OAuth Integrations / Google

KMUC – Google Integration

KMUC is a business software platform with two Google OAuth clients. The general KMUC client supports business features such as Google sign-in and account identification. The separate KMUC Booking client allows authorized business administrators to connect Google Workspace services for booking workflows. Each connection is optional and is activated only after permission is granted on the Google OAuth consent screen.

Google services and OAuth clients

KMUC uses its Google OAuth client for general business features, including signing users in with Google, identifying the authenticated account, and associating that account with the appropriate KMUC user or organization. This client requests only basic identity permissions: OpenID, email address, and profile information.

KMUC Booking uses a separate Google OAuth client. Google Calendar provides the list of selectable calendars, checks availability, and synchronizes booking events. Gmail can send booking confirmations, reminders, or other workflow-related messages when this feature is enabled for the relevant booking workflow. Only authorized administrators can connect this client and explicitly grant its additional Google Workspace permissions.

How the integration works

For general KMUC business features, a user chooses Google sign-in, reviews the basic identity permissions, and signs in with the selected Google account. KMUC uses the returned identity information to authenticate the user and associate the sign-in with the correct KMUC account.

For KMUC Booking:

  1. An authorized administrator starts the Google connection from KMUC Booking.
  2. Google displays the requested permissions, which the administrator can approve.
  3. The administrator selects the calendar to be used for bookings.
  4. KMUC checks availability and synchronizes new, updated, or canceled appointments.

Access can be revoked at any time from the Google Account connections page . After revocation, KMUC can no longer access the authorized Google services.

Requested permissions
KMUC: openid, email, and profile
Sign users in, identify their Google account, and display their email address and basic profile information.
KMUC Booking: openid, email, and profile
Sign administrators in and associate the connected Google Workspace account with their KMUC Booking account.
KMUC Booking: calendar.calendarlist.readonly
Display available calendars so an administrator can select the booking calendar.
KMUC Booking: calendar.freebusy
Check free and busy periods without reading complete calendar contents.
KMUC Booking: calendar.events
Create, update, and delete booking events in the selected calendar.
KMUC Booking: gmail.send
Send emails initiated by the administrator or triggered by enabled booking workflows.
Data usage and protection

KMUC reads the Google account ID, email address, basic profile information, the list of available calendars, and free/busy information. To synchronize appointments, KMUC creates, updates, or deletes booking events containing the required appointment details in the selected calendar. When email sending is enabled, messages intended for delivery are transmitted through Gmail.

Google user data is processed solely to provide the KMUC features enabled by the administrator. Only authorized administrators can connect an account. KMUC does not sell Google user data, use it for advertising, or disclose it for independent advertising purposes. Access and refresh tokens are stored securely and used only for the authorized connection.