{"_id":"@aiquants/auth-google-directory","_rev":"5-c74b120772f5592bed2ba2f3e2c25018","name":"@aiquants/auth-google-directory","dist-tags":{"latest":"0.4.2"},"versions":{"0.2.0":{"name":"@aiquants/auth-google-directory","version":"0.2.0","keywords":["auth","google","workspace","directory","cloud-identity","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-google-directory@0.2.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"887f2fb47989e0536cb2893033e654dd46691b0e","tarball":"https://registry.npmjs.org/@aiquants/auth-google-directory/-/auth-google-directory-0.2.0.tgz","fileCount":9,"integrity":"sha512-cyfND4S7KFOk8PLdZ2IHhsJHky0nkP7vCTYJLwQiwg0vkiz11m+Tf4HHe5MrqPZWxyqIGpGnCVhkRwvXJPxFcg==","signatures":[{"sig":"MEYCIQChu9yN9w/u7tF3hJr7ELhCYfQXnSA74wjI6x0JCL3K+QIhAMkZNf+xi4FDtQ9qBvJyCUXivK2HZuShWPtQ4DpwwJWO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":145966},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Google Workspace implementation of the @aiquants/auth-directory-core DirectoryProvider port: Admin SDK Directory for direct membership, Cloud Identity for nested membership, and a domain-wide delegation token provider. Read-only by construction — the inje","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@types/node":"^25.9.1","google-auth-library":"^10.7.0","@aiquants/auth-directory-core":"0.1.0"},"peerDependencies":{"google-auth-library":">=9","@aiquants/auth-directory-core":"^0.1.0"},"peerDependenciesMeta":{"google-auth-library":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-google-directory_0.2.0_1788959739385_0.8859302460874838","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@aiquants/auth-google-directory","version":"0.3.0","keywords":["auth","google","workspace","directory","cloud-identity","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-google-directory@0.3.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"6e46621f64ca470019651558e439235e77324232","tarball":"https://registry.npmjs.org/@aiquants/auth-google-directory/-/auth-google-directory-0.3.0.tgz","fileCount":9,"integrity":"sha512-zAe82Tuku4l0c5e0R6/oVJzZz5m1pZPhdWnNhy2FPd32S5XjNvNlkcYdU93vimPFI2kIPPi6LkwLtljCm5r0+Q==","signatures":[{"sig":"MEQCIERquP6oikBCVDIA5+EEqtOvoDvLYCYgE2dJhJtjkUYEAiAhMwQhbS0teKHEj/rfhgSJ9rI45Ggu7TmkxETigfaOeA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":173089},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Google Workspace implementation of the @aiquants/auth-directory-core DirectoryProvider port: Admin SDK Directory for direct membership, Cloud Identity for nested membership, and a domain-wide delegation token provider. Read-only by construction — the inje","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@types/node":"^25.9.1","google-auth-library":"^10.7.0","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"google-auth-library":">=9","@aiquants/auth-directory-core":"^0.2.0"},"peerDependenciesMeta":{"google-auth-library":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-google-directory_0.3.0_1789006189308_0.9034513855988526","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@aiquants/auth-google-directory","version":"0.4.0","keywords":["auth","google","workspace","directory","cloud-identity","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-google-directory@0.4.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"440463109645aee580519c5caeaf114a7c0ef7ef","tarball":"https://registry.npmjs.org/@aiquants/auth-google-directory/-/auth-google-directory-0.4.0.tgz","fileCount":9,"integrity":"sha512-LPMSvBQFtpU5eCx9V5qs6S7o3DYbM9/yYhn9FAS6gEX7ZBnDfSRH7+0dYTBFjqfDPvJ7EqCw+u5ya6v0nC6aGw==","signatures":[{"sig":"MEYCIQCnC/jyCxMjiUBLnElrP9t5mc/lBD1dBvggMI3lK+K4pAIhAKHVeAwiJ/+VMsh1UnWcSyMz9lYwDLBR1WBOjC3jPkIf","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":191486},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Google Workspace implementation of the @aiquants/auth-directory-core DirectoryProvider port: Admin SDK Directory for direct membership, Cloud Identity for nested membership, and a domain-wide delegation token provider. Read-only by construction — the