Integration · Google Workspace
The team vault that opens
with your Google identity
If your organisation runs Google Workspace, your team already has its Keyvaci sign-in. No new passwords to distribute, no user list to upload, and nothing to install in your domain.
What the integration does
Domain-verified, from the very first click
Only a real super administrator
Creating your organisation requires a super administrator of that Workspace domain, and we check it against Google's own directory rather than believing a claim in a token. Someone with a work email address cannot register your company's vault.
One domain, one organisation
Your domain maps to exactly one Keyvaci organisation, and colleagues on the same domain still need an invitation to join it. Nobody arrives inside your vaults just by holding an address that ends the right way.
Personal Gmail is refused
A sign-in without a Workspace domain is rejected at the door. Without a directory there is nothing to attach an organisation to, so those accounts take the email route instead, with identical encryption. The rule lives in one place, not scattered across the service.
SSO without weakening encryption
Google answers who you are. What you can decrypt still comes only from your master password, derived on your device. The two systems are separate by design, so adding SSO never dents the zero-knowledge property.
Your identity policy rides along
Whatever your Workspace enforces at sign-in applies to Keyvaci, because sign-in is your directory. Where the directory says nothing about a second factor, Keyvaci treats that as unproven and answers with its own step-up rather than assuming.
A stable identity, not an email address
Members are anchored to the permanent identifier Google issues, not to the address on it. Someone can be renamed or married or move team without becoming a stranger to their own vaults.
Setup, in full
Three steps, no ticket to IT
Sign in with Google
A super administrator of your Workspace domain clicks "Sign in with Google" and consents, exactly as with any Workspace app. Nothing is written to your directory.
Create the organisation
Keyvaci confirms the administrator role with Google, then your browser generates the organisation's signing and recovery keys locally, shows them once, and never sends them to us.
Invite by email
Members sign in with their existing Google account and are recognised automatically. Each sets a master password, gets countersigned by an admin, and starts receiving vaults.
Already using Keyvaci with email accounts? Nothing has to be migrated. Sign-in and cryptography are separate systems, so linking a Google identity leaves keys and vaults exactly where they are, with no re-encryption.
Workspace questions
Asked by every Workspace admin so far
Does this require changes to our Workspace?
No. Users consent at first sign-in as they would for any Workspace application, and nothing is written back to your directory. When an administrator creates the organisation we read enough to confirm they really are a super administrator of that domain, and nothing else.
Can someone register our company's vault without being an admin?
No. The founder check is done against Google's directory, not against a claim in the token, so an ordinary member cannot create an organisation for your domain. They can join yours, once invited.
What about contractors who are not in our Workspace?
They join by email with mandatory verification, and are countersigned by an administrator before they can receive any vault, exactly like directory members. The encryption is identical either way.
Can we use Google sign-in in the browser extension and the mobile apps?
Not yet. The extension and the mobile apps support Microsoft Entra ID and email accounts today, and Google is being brought to both next. In the meantime everyone in a Workspace organisation can use those clients through email sign-in, with the same encryption and the same audit trail. Where each client stands today.
Do we lose anything by starting on email accounts?
No security property, no. Client-side encryption, countersigned keys, admin recovery, rotation, and audit are identical. What you gain by moving to Google sign-in is one fewer password for people to manage, and a joiner-leaver process that follows the directory you already run.
Your domain is the hard part. It's done.
Everything else takes minutes. Fourteen days, every feature, no card.