CSE Integration Guideline
Google CSE Integration Guideline
Last updated
Google CSE Integration Guideline
Last updated
Audience: Workspace Admin / Oten KMS Admin Purpose: Connect your Google Workspace with Oten KMS and Oten IDP so your users can encrypt and access client-side encrypted files (Docs, Sheets, Slides, Drive, Gmail, Meet, Calendar) using your organization-owned encryption keys.
Oten KMS
External Key Service (KACLS) controlling Customer-Managed Keys (CMKs)
Oten IDP
Identity Provider verifying user identity and workspace membership
Google Workspace
Service requesting data-encryption keys (DEKs) from Oten KMS via Google CSE API
From the Oten KMS → CSE Configuration page, copy the following:
You will use these values in the Google Admin Console.
✅ You’re ready to use Google CSE with Oten KMS
Sign up for an Oten Business account.
Create or select an Oten Organization.
Ensure at least one workspace is created within the organization.
Log in to the Oten Portal using your Oten IDP account.
Navigate to Oten KMS Settings.
Activate Oten KMS for your organization or selected workspace.
Create initial encryption keys (default KEK).
Oten IDP URL
Client ID
Oten KMS KACLS Service URL
Log in to admin.google.com with a Google Workspace Admin account.
Ensure your Google Workspace is on an Enterprise plan that supports CSE.
Navigate to:
Configure:
Identity Provider (IDP) using the Oten IDP URL
Key Access Control List Service (KACLS) using the Oten KMS KACLS URL
Create or open a Google Docs/Sheets/Drive file.
Enable Client-Side Encryption.
Confirm that encryption keys are managed via Oten KMS.
View encrypted file activity in the Oten KMS Portal.