Google Workspace · Arazzo Workflow

Google Workspace Reset a User Password

Version 1.0.0

Confirm a user, set a new password forcing change at next login, sign them out.

1 workflow 1 source API 1 provider
View Spec View on GitHub CalendarCollaborationEmailProductivityStorageVideo ConferencingArazzoWorkflows

Provider

google-workspace

Workflows

reset-user-password
Set a temporary password for a user and revoke their existing sessions.
Reads the user to confirm it exists, patches a new password with changePasswordAtNextLogin set, and signs the user out of all sessions to invalidate existing credentials.
3 steps inputs: accessToken, newPassword, userKey outputs: primaryEmail, userId
1
lookupUser
Confirm the user exists and capture its id before changing the password.
2
setPassword
Patch the user with the new temporary password and force a password change at the next login.
3
revokeSessions
Sign the user out of all active sessions so the previous password can no longer be used.

Source API Descriptions

Arazzo Workflow Specification

Raw ↑
arazzo: 1.0.1
info:
  title: Google Workspace Reset a User Password
  summary: Confirm a user, set a new password forcing change at next login, sign them out.
  description: >-
    A help-desk password reset flow. The workflow confirms the user exists,
    patches a new temporary password while forcing a password change at next
    login, and signs the user out of all sessions so the old credentials can no
    longer be used. Every step spells out its request inline so the flow can be
    read and executed without opening the underlying OpenAPI description.
  version: 1.0.0
  x-realizes-capability-ids:
  - BC-620.20
  x-capability-derivation:
    method: 'deterministic join: sourceDescriptions -> per-tag OpenAPI -> tag/capability edge. No classification at this step.'
    min_confidence: 0.7
    sources:
    - capability_id: BC-620.20
      capability_name: Identity & Access Management
      spec: google-workspace-users-api-openapi.yml
      confidence: 0.85
    model: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0
sourceDescriptions:
- name: usersApi
  url: ../openapi/google-workspace-users-api-openapi.yml
  type: openapi
workflows:
- workflowId: reset-user-password
  summary: Set a temporary password for a user and revoke their existing sessions.
  description: >-
    Reads the user to confirm it exists, patches a new password with
    changePasswordAtNextLogin set, and signs the user out of all sessions to
    invalidate existing credentials.
  inputs:
    type: object
    required:
    - accessToken
    - userKey
    - newPassword
    properties:
      accessToken:
        type: string
        description: OAuth 2.0 bearer access token with the admin.directory.user scope.
      userKey:
        type: string
        description: Primary email, alias, or unique id of the user to reset.
      newPassword:
        type: string
        description: The new temporary password, 8-100 ASCII characters.
  steps:
  - stepId: lookupUser
    description: >-
      Confirm the user exists and capture its id before changing the password.
    operationId: getUser
    parameters:
    - name: userKey
      in: path
      value: $inputs.userKey
    - name: Authorization
      in: header
      value: "Bearer $inputs.accessToken"
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      userId: $response.body#/id
      primaryEmail: $response.body#/primaryEmail
  - stepId: setPassword
    description: >-
      Patch the user with the new temporary password and force a password
      change at the next login.
    operationId: patchUser
    parameters:
    - name: userKey
      in: path
      value: $inputs.userKey
    - name: Authorization
      in: header
      value: "Bearer $inputs.accessToken"
    requestBody:
      contentType: application/json
      payload:
        password: $inputs.newPassword
        changePasswordAtNextLogin: true
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      userId: $response.body#/id
  - stepId: revokeSessions
    description: >-
      Sign the user out of all active sessions so the previous password can no
      longer be used.
    operationId: signOutUser
    parameters:
    - name: userKey
      in: path
      value: $inputs.userKey
    - name: Authorization
      in: header
      value: "Bearer $inputs.accessToken"
    successCriteria:
    - condition: $statusCode == 204
  outputs:
    userId: $steps.setPassword.outputs.userId
    primaryEmail: $steps.lookupUser.outputs.primaryEmail

Work with this as data

Every workflow here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for arazzo workflows

4 MCP tools reach this
  • find_arazzoBrowse and filter every workflow in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/google-workspace-reset-user-password-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.