Google Identity Platform
Overview
The Google Identity Platform integration lets Ploy see every account in one of your Identity Platform user pools, whether each account is enabled, and which second factors it has enrolled. Ploy can also create, disable, re-enable and delete accounts from flows and access requests.
This integration is in beta. It was built from Google's published API behaviour and has not yet been verified against a live Identity Platform project. While it is in beta, the first step of setup is a required consent checkbox: by ticking it you allow Ploy to keep redacted copies of error responses from Google (with personal data such as names and email addresses removed) so we can fix problems quickly. Nothing else changes while the integration is in beta.
What Ploy reads
Every account in the connected user pool, keyed on its Identity Platform user ID, with its email address and display name.
Whether each account is enabled or disabled. Disabled accounts are shown as having lost access.
Whether each account has a second factor enrolled (phone, authenticator app or email).
The user pool itself, shown as an account resource.
Anonymous accounts (guest sessions with no email, phone number or linked sign-in provider) are not imported. Identity Platform has no groups or roles for its users, so none are shown.
Before you start
You need permission in Google Cloud to create service accounts and keys, and to grant IAM roles, on the project that runs Identity Platform.
One connection reads one user pool: either the project's own users, or one tenant inside it. If your project uses multi-tenancy and you want several tenants in Ploy, connect each tenant separately.
Step 1: Create a service account for Ploy
In the Google Cloud console, open the project that runs Identity Platform.
Go to IAM & Admin, then Service Accounts, and create a service account named, for example,
ploy-identity-platform.Grant it a role that holds the permissions below. If no predefined role fits, create a custom role under IAM & Admin, Roles with exactly these permissions.
To read accounts, the role needs:
firebaseauth.users.get
To let Ploy create, disable, re-enable and delete accounts, the role also needs:
firebaseauth.users.createfirebaseauth.users.updatefirebaseauth.users.deletefirebaseauth.users.sendEmail
Step 2: Create a JSON key
Open the service account, go to the Keys tab and choose Add key, then Create new key.
Choose JSON. Google Cloud downloads a key file. Keep it safe: it is the only copy.
Step 3: Connect in Ploy
In Ploy, go to Integrations, find Google Identity Platform and choose Connect.
Tick the beta consent checkbox.
Paste the whole contents of the JSON key file, from the opening brace to the closing one.
Enter the Google Cloud project ID. It is shown on the project's dashboard and is usually the
project_idin the key file.If you want one tenant's users rather than the project's own, enter the tenant ID shown on Identity Platform's Tenants page. Otherwise leave it blank.
Choose Test connection. Ploy reads one account to confirm the key, project and tenant are right, then save.
Ploy scans the user pool every six hours.
What Ploy can change
Create user: creates an enabled account with the person's email address and name. Ploy does not set a password. You can choose to have Identity Platform email the person a link to set their own password.
Disable and re-enable: disabling blocks sign-in and also signs the person out of any existing sessions. Re-enabling lets them sign in again.
Remove user: permanently deletes the account. Identity Platform has no way to restore a deleted account. Removing someone who is already gone counts as done.
Troubleshooting
Google rejected the service account key: the key may have been deleted or the service account disabled. Create a new key and paste it again.
The service account cannot read users: grant it a role holding
firebaseauth.users.geton the project.Google could not find that project or tenant: check the project ID and tenant ID, and that Identity Platform is enabled on the project.
A change from Ploy was refused: the service account is missing one of the write permissions listed in Step 1.