Google Vault · Authentication Profile
Google Vault Authentication
Authentication
Every Vault API method requires an OAuth 2.0 access token; there is no API-key or unauthenticated path. Vault is an admin surface, so the token must belong to a Google Workspace user who holds Vault privileges (or to a service account with domain-wide delegation impersonating one). The authorization server is accounts.google.com, whose OIDC and RFC 8414 metadata are saved verbatim under well-known/.
Google Vault secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).
eDiscoveryLegal HoldInformation GovernanceComplianceArchivingRetentionGoogle WorkspaceAudit
Methods: oauth2
Schemes: 1
OAuth flows: authorizationCode
API key in:
Security Schemes
googleOAuth oauth2
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.