Enabling the Verified Access API on the Google Developer's Site

Verified access is required for the non-interactive authentication of Chromebook devices, but is an optional step if you are using a Chromebook device configuration within an enrollment workflow to onboard Chromebook devices.

For this step, you need to have a Google developer's account and Google administrator account.

Follow these steps to enable the verified access API:

Note: You can also refer to Google developer's documentation for more information.

  1. Log in to the Google developer's console.
  2. Go to APIs & Services > Library.

    APIs & Services portion of Google Developer's Console

  3. From the APIs & Services > Library area of the UI, search on "Chrome Verified Access API."
  4. When the API appears, click on the name of the API, then click the Enable button.
  5. Go to APIs & Services > Credentials.
  6. At the top of the ensuing screen (see below), click Create Credentials > API key.

    Google Dev Console: APIs & Services > Credentials > Create Credentials

  7. You are presented with a screen that shows the newly created API key. The value "GoogleAPIKey" in the screen below will be replaced with the actual key.

    API Key Created

    Note: You will need the API key during Chromebook configuration in the Cloudpath UI.
  8. Click RESTRICT KEY.
  9. On the ensuing screen, scroll to the bottom and do the following:
    1. Select the "Restrict key" radio button.
    2. From the drop-down list, select "Chrome Verified Access API."
    3. Click Save.

    Setting API Restrictions

  10. Check that the main Credentials Screen - with the API key and the restrictions you set - is now displayed:

    Main Credentials Screen: API Key and Restrictions

  11. Create a service account by performing the following steps:
    1. Click "Manage service accounts" in the main Credentials screen.
    2. In the ensuing screen, click + CREATE SERVICE ACCOUNT.
    3. In the Create Service Account screen, enter the credentials, then click Create.

      Creating the Service Account

    4. After you have created the service accound, click the DONE button.
    5. You can now go back to the main Credentials screen (APIs & Services > Credentials) to confirm that the service account has been added, such as in the example screen below.

      Credentials Screen After Service Account Has Been Created

  12. Create a JSON key for the service account by following these steps:
    1. Click on the service account email link (shown under "Service Accounts" in the preceding screen).
    2. In the ensuing screen, click KEYS near the top of the screen, then click the ADD KEY dropdown, then select "Create new key".

      Creating a New JSON Key for the Service Account

    3. On the popup window (below), with JSON selected, click Create.

      JSON Popup Window to Create JSON Key

    4. The private key is then created and saved. Be sure to take note where the private key gets saved on your computer because you will need this key in the Cloudpath UI.

      Private JSON Key Created and Saved

  13. Now, log in to the Google admin console to perform steps related to user and browser or device settings:
    1. Go to Devices > Chrome > Settings.
    2. If performing a user enrollment, select the tab "USER & BROWSER SETTINGS"; if performing a device enrollment, select the tab "DEVICE SETTINGS".
    3. Set your options as desired.
    4. Search for "Verified Mode" in the scroll list.
    5. For the Verified Mode portion:
      • Select the desired "Verified Mode boot check" type.
      • For the "Services with full access" field, enter the service account email address that you created from the Google developer's console. (Note: If you selected the "USERS & BROWSER SETTINGS" tab, this field is called "Service accounts which are allowed to receive user data.")

      Verified Mode Settings on the Google Admin Console

    6. Save your settings.