ToastBit

Google Workspace admin setup

One-time setup, about 5 minutes. After it, a super admin can ask Claude to check which apps your team connected to Google Workspace.

What ToastBit asks Google for

Permission Google showsWhy ToastBit needs itWhat ToastBit does with it
See info about users on your domainTo know which accounts to checkReads the user list. Suspended users are skipped.
Manage data access permissions for users on your domainThis is the only Google permission that can list each user's connected appsReads the list only. Google's permission would allow removing an app's access, but the extension is built to send read requests to two list addresses and nothing else. It does not remove or change apps.
Google names the second permission "Manage" because Google offers no read-only version. ToastBit never uses the change or delete side of it. Sign-in is kept in memory only and never saved to disk. Asking Claude to sign out revokes it, and ToastBit tells you if Google did not confirm. Otherwise the access ends when Claude quits and expires at Google within an hour.

Step 1. Mark ToastBit as trusted

You need the Service Settings admin privilege (a super admin has it).

  1. Open the Google Admin console.
  2. Go to Menu → Security → Access and data control → API controls.
  3. Click Manage App Access, then Configure new app.
  4. Search for this client ID and select ToastBit AI Check:
    169582214226-lmtk199dnssb9an4fe8gh8cb27gt1bea.apps.googleusercontent.com
  5. Choose who it applies to. Your admin team's organizational unit is enough.
  6. Choose Trusted, click Continue, then Finish.

Until Google finishes reviewing ToastBit, Google may show an "unverified app" screen. Trusting the app in your console is Google's documented way for your own domain to use it.

Step 2. Run the check

  1. On the admin's computer, install the extension.
  2. In Claude Desktop, type: Check our Google Workspace for connected AI apps
  3. A Google sign-in page opens. Sign in as a super admin and allow both permissions.
  4. Return to Claude. It lists connected apps, what each can access, and which look like AI tools. People appear only as counts.
  5. To see who uses each app, ask Claude to save the report with user emails. That file stays on your computer. ToastBit never sends the emails to Claude.

Remove ToastBit's access at any time

What the Google check does not cover