inje","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@types/node":"^25.9.1","@aiquants/auth-core":"0.6.0","google-auth-library":"^10.7.0","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"@aiquants/auth-core":"^0.6.0","google-auth-library":">=9","@aiquants/auth-directory-core":"^0.2.0"},"peerDependenciesMeta":{"google-auth-library":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-google-directory_0.4.0_1789030472399_0.3638903321276743","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@aiquants/auth-google-directory","version":"0.4.1","keywords":["auth","google","workspace","directory","cloud-identity","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-google-directory@0.4.1","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"1a4da251a92f3d592db4dc7c43da962c2700e725","tarball":"https://registry.npmjs.org/@aiquants/auth-google-directory/-/auth-google-directory-0.4.1.tgz","fileCount":9,"integrity":"sha512-F6VZWENJqQXKc149aS/y6KgNlzPeeCAFh/66+jZKBBFCgn0ftCmb0uxz5iy++W1djBnAljDDbx+eSm/Q5y3A7A==","signatures":[{"sig":"MEUCIHQNH3ByGK4AAE2PrNmvHKQ1RagRzEC+KkryamaGCP6NAiEA60RNDNKQe/ID0YpjCJeoNBOlTTxtyfArFey/ogb1uqc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":192866},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Google Workspace implementation of the @aiquants/auth-directory-core DirectoryProvider port: Admin SDK Directory for direct membership, Cloud Identity for nested membership, and a domain-wide delegation token provider. Read-only by construction — the inje","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@types/node":"^25.9.1","@aiquants/auth-core":"0.6.0","google-auth-library":"^10.7.0","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"@aiquants/auth-core":"^0.6.0","google-auth-library":">=9","@aiquants/auth-directory-core":"^0.2.0"},"peerDependenciesMeta":{"google-auth-library":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-google-directory_0.4.1_1789174970804_0.2505610104926288","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"_id":"@aiquants/auth-google-directory@0.4.2","dist":{"shasum":"6a23981e461b659a39f9377e97ca65817fb6c140","tarball":"https://registry.npmjs.org/@aiquants/auth-google-directory/-/auth-google-directory-0.4.2.tgz","fileCount":7,"integrity":"sha512-2iFysB0WXd6IEFEgEkeEZlWPODfQAmZMa2nIP9Zo9mH6GVmUiEj9wJfr9qWKamw6NdwpGp/+L1EswkGQDtrJPA==","signatures":[{"sig":"MEUCIQC725oYk4RSE+f8E4EWYH5wJngw/l9RY2qrmetggtNIGgIgGD7+eTuXAnZGpCqx9Qw4mKX4ppFgmATeiVvDhPSWhNs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEE/6SUJZztMNluyGRkdntYX0dehSn/KPTfSCfYUA+TDAiEAumz2TAroAvsiK+QH1T3Pd/9TDbgThI/HqGAqYg+ME2c="}],"unpackedSize":39963},"main":"dist/index.js","name":"@aiquants/auth-google-directory","types":"dist/index.d.ts","author":{"url":"https://x.com/fehdek","name":"fehde-k"},"module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"license":"MIT","scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup && node ../../.config/scripts/strip-dts-comments.mjs dist","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"version":"0.4.2","_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"keywords":["auth","google","workspace","directory","cloud-identity","typescript"],"description":"Google Workspace implementation of the @aiquants/auth-directory-core DirectoryProvider port: Admin SDK Directory for direct membership, Cloud Identity for nested membership, and a domain-wide delegation token provider. Read-only by construction — the inje","directories":{},"maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"sideEffects":false,"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@types/node":"^25.9.1","@aiquants/auth-core":"0.6.1","google-auth-library":"^10.7.0","@aiquants/auth-directory-core":"0.2.1"},"peerDependencies":{"@aiquants/auth-core":"^0.6.1","google-auth-library":">=9","@aiquants/auth-directory-core":"^0.2.1"},"peerDependenciesMeta":{"google-auth-library":{"optional":true}},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth-google-directory_0.4.2_1789699480573_0.1398452066188347"}}},"time":{"created":"2026-09-09T13:15:39.172Z","modified":"2026-09-18T02:44:40.832Z","0.2.0":"2026-09-09T13:15:39.502Z","0.3.0":"2026-09-10T02:09:49.483Z","0.4.0":"2026-09-10T08:54:32.524Z","0.4.1":"2026-09-12T01:02:51.012Z","0.4.2":"2026-09-18T02:44:40.659Z"},"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","keywords":["auth","google","workspace","directory","cloud-identity","typescript"],"description":"Google