How-to

Google Calendar synchronisation

Last updated August 11, 2025 · Tushar Agarwal

On this page

HRStop lets you synchronize the employee leave calendar with Google Calendar. Follow the steps below to set up the required configurations:

  • Create a service account
  • Delegate domain-wide authority to the service account
  • Upload the JSON file
Create a service account

The Google OAuth system supports server-to-server interactions such as those between a web application and a Google service. For this scenario, you need a service account, which is an account that belongs to your application instead of to an individual end-user. Your application calls Google APIs on behalf of the service account, so users aren't directly involved.

  • A service account's credentials include a generated email address that is unique and at least one public/private key pair. If domain-wide delegation is enabled, then a client ID is also part of the service account's credentials.
  • Open the Service Account Page and select a project from the top bar.
  • Click "+Create Service Account" and enter the name and description for the service account. You can use the default service account ID or choose a different, unique one. When done, click the Create button.
  • Next, you get the option to update account permissions. The Service account permissions section is Optional. Skip it and click the Continue button.
  • A new page opens with the title "Grant users access to this service account". Scroll down to the Create key section and click Create key.
  • In the side panel, select the format for your key: JSON (recommended).
  • Click the Create button. Your new public/private key pair is generated and downloaded to your machine; it serves as the only copy of this key.
Grant G Suite domain-wide authority to the service account
  • Locate the newly created service account in the table. Under the Actions section, click the Edit option.
  • In the service account details, click Show domain-wide delegation and ensure that the Enable G Suite Domain-wide Delegation check box is selected.
  • If you haven't yet configured your app's OAuth consent screen, you must do so before you can enable domain-wide delegation. Follow the on-screen instructions to configure the OAuth consent screen, then repeat the above steps and select the check box again.
  • Click the Save button to update the service account and return to the table of service accounts. A new column, Domain-wide delegation, appears. Click View Client ID to obtain the client ID and make a note of it.
Delegate domain-wide authority to the service account

Now, as an administrator of the G Suite domain, complete the following steps:

  • Go to your G Suite domain’s Admin console.
  • Select Security from the list of controls. If you don't see Security listed, select More controls from the gray bar at the bottom of the page, then select Security from the list of controls. If you can't see the controls, make sure you're signed in as an administrator for the domain.
  • Select Show more and then Advanced settings from the list of options.
  • Select Manage API client access in the Authentication section.
  • In the Client Name field, enter the service account's Client ID. You can find your service account's client ID in the Service accounts page.
  • In the One or More API Scopes field, enter the list of scopes that your application should be granted access to. For example, if your application needs domain-wide access to the Google Drive API and the Google Calendar API, enter https://www.googleapis.com/aut....
  • Click Authorize.
Note
Upload the JSON file

Upload the file you get while "Creating the Service account" to the link shared by the HRStop team.

Output

When an employee applies for leave and the reporting manager approves it, the Approved leave appears on the Google Calendar of the employee and their direct reporting manager.