Manage Google Cloud Identity groups, devices, memberships, and inbound SSO profiles via CLI.
Works with
Covers six resource categories: customers, devices, groups, inbound OIDC/SAML SSO profiles, and SSO assignments
Device operations include creation, deletion, wiping, and user management; group operations support CRUD, search, lookup, and security settings
SSO profile management supports OIDC and SAML configurations with multi-party approval workflows for sensitive actions
Requires Google W
AI-first code editor with Composer
Before installing skills in Cursor, ensure your development environment meets these requirements:
node --versiongws-cloudidentityExecute the skills CLI command in your project's root directory to begin installation:
Fetches gws-cloudidentity from googleworkspace/cli and configures it for Cursor.
The CLI shows a list of agents. Use arrow keys and space to select Cursor:
Confirm successful installation by checking the skill directory location:
Restart Cursor to activate gws-cloudidentity. Access via /gws-cloudidentity in your agent's command palette.
We perform automated surface-level scans (Gen AI Scanner, Socket, Snyk) during installation. These checks detect common vulnerabilities but do not guarantee complete security. Always review skill source code and verify the publisher's reputation before production use.
Skills execute code in your environment. Always review source, verify the publisher, and test in isolation before production.
Submit your Claude Code skill and start earning
Automate repetitive workflows and reduce manual effort
Example
Generate reports, summarize documents, draft communications
Save 3-5 hours per week on routine tasks
Learn new skills, understand complex topics, get expert guidance
Example
Explain concepts, provide examples, suggest learning resources
Accelerate learning and skill development by 2x
Enhance output quality through reviews, suggestions, and refinements
Example
Review drafts, suggest improvements, catch errors
Improve work quality by 30-40% with less effort
0
total installs
0
this week
23.9K
GitHub stars
0
upvotes
Run in your terminal
0
installs
0
this week
23.9K
stars
PREREQUISITE: Read
../gws-shared/SKILL.mdfor auth, global flags, and security rules. If missing, rungws generate-skillsto create it.
gws cloudidentity <resource> <method> [flags]
userinvitations — Operations on the 'userinvitations' resourcecancelWipe — Cancels an unfinished device wipe. This operation can be used to cancel device wipe in the gap between the wipe operation returning success and the device being wiped. This operation is possible when the device is in a "pending wipe" state. The device enters the "pending wipe" state when a wipe device command is issued, but has not yet been sent to the device. The cancel wipe will fail if the wipe command has already been issued to the device.create — Creates a device. Only company-owned device may be created. Note: This method is available only to customers who have one of the following SKUs: Enterprise Standard, Enterprise Plus, Enterprise for Education, and Cloud Identity Premiumdelete — Deletes the specified device.get — Retrieves the specified device.list — Lists/Searches devices.wipe — Wipes all data on the specified device.deviceUsers — Operations on the 'deviceUsers' resourcecreate — Creates a Group.delete — Deletes a Group.get — Retrieves a Group.getSecuritySettings — Get Security Settingslist — Lists the Group resources under a customer or namespace.lookup — Looks up the resource name of a Group by its EntityKey.patch — Updates a Group.search — Searches for Group resources matching a specified query.updateSecuritySettings — Update Security Settingsmemberships — Operations on the 'memberships' resourcecreate — Creates an InboundOidcSsoProfile for a customer. When the target customer has enabled Multi-party approval for sensitive actions, the Operation in the response will have "done": false, it will not have a response, and the metadata will have "state": "awaiting-multi-party-approval".delete — Deletes an InboundOidcSsoProfile.get — Gets an InboundOidcSsoProfile.list — Lists InboundOidcSsoProfile objects for a Google enterprise customer.patch — Updates an InboundOidcSsoProfile. When the target customer has enabled Multi-party approval for sensitive actions, the Operation in the response will have "done": false, it will not have a response, and the metadata will have "state": "awaiting-multi-party-approval".create — Creates an InboundSamlSsoProfile for a customer. When the target customer has enabled Multi-party approval for sensitive actions, the Operation in the response will have "done": false, it will not have a response, and the metadata will have "state": "awaiting-multi-party-approval".delete — Deletes an InboundSamlSsoProfile.get — Gets an InboundSamlSsoProfile.list — Lists InboundSamlSsoProfiles for a customer.patch — Updates an InboundSamlSsoProfile. When the target customer has enabled Multi-party approval for sensitive actions, the Operation in the response will have "done": false, it will not have a response, and the metadata will have "state": "awaiting-multi-party-approval".idpCredentials — Operations on the 'idpCredentials' resourcecreate — Creates an InboundSsoAssignment for users and devices in a Customer under a given Group or OrgUnit.delete — Deletes an InboundSsoAssignment. To disable SSO, Create (or Update) an assignment that has sso_mode == SSO_OFF.get — Gets an InboundSsoAssignment.list — Lists the InboundSsoAssignments for a Customer.patch — Updates an InboundSsoAssignment. The body of this request is the inbound_sso_assignment field and the update_mask is relative to that. For example: a PATCH to /v1/inboundSsoAssignments/0abcdefg1234567&update_mask=rank with a body of { "rank": 1 } moves that (presumably group-targeted) SSO assignment to the highest priority and shifts any other group-targeted assignments down in priority.get — Get a policy.list — List policies.Before calling any API method, inspect it:
# Browse resources and methods
gws cloudidentity --help
# Inspect a method's required params, types, and defaults
gws schema cloudidentity.<resource>.<method>
Use gws schema output to build your --params and --json flags.
Prerequisites
Time Estimate
15-45 minutes depending on use case complexity
Steps
Common Pitfalls
✓ Do
✗ Don't
💡 Pro Tips
✓ Use when
Use when skill capabilities match your task, clear ROI on time saved, and you can validate outputs. Best for repetitive tasks, learning, and quality improvement.
✗ Avoid when
Avoid when task requires deep expertise you can't validate, involves sensitive decisions, or when learning process is more valuable than speed of completion.
googleworkspace/cli
googleworkspace/cli
davila7/claude-code-templates
wshobson/agents
jeffallan/claude-skills
dpearson2699/swift-ios-skills
gws-cloudidentity is among the better-maintained entries we tried; worth keeping pinned for repeat workflows.
We added gws-cloudidentity from the explainx registry; install was straightforward and the SKILL.md answered most questions upfront.
Useful defaults in gws-cloudidentity — fewer surprises than typical one-off scripts, and it plays nicely with `npx skills` flows.
gws-cloudidentity reduced setup friction for our internal harness; good balance of opinion and flexibility.
gws-cloudidentity is among the better-maintained entries we tried; worth keeping pinned for repeat workflows.
Keeps context tight: gws-cloudidentity is the kind of skill you can hand to a new teammate without a long onboarding doc.
Registry listing for gws-cloudidentity matched our evaluation — installs cleanly and behaves as described in the markdown.
gws-cloudidentity fits our agent workflows well — practical, well scoped, and easy to wire into existing repos.
Useful defaults in gws-cloudidentity — fewer surprises than typical one-off scripts, and it plays nicely with `npx skills` flows.
gws-cloudidentity has been reliable in day-to-day use. Documentation quality is above average for community skills.
showing 1-10 of 40