關於 Google Workspace 的其他注意事項
透過集合功能整理內容
你可以依據偏好儲存及分類內容。
如果應用程式的目標對象是外部使用者,您可能希望盡可能觸及更多 Google 帳戶,包括由 Google Workspace 機構管理的 Google 帳戶。
Google Workspace 管理員可以透過 API 存取控制選項,啟用或限制客戶和第三方的應用程式及服務帳戶對於 Google Workspace API 的存取權。Google Workspace 管理員可透過這項功能,限制只有機構信任的 OAuth 用戶端 ID 才能存取,藉此降低第三方存取 Google 服務的相關風險。
為盡可能觸及最多 Google 帳戶使用者,並建立信任感,建議您採取下列做法:
- 將應用程式送交 Google 驗證。如適用,您必須將應用程式送交品牌驗證,以及機密和受限制範圍驗證。Google Workspace 管理員可以查看應用程式的驗證狀態,他們可能會信任 Google 驗證過的應用程式,而非狀態為「未驗證」或不明的應用程式。
- Google Workspace 管理員可以授予應用程式的 OAuth 用戶端 ID 存取受限制服務和高風險範圍的權限。如果您在說明文件中加入應用程式的 OAuth 用戶端 ID,Google Workspace 管理員和貴機構的應用程式擁護者就能取得授權應用程式存取權所需的資訊,也能瞭解應用程式存取機構資料前可能需要進行哪些設定變更。
- 定期監控您在設定 OAuth Consent Screen page時提供的使用者支援電子郵件地址。Google Workspace 管理員在審查應用程式存取權時,會看到這個電子郵件地址,並可能向您提出相關問題和疑慮。
將專案與機構建立關聯
如果您是 Google Workspace 使用者,強烈建議您在 Google Workspace 或 Cloud Identity 帳戶的機構資源中建立開發人員專案。這樣一來,您就能使用企業管理功能,例如重要通知、存取權控管和專案生命週期管理,不必將其連結至個別開發人員帳戶。否則日後可能難以 (或無法) 轉移給新擁有者。
設定開發人員專案時,請在機構中建立專案,或將現有專案遷移至機構。
除非另有註明,否則本頁面中的內容是採用創用 CC 姓名標示 4.0 授權,程式碼範例則為阿帕契 2.0 授權。詳情請參閱《Google Developers 網站政策》。Java 是 Oracle 和/或其關聯企業的註冊商標。
上次更新時間:2025-08-31 (世界標準時間)。
[null,null,["上次更新時間:2025-08-31 (世界標準時間)。"],[[["\u003cp\u003eApps targeting external Google Accounts should consider Google Workspace admin controls and aim for wide accessibility.\u003c/p\u003e\n"],["\u003cp\u003eVerification of your app by Google, including brand and sensitive/restricted scopes, builds trust with Google Workspace admins.\u003c/p\u003e\n"],["\u003cp\u003eTo enable access, provide your app's OAuth client ID to Google Workspace admins for configuration.\u003c/p\u003e\n"],["\u003cp\u003eAssociate your developer project with a Google Workspace or Cloud Identity organization for better management and future transitions.\u003c/p\u003e\n"],["\u003cp\u003eActively monitor your support email address for inquiries from Google Workspace admins regarding your app's access.\u003c/p\u003e\n"]]],[],null,["If your app targets an\n[external user\ntype](https://support.google.com/cloud/answer/10311615#user-type-external), you might want to address the widest possible audience of Google Accounts, which\nincludes Google Accounts administered by a Google Workspace organization.\n\nGoogle Workspace administrators can use [API\naccess controls](https://support.google.com/a/answer/7281227) to enable or restrict access to Google Workspace APIs for customer-owned and\nthird-party applications and service accounts. This feature lets Google Workspace administrators\nrestrict access to only OAuth client IDs that are trusted by the organization, which reduces the\nrisk associated with third-party access to Google Services.\n\nTo reach the widest possible audience of Google Accounts and to foster trust, we recommend the\nfollowing:\n\n- Submit your app for verification by Google. If applicable, you must submit your app for [brand\n verification](/identity/protocols/oauth2/production-readiness/brand-verification), as well as [sensitive](/identity/protocols/oauth2/production-readiness/sensitive-scope-verification) and [restricted](/identity/protocols/oauth2/production-readiness/restricted-scope-verification) scopes verification. Google Workspace admins can view your app's verified status, and they might trust apps that Google verifies more than apps with an [unverified](https://support.google.com/a/answer/9352843) or unknown status.\n- Google Workspace admins can give your app's OAuth client IDs access to restricted services and the high-risk scopes within. If you include your app's OAuth client ID in your help documents, you can provide Google Workspace admins, and advocates for your app within their organizations, the information needed to give access to your app. It can also help them understand what configuration changes might be needed before your app can access an organization's data.\n- Routinely monitor your user support email address that you provide when you configure your OAuth [Consent Screen page](https://console.developers.google.com/apis/credentials/consent). Google Workspace admins can view this email address when they review your app's access, and they might reach out to you with possible questions and concerns.\n\nAssociate your project with an organization\n\nIf you are a Google Workspace user, it is strongly recommended that your developer project is\ncreated inside a [organization resource](https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy#organizations) within your [Google Workspace](https://gsuite.google.com/)\nor [Cloud Identity](https://cloud.google.com/identity) account. This allows you to\nuse [enterprise management features](https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy#benefits_of_the_organization_resource), such as\n[important notifications](https://cloud.google.com/resource-manager/docs/managing-notification-contacts), access control and project lifecycle management, without tying it\nto an individual developer account. Otherwise, it might be difficult (or impossible) to transfer\nto a new owner in the future.\n\nWhen setting up your developer project,\n[create it in\nan organization](https://cloud.google.com/resource-manager/docs/creating-managing-projects) or\n[migrate your\nexisting projects into an organization](https://cloud.google.com/resource-manager/docs/migrating-projects-billing)."]]