Gws Cloudidentity
Google Cloud Identity: Manage identity groups and memberships.
$ npx claude-code-templates@latest --command="google-workspace/gws-cloudidentity" --yesRequires Claude Code. The command adds this command to your project's .claudedirectory — nothing runs on ToolZip's servers.
What's inside this command
Component source
Google Workspace Cloudidentity
Execute Google Workspace Cloudidentity operations: $ARGUMENTS
Prerequisites
- Google Workspace CLI (
gws) must be installed - Authentication configured: Run
gws auth statusto verify - Review
gws cloudidentity --helpfor all available commands
Available Resources and Methods
cloudidentity (v1)
PREREQUISITE: Read../gws-shared/SKILL.mdfor auth, global flags, and security rules. If missing, rungws generate-skillsto create it.
gws cloudidentity <resource> <method> [flags]
API Resources
customers
- userinvitations — Operations on the 'userinvitations' resource
devices
- cancelWipe — Cancels an unfinished device wipe. This operation can be used to cancel device wipe in the gap between the wipe operation returning success and the device being wiped. This operation is possible when the device is in a "pending wipe" state. The device enters the "pending wipe" state when a wipe device command is issued, but has not yet been sent to the device. The cancel wipe will fail if the wipe command has already been issued to the device.
- create — Creates a device. Only company-owned device may be created. Note: This method is available only to customers who have one of the following SKUs: Enterprise Standard, Enterprise Plus, Enterprise for Education, and Cloud Identity Premium
- delete — Deletes the specified device.
- get — Retrieves the specified device.
- list — Lists/Searches devices.
- wipe — Wipes all data on the specified device.
- deviceUsers — Operations on the 'deviceUsers' resource
groups
- create — Creates a Group.
- delete — Deletes a Group.
- get — Retrieves a Group.
- getSecuritySettings — Get Security Settings
- list — Lists the Group resources under a customer or namespace.
- lookup — Looks up the resource name of a Group by its EntityKey.
- patch — Updates a Group.
- search — Searches for Group resources matching a specified query.
- updateSecuritySettings — Update Security Settings
- memberships — Operations on the 'memberships' resource
inboundOidcSsoProfiles
- create — Creates an InboundOidcSsoProfile for a customer. When the target customer has enabled Multi-party approval for sensitive actions, the Operation in the response will have "done": false, it will not have a response, and the metadata will have "state": "awaiting-multi-party-approval".
- delete — Deletes an InboundOidcSsoProfile.
- get — Gets an InboundOidcSsoProfile.
- list — Lists InboundOidcSsoProfile objects for a Google enterprise customer.
- patch — Updates an InboundOidcSsoProfile. When the target customer has enabled Multi-party approval for sensitive actions, the Operation in the response will have "done": false, it will not have a response, and the metadata will have "state": "awaiting-multi-party-approval".
inboundSamlSsoProfiles
- create — Creates an InboundSamlSsoProfile for a customer. When the target customer has enabled Multi-party approval for sensitive actions, the Operation in the response will have "done": false, it will not have a response, and the metadata will have "state": "awaiting-multi-party-approval".
- delete — Deletes an InboundSamlSsoProfile.
- get — Gets an InboundSamlSsoProfile.
- list — Lists InboundSamlSsoProfiles for a customer.
- patch — Updates an InboundSamlSsoProfile. When the target customer has enabled Multi-party approval for sensitive actions, the Operation in the response will have "done": false, it will not have a response, and the metadata will have "state": "awaiting-multi-party-approval".
- idpCredentials — Operations on the 'idpCredentials' resource
inboundSsoAssignments
- create — Creates an InboundSsoAssignment for users and devices in a Customer under a given Group or OrgUnit.
- delete — Deletes an InboundSsoAssignment. To disable SSO, Create (or Update) an assignment that has sso_mode == SSO_OFF.
- get — Gets an InboundSsoAssignment.
- list — Lists the InboundSsoAssignments for a Customer.
- patch — Updates an InboundSsoAssignment. The body of this request is the inbound_sso_assignment field and the update_mask is relative to that. For example: a PATCH to /v1/inboundSsoAssignments/0abcdefg1234567&update_mask=rank with a body of { "rank": 1 } moves that (presumably group-targeted) SSO assignment to the highest priority and shifts any other group-targeted assignments down in priority.
policies
- get — Get a policy.
- list — List policies.
Discovering Commands
Before calling any API method, inspect it:
# Browse resources and methods
gws cloudidentity --help
# Inspect a method's required params, types, and defaults
gws schema cloudidentity.<resource>.<method>
Use gws schema output to build your --params and --json flags.
Usage
# List available resources and methods
gws cloudidentity --help
# Inspect method schema before calling
gws schema cloudidentity.<resource>.<method>
# Execute command with arguments
gws cloudidentity $ARGUMENTS
Task
Execute the requested Cloudidentity operation: $ARGUMENTS
- Verify Prerequisites
gws is installed: gws --version
- Verify authentication: gws auth status
- Review available commands: gws cloudidentity --help
- Inspect Method Schema
- Use gws schema to understand required fields
- Review parameter types and constraints
- Execute Operation
- Use --params for query/path parameters
- Use --json for request body
- Handle pagination with --max-results or --page-token
- Error Handling
- Review API quotas and rate limits
- Handle authentication issues
- Retry transient failures
License: Apache License 2.0 Source: Google Workspace CLI Original Skill:
gws-cloudidentityRelated Claude Code Commands
Gws Events Renew
Google Workspace Events: Renew/reactivate Workspace Events subscriptions.
Gws Sheets Read
Google Sheets: Read values from a spreadsheet.
Gws Calendar Insert
Google Calendar: Create a new event.
Gws Gmail Watch
Gmail: Watch for new emails and stream them as NDJSON.
Gws Sheets Append
Google Sheets: Append a row to a spreadsheet.
Gws Alertcenter
Google Workspace Alert Center: Manage Workspace security alerts.
Catalog data and component content are sourced from the open-source davila7/claude-code-templates project (MIT license). ToolZip curates the listing and writes original descriptions; every component links back to its original source. Claude Code is a product of Anthropic. ToolZip is an independent catalog and is not affiliated with or endorsed by Anthropic.