Overview
This guide explains how to integrate Trustifi inbound and outbound protection with Google Workspaces using the Google Workspace API. The integration enables automated synchronization of Google groups and aliases, mailbox threat scanning and remediation, removal of existing malicious emails, and additional advanced Trustifi module functionality.
Step-by-Step Guide
Step 1: Navigating to the Google Workspace Integration in Trustifi
Ensure you have Global Admin permissions in your Google tenant, then follow these steps:
From either “Outbound Management” or "Inbound Management" navigate to the “Integrations” tab.
Find and select the "Google Workspace" section.

Click on the "Connect" button.

Step 2: Navigating to Domain Wide Delegation in Google Admin Center
Open a new browser tab and sign in to the Google Admin Center using a Google Global Admin account.
Navigate to the "API Controls" page.
Click "Manage Domain Wide Delegation".

Step 3: Adding the Trustifi Client ID
On the Domain Wide Delegation page, click "Add new".

Return to the Trustifi portal integration window and copy the "Client ID" (available through the provided link in section 5 of the interface).

Paste the copied Client ID into the corresponding field in the Google Admin Center.

Step 4: Adding the Trustifi OAuth Scopes
In the Trustifi integration window, copy the OAuth scopes (available through the provided link in section 6).

Paste the OAuth scopes into the appropriate field in the Google Admin Center pop-up.

Click "Authorize".
Verify that the Trustifi API client now appears in the API client list with 7 total scopes.

Step 5: Locating and Copying the Google Entity ID
In the Google Admin Center, navigate to:
"Set up single sign-on (SSO) with Google as the SAML Identity Provider (IdP)".
Locate the "Entity ID" URL.
Example format:https://accounts.google.com/o/saml2?idpid={your_ID_here}
Copy the ID segment that appears after idpid=.

Step 6: Finalizing the API Connection in Trustifi
Return to the Trustifi portal Google Workspace integration interface.
Enter the following:
Your Google Global Admin email address
The copied Entity ID

Click "Connect" to finalize the connection.
The connection process completes in approximately one minute.
Once successful, the connection status displays as "Connected" in green.
