googleapis.com and automatically injects your OAuth token.
Authentication
All requests require the Maton API key in the Authorization header:
Authorization: Bearer $MATON_API_KEY
Environment Variable: Set your API key as MATON_API_KEY:
export MATON_API_KEY="YOUR_API_KEY"
Getting Your API Key
- Sign in or create an account at maton.ai
- Go to maton.ai/settings
- Copy your API key
Connection Management
Manage your Google OAuth connections at https://ctrl.maton.ai.
List Connections
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections?app=google-workspace-admin&status=ACTIVE')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Create Connection
python <<'EOF'
import urllib.request, os, json
data = json.dumps({'app': 'google-workspace-admin'}).encode()
req = urllib.request.Request('https://ctrl.maton.ai/connections', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Get Connection
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Response:
{
"connection": {
"connection_id": "21fd90f9-5935-43cd-b6c8-bde9d915ca80",
"status": "ACTIVE",
"creation_time": "2025-12-08T07:20:53.488460Z",
"last_updated_time": "2026-01-31T20:03:32.593153Z",
"url": "https://connect.maton.ai/?session_token=...",
"app": "google-workspace-admin",
"metadata": {}
}
}
Open the returned url in a browser to complete OAuth authorization.
Delete Connection
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}', method='DELETE')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Specifying Connection
If you have multiple Google Workspace Admin connections, specify which one to use with the Maton-Connection header:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://gateway.maton.ai/google-workspace-admin/admin/directory/v1/users?customer=my_customer')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Maton-Connection', '21fd90f9-5935-43cd-b6c8-bde9d915ca80')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
If omitted, the gateway uses the default (oldest) active connection.
API Reference
Users
List Users
GET /google-workspace-admin/admin/directory/v1/users?customer=my_customer&maxResults=100
Query parameters:
customer- Customer ID ormy_customerfor your domain (required)domain- Filter by specific domainmaxResults- Maximum results per page (1-500, default 100)orderBy- Sort byemail,familyName, orgivenNamequery- Search query (e.g.,email:john*,name:John*)pageToken- Token for pagination
Example:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://gateway.maton.ai/google-workspace-admin/admin/directory/v1/users?customer=my_customer&query=email:john*')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Response:
{
"kind": "admin#directory#users",
"users": [
{
"id": "123456789",
"primaryEmail": "[email protected]",
"name": {
"givenName": "John",
"familyName": "Doe",
"fullName": "John Doe"
},
"isAdmin": false,
"isDelegatedAdmin": false,
"suspended": false,
"creationTime": "2024-01-15T10:30:00.000Z",
"lastLoginTime": "2025-02-01T08:00:00.000Z",
"orgUnitPath": "/Sales"
}
],
"nextPageToken": "..."
}
Get User
GET /google-workspace-admin/admin/directory/v1/users/{userKey}
userKey can be the user's primary email or unique user ID.
Create User
POST /google-workspace-admin/admin/directory/v1/users
Content-Type: application/json
{
"primaryEmail": "[email protected]",
"name": {
"givenName": "Jane",
"familyName": "Smith"
},
"password": "temporaryPassword123!",
"changePasswordAtNextLogin": true,
"orgUnitPath": "/Engineering"
}
Update User
PUT /google-workspace-admin/admin/directory/v1/users/{userKey}
Content-Type: application/json
{
"name": {
"givenName": "Jane",
"familyName": "Smith-Johnson"
},
"suspended": false,
"orgUnitPath": "/Sales"
}
Patch User (partial update)
PATCH /google-workspace-admin/admin/directory/v1/users/{userKey}
Content-Type: application/json
{
"suspended": true
}
Delete User
DELETE /google-workspace-admin/admin/directory/v1/users/{userKey}
Make User Admin
POST /google-workspace-admin/admin/directory/v1/users/{userKey}/makeAdmin
Content-Type: application/json
{
"status": true
}
Groups
List Groups
GET /google-workspace-admin/admin/directory/v1/groups?customer=my_customer
Query parameters:
customer- Customer ID ormy_customer(required)domain- Filter by domainmaxResults- Maximum results (1-200)userKey- List groups for a specific user
Get Group
GET /google-workspace-admin/admin/directory/v1/groups/{groupKey}
groupKey can be the group's email or unique ID.
Create Group
POST /google-workspace-admin/admin/directory/v1/groups
Content-Type: application/json
{
"email": "[email protected]",
"name": "Engineering Team",
"description": "All engineering staff"
}
Update Group
PUT /google-workspace-admin/admin/directory/v1/groups/{groupKey}
Content-Type: application/json
{
"name": "Engineering Department",
"description": "Updated description"
}
Delete Group
DELETE /google-workspace-admin/admin/directory/v1/groups/{groupKey}
Group Members
List Members
GET /google-workspace-admin/admin/directory/v1/groups/{groupKey}/members
Add Member
POST /google-workspace-admin/admin/directory/v1/groups/{groupKey}/members
Content-Type: application/json
{
"email": "[email protected]",
"role": "MEMBER"
}
Roles: OWNER, MANAGER, MEMBER
Update Member Role
PATCH /google-workspace-admin/admin/directory/v1/groups/{groupKey}/members/{memberKey}
Content-Type: application/json
{
"role": "MANAGER"
}
Remove Member
DELETE /google-workspace-admin/admin/directory/v1/groups/{groupKey}/members/{memberKey}
Organizational Units
List Org Units
GET /google-workspace-admin/admin/directory/v1/customer/my_customer/orgunits
Query parameters:
type-all(default) orchildrenorgUnitPath- Parent org unit path
Get Org Unit
GET /google-workspace-admin/admin/directory/v1/customer/my_customer/orgunits/{orgUnitPath}
Create Org Unit
POST /google-workspace-admin/admin/directory/v1/customer/my_customer/orgunits
Content-Type: application/json
{
"name": "Engineering",
"parentOrgUnitPath": "/",
"description": "Engineering department"
}
Update Org Unit
PUT /google-workspace-admin/admin/directory/v1/customer/my_customer/orgunits/{orgUnitPath}
Content-Type: application/json
{
"description": "Updated description"
}
Delete Org Unit
DELETE /google-workspace-admin/admin/directory/v1/customer/my_customer/orgunits/{orgUnitPath}
Domains
List Domains
GET /google-workspace-admin/admin/directory/v1/customer/my_customer/domains
Get Domain
GET /google-workspace-admin/admin/directory/v1/customer/my_customer/domains/{domainName}
Roles
List Roles
GET /google-workspace-admin/admin/directory/v1/customer/my_customer/roles
List Role Assignments
GET /google-workspace-admin/admin/directory/v1/customer/my_customer/roleassignments
Query parameters:
userKey- Filter by userroleId- Filter by role
Create Role Assignment
POST /google-workspace-admin/admin/directory/v1/customer/my_customer/roleassignments
Content-Type: application/json
{
"roleId": "123456789",
"assignedTo": "user_id",
"scopeType": "CUSTOMER"
}
Code Examples
JavaScript
const headers = {
'Authorization': `Bearer ${process.env.MATON_API_KEY}`
};
// List users
const users = await fetch(
'https://gateway.maton.ai/google-workspace-admin/admin/directory/v1/users?customer=my_customer',
{ headers }
).then(r => r.json());
// Create user
await fetch(
'https://gateway.maton.ai/google-workspace-admin/admin/directory/v1/users',
{
method: 'POST',
headers: { ...headers, 'Content-Type': 'application/json' },
body: JSON.stringify({
primaryEmail: '[email protected]',
name: { givenName: 'New', familyName: 'User' },
password: 'TempPass123!',
changePasswordAtNextLogin: true
})
}
);
Python
import os
import requests
headers = {'Authorization': f'Bearer {os.environ["MATON_API_KEY"]}'}
# List users
users = requests.get(
'https://gateway.maton.ai/google-workspace-admin/admin/directory/v1/users',
headers=headers,
params={'customer': 'my_customer'}
).json()
# Create user
response = requests.post(
'https://gateway.maton.ai/google-workspace-admin/admin/directory/v1/users',
headers=headers,
json={
'primaryEmail': '[email protected]',
'name': {'givenName': 'New', 'familyName': 'User'},
'password': 'TempPass123!',
'changePasswordAtNextLogin': True
}
)
Notes
- Use
my_customeras the customer ID for your own domain - User keys can be primary email or unique user ID
- Group keys can be group email or unique group ID
- Org unit paths start with
/(e.g.,/Engineering/Frontend) - Admin privileges are required for most operations
- Password must meet Google's complexity requirements
- IMPORTANT: When using curl commands, use
curl -gwhen URLs contain brackets (fields[],sort[],records[]) to disable glob parsing - IMPORTANT: When piping curl output to
jqor other commands, environment variables like$MATON_API_KEYmay not expand correctly in some shell environments. You may get "Invalid API key" errors when piping.
Error Handling
| Status | Meaning |
|---|---|
| 400 | Missing Google Workspace Admin connection |
| 401 | Invalid or missing Maton API key |
| 403 | Insufficient admin privileges |
| 404 | User, group, or resource not found |
| 429 | Rate limited (10 req/sec per account) |
| 4xx/5xx | Passthrough error from Admin SDK API |
Troubleshooting: API Key Issues
- Check that the
MATON_API_KEYenvironment variable is set:
echo $MATON_API_KEY
- Verify the API key is valid by listing connections:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Troubleshooting: Invalid App Name
- Ensure your URL path starts with
google-workspace-admin. For example:
- Correct:
https://gateway.maton.ai/google-workspace-admin/admin/directory/v1/users?customer=my_customer - Incorrect:
https://gateway.maton.ai/admin/directory/v1/users?customer=my_customer
Resources
-
07.31
遗忘之海渡桥岛遗迹如何进 遗忘之海渡桥岛遗迹探索攻略
-
07.31
遗忘之海角色分享内容一览 遗忘之海有什么角色
-
07.31
遗忘之海捏脸玩法实用技巧 遗忘之海捏脸玩法分享
-
07.31
遗忘之海小斧头是谁 遗忘之海小斧头角色分享
-
07.31
遗忘之海是什么类型的游戏 遗忘之海玩法内容详细说明
-
07.31
龙之剑觉醒最终配装如何搭配 龙之剑觉醒最终配装思路分享
-
-
- 下一站江湖2百殊刀怎么获得
- 07.31
-
- 名将杀2V2如何快速上分
- 07.31
-
- 异环shinku是谁
- 07.31
-
- 掌上英雄联盟如何查看胜率排行
- 07.31
-
- 卡牌修仙传狐狸获取方法途径分享
- 07.31
-
-
下载
- |
-
-
下载
- 《行尸走肉第一章》免安装中文汉化硬盘版下载
- 单机|436 MB
- 一款以动作冒险为主题的游戏
-
-
下载
- 《街头霸王X铁拳》免安装中文汉化硬盘版下载
- 单机|111MB
- 一款非常好玩的格斗游戏
-
-
下载
- |
-
-
下载
- 《暗黑破坏神3》免安装繁体中文正式版下载
- 单机|7630 MB
- 一款以角色扮演为主题的游戏
-
-
下载
- 《马克思佩恩3》免安装硬盘版下载
- 单机|27033 MB
- 一款以第三人称射击为主题的游戏