Stop Google Cloud sign-ins expiring
When a Google Workspace ends VPS Snaps' Google Cloud sign-in every few hours, backups stop until someone signs in. How an admin exempts VPS Snaps, in two minutes.
Someone in your organization backs up servers on Google Cloud with VPS Snaps, and your Google Workspace keeