Google Workspace sync shows “Invalid input” after uploading new service account JSONSolved

Participant
Discussion
22 hours ago Sep 30, 2026

Our Google Workspace directory sync in Hexnode stopped working after running fine for a long time. I created a new service account under the same Google Cloud project, generated a new JSON key, and uploaded it in the Google Workspace sync configuration. The required APIs, including Admin SDK API, appear to be enabled and I can see API traffic in Google Cloud.

However, when I try to save the updated configuration in Hexnode, it just returns an “Invalid input” error. Domain-wide delegation is enabled and the OAuth client ID is added in Google Admin Console. What else should I check?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
21 hours ago Sep 30, 2026
Marked SolutionPending Review

Hi @wyatt_simmons ,

Welcome to the Hexnode Community.

For a Google Workspace sync configuration that fails with “Invalid input” after replacing the service account JSON, verify these three areas together:

1. OAuth scopes in Google Admin Console

  • Go to Google Admin console > Security > Access and data control > API controls > Manage Domain Wide Delegation.
  • Open the client ID associated with the new service account.
  • Make sure only the required Hexnode Google Workspace scopes are configured for directory access, specifically the scopes for users, groups, and domains, as listed in the Hexnode Google Workspace integration documentation.
  • Remove any unrelated or invalid scope, such as an old or incorrect read-only app scope that does not belong to the Google Workspace directory sync configuration.

2. Admin email in the Hexnode Google Workspace integration

  • The admin email field must contain a valid Google Workspace domain administrator account.
  • Do not enter the service account email or a standard user email in this field.
  • The service account provides the delegated access mechanism, but Google Workspace still requires an admin account to authorize domain-level access to users and groups.

3. Service account JSON key

  • Upload the current JSON key generated for the service account that matches the client ID configured for domain-wide delegation.
  • If the previous credential is stale or replaced, save the configuration again using the latest JSON key.

After correcting the scopes and admin email, save the configuration and re-initiate the directory sync. The user and group data should then start syncing again.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
19 hours ago Sep 30, 2026
Marked SolutionPending Review

Is the admin email always required? I was hoping to keep this tied only to a limited service account instead of a personal global admin account.

Marked SolutionPending Review
Hexnode Expert
18 hours ago Sep 30, 2026
Marked SolutionPending Review

Yes @grace_t , the admin email is required for this integration. Google Workspace domain-wide delegation uses the service account to delegate access, but the request must be authorized against a domain administrator account to read directory-level objects such as users, groups, and domains.

The service account access remains limited to the OAuth scopes configured in Google Admin Console. Adding the admin email does not grant Hexnode unrestricted access beyond those configured scopes. However, if the admin account used in the configuration is removed or loses the required administrator privileges, the sync may fail again. In that case, update the integration with another valid domain admin email, confirm the required scopes, upload the valid JSON key if needed, and run the sync again.

Regards,
Isabel Lora
Hexnode UEM

Save