Workspace implementation of the @aiquants/auth-directory-core DirectoryProvider port: Admin SDK Directory for direct membership, Cloud Identity for nested membership, and a domain-wide delegation token provider. Read-only by construction — the inje","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"readme":"# @aiquants/auth-google-directory\n\nGoogle Workspace implementation of the `DirectoryProvider` port from\n[`@aiquants/auth-directory-core`](../auth-directory-core). It is the only **directory** adapter that\nknows about Google: the sync core, its drizzle adapter and the identity DTOs stay provider-agnostic,\nand a deployment without Google Workspace simply never wires this package in. (Google appears\nelsewhere in the repository — `@aiquants/auth-react-router` carries the OAuth sign-in strategy — but\nnothing outside this package knows how to read the *directory*.)\n\n## Read-only by construction\n\nThe provider exposes exactly two methods, both reads. `FetchLike` accepts only headers and an abort\nsignal — there is no slot for a method or a body — so \"GET only\" is enforced by the type rather than\nby convention, in this package *and* in whatever fetch a host injects.\n\n`createDomainWideDelegationTokenProvider` refuses any scope that does not end in `.readonly`,\nincluding the `additionalScopes` a caller supplies. That guard covers the scope set this package\nbuilds; the **actual** boundary is `createClient`, which a caller could use to mint a JWT with any\nscopes it likes. Read-only therefore rests on two things: this guard, and the narrowness of the\nadmin role granted to the impersonated user.\n\n## Never report \"0 members\" for \"could not read\"\n\nThe caller treats the returned list as the whole upstream truth and deletes everything missing from\nit. Reporting a failure as an empty array therefore becomes a mass revocation. Accordingly:\n\n| Situation | Behaviour |\n| --- | --- |\n| A page fails mid-listing | Throw; the pages already collected are discarded |\n| Paging stops advancing (the same `pageToken` returns) | Throw rather than loop |\n| More than 200 pages | Throw rather than report a truncated list |\n| A `200` body is not this endpoint's document | Throw rather than read it as an empty result |\n| A member row carries no address, or a type/status this adapter cannot classify | Throw rather than silently drop a person |\n| An attempt exceeds `timeoutMs` | Abort it; a hung request would otherwise stall the whole run |\n| No access token | Throw rather than send an unauthenticated request |\n| `403` / `404` on a member listing | Throw; only `getGroup` maps `404` to `null` |\n\n`getGroup` returns `null` for `404` **only**. Folding any other failure into `null` would turn\n\"cannot reach the directory\" into \"the group was deleted\", and the caller deactivates the group on\nthat answer.\n\n### Which failures are worth waiting on\n\nRetries cover `429`, `408`, `5xx` — **and `403` when the body names a rate-limit reason**. Google's\nDirectory API documents three rate-limit errors and two of them are `403`\n(`userRateLimitExceeded`, `quotaExceeded`), so treating every `403` as permanent makes a run collapse\nthe moment it touches a quota, and abandons a failure that waiting would have fixed. A `403` with any\nother reason — and every `404` — is a configuration mistake that waiting cannot fix, and every second\nspent waiting is a second of staleness.\n\nBackoff is exponential with jitter. Without jitter, calls rejected together retry together and\nre-enter the same rate limit in the same shape.\n\nAn `as T` cast is not validation: a corporate proxy that answers a policy block with HTTP 200 and a\nJSON body parses cleanly, carries no `members`, and would otherwise read as an empty group. Every\nresponse is checked against the document that endpoint actually returns — Admin SDK bodies must\ncarry the right `kind`, Cloud Identity bodies must carry no key that endpoint never returns.