Keyvaci

Integration · Google Workspace

The team vault that opens
with your Google identity

If your organisation runs Google Workspace, your team already has its Keyvaci sign-in. No new passwords to distribute, no user list to upload, and nothing to install in your domain.

Google Workspace SSO · available now in the web app Extension and phone · Microsoft and email today

What the integration does

Domain-verified, from the very first click

Only a real super administrator

Creating your organisation requires a super administrator of that Workspace domain, and we check it against Google's own directory rather than believing a claim in a token. Someone with a work email address cannot register your company's vault.

One domain, one organisation

Your domain maps to exactly one Keyvaci organisation, and colleagues on the same domain still need an invitation to join it. Nobody arrives inside your vaults just by holding an address that ends the right way.

Personal Gmail is refused

A sign-in without a Workspace domain is rejected at the door. Without a directory there is nothing to attach an organisation to, so those accounts take the email route instead, with identical encryption. The rule lives in one place, not scattered across the service.

SSO without weakening encryption

Google answers who you are. What you can decrypt still comes only from your master password, derived on your device. The two systems are separate by design, so adding SSO never dents the zero-knowledge property.

Your identity policy rides along

Whatever your Workspace enforces at sign-in applies to Keyvaci, because sign-in is your directory. Where the directory says nothing about a second factor, Keyvaci treats that as unproven and answers with its own step-up rather than assuming.

A stable identity, not an email address

Members are anchored to the permanent identifier Google issues, not to the address on it. Someone can be renamed or married or move team without becoming a stranger to their own vaults.

Setup, in full

Three steps, no ticket to IT

Sign in with Google

A super administrator of your Workspace domain clicks "Sign in with Google" and consents, exactly as with any Workspace app. Nothing is written to your directory.

Create the organisation

Keyvaci confirms the administrator role with Google, then your browser generates the organisation's signing and recovery keys locally, shows them once, and never sends them to us.

Invite by email

Members sign in with their existing Google account and are recognised automatically. Each sets a master password, gets countersigned by an admin, and starts receiving vaults.

Already using Keyvaci with email accounts? Nothing has to be migrated. Sign-in and cryptography are separate systems, so linking a Google identity leaves keys and vaults exactly where they are, with no re-encryption.

Workspace questions

Asked by every Workspace admin so far

Does this require changes to our Workspace?

No. Users consent at first sign-in as they would for any Workspace application, and nothing is written back to your directory. When an administrator creates the organisation we read enough to confirm they really are a super administrator of that domain, and nothing else.

Can someone register our company's vault without being an admin?

No. The founder check is done against Google's directory, not against a claim in the token, so an ordinary member cannot create an organisation for your domain. They can join yours, once invited.

What about contractors who are not in our Workspace?

They join by email with mandatory verification, and are countersigned by an administrator before they can receive any vault, exactly like directory members. The encryption is identical either way.

Can we use Google sign-in in the browser extension and the mobile apps?

Not yet. The extension and the mobile apps support Microsoft Entra ID and email accounts today, and Google is being brought to both next. In the meantime everyone in a Workspace organisation can use those clients through email sign-in, with the same encryption and the same audit trail. Where each client stands today.

Do we lose anything by starting on email accounts?

No security property, no. Client-side encryption, countersigned keys, admin recovery, rotation, and audit are identical. What you gain by moving to Google sign-in is one fewer password for people to manage, and a joiner-leaver process that follows the directory you already run.

Your domain is the hard part. It's done.

Everything else takes minutes. Fourteen days, every feature, no card.