Configure a Shared Account for a Google Workspace App Integration in Okta
Last Updated:
Overview
A shared account for a single Google Workspace application integration requires an existing main integration in Okta. Administrators must create a separate Google Workspace application integration for each shared account and use Postman to share the x.509 certificate between the applications.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Google Workspace App Integration
Solution
The shared application integration requires specific configuration.
Create a new Google Workspace application integration and configure the domain and sign-on settings by following these steps.
- Set the domain to match that of the main application integration from which the shared account originates.
- Select the links to display (it is possible to display more than one).
- Click Save or Next and navigate to the Sign On tab.
- Scroll down to the Credentials Details section and select Custom for the Application username format.
- Enter the shared account name in double quotes in the text box and click Save.
How is the certificate shared with the new Google Workspace application instance?
Sharing an existing certificate between two applications requires user-based API access and the Postman Apps API collection.
In order to share the existing certificate with the new app integration, the following is needed:
- User-based API access setup (super user access).
- Fork the Apps API collection and use it in the Postman environment.
- After the Postman environment with Okta is set up, share the certificates between apps.
Retrieve the application IDs and key IDs to clone the certificate using Postman by following these steps.
- Open Postman, navigate to the Apps collection, and use the List Apps API command to retrieve the application ID for the source application (App1).
- Retrieve the key ID for the source application (App1).
- Retrieve the application ID for the target application (App2).
- Navigate to the Apps collection, select Certificate Operations, and search for the Share/Clone certificate API call.
- Execute the API call using the following format:
{{url}}/api/v1/apps/app1ID/credentials/keys/{{keyIdForApp1}}/clone?targetAid=app2ID
NOTE: App1 is the source application from which the certificate is shared, and App2 is the target application that receives the certificate.
The new certificate requires activation and user assignment.
Activate the shared certificate and assign users to the new Google Workspace application by following these steps.
- Activate the certificate in the new Google Workspace shared application.
- Assign users or groups to the application and test the configuration.
When a user clicks the shared Google Workspace application, a new tab opens for the Google application logged in as the shared account user.
NOTE: Using a shared account poses security risks. These steps provide a workaround, and administrators assume any security risk arising from using a shared account.