\n\n## Membership modes\n\n| Mode | Endpoints | Scopes |\n| --- | --- | --- |\n| `direct` | Admin SDK `groups.get` + `members.list` | `admin.directory.group.readonly`, `admin.directory.group.member.readonly` |\n| `transitive` | Admin SDK `groups.get`, Cloud Identity `groups:lookup` + `memberships:searchTransitiveMemberships` | the two above, plus `cloud-identity.groups.readonly` |\n\n`getGroup` runs for every link in both modes (it is how a vanished group is detected), so the group\nscope is always required — provisioning only the member scope yields `403` on the first call.\n\nIn `direct` mode, rows of type `GROUP` are dropped rather than expanded — that is what \"direct\"\npromises — and `EXTERNAL` members are kept, because an external collaborator is a real person whose\nmembership would otherwise be deleted on the next sync. Suspended and archived accounts are dropped:\nmembership they cannot use is not membership. A `type` or `status` this adapter cannot classify\n(`CUSTOMER`, for instance, which means \"the whole domain\") is an **error**, not a silent drop — a\ngroup that reports zero members produces a plan that removes everyone.\n\nIn `transitive` mode, nested groups appear as members in their own right and are dropped, and\nexternal-identity keys (which carry a `namespace` and whose id is not an address) are refused.\nCloud Identity does **not** expose member status, so suspended accounts cannot be filtered there; a\nsuspended Google account cannot complete sign-in, so the ledger entry grants nothing, but the\nasymmetry with `direct` mode is real and is recorded here rather than papered over. Transitive rows\nalso carry no upstream user id, so matching for those groups falls back to the address — the\nanti-address-reuse precedence documented on the port degrades to address-only.\n\n`searchTransitiveMemberships` is available only to Google Workspace Enterprise Standard / Plus /\nEducation and Cloud Identity Premium accounts; other editions receive `403 PERMISSION_DENIED`.\n\nCloud Identity addresses a group by resource name, which is not interchangeable with the Admin SDK\nnumeric id, so `transitive` looks the group up by address. The address comes from the\n`DirectoryGroup` the caller already fetched — the port takes the group, not an id, so no second\n`groups.get` is issued and no window opens between the two reads. The resource name is resolved per\ncall rather than cached, because a cached name survives an upstream re-addressing and keeps pointing\nat the old group.\n\n`maxPages` (default 200) bounds paging and therefore the largest group this adapter will report:\n200 × `pageSize` 200 = 40,000 members. Exceeding it throws rather than truncating, and a deployment\nwith larger groups must raise it deliberately.\n\n## Domain-wide delegation\n\n```ts\nconst getAccessToken = createDomainWideDelegationTokenProvider({\n    createClient: ({ subject, scopes }) => new JWT({ keyFile, subject, scopes }),\n    subject: \"directory-reader@example.com\",\n    includeNestedScope: false,\n})\n```\n\n> ⚠️ **Never impersonate a super administrator.** Domain-wide delegation acts *as* the named user, so\n> impersonating a super admin makes the service-account key a super-admin key. Create a dedicated\n> user, give it a custom admin role holding only `Groups > Read`, and name that user.\n\n`google-auth-library` is an **optional** peer: it is needed only for this helper. The provider itself\ntakes a `getAccessToken` function and depends on no Google SDK, which is also why it is fully\ntestable without a network or a credential.\n\n## Install\n\n```bash\npnpm add @aiquants/auth-google-directory @aiquants/auth-directory-core\npnpm add google-auth-library   # only if you construct the JWT for the delegation helper\n```\n\nThis package imports no Google SDK. `google-auth-library` is declared as an optional peer only\nbecause the delegation helper's example constructs a `JWT`; the construction happens in the\nconsumer's code, not here.\n","readmeFilename":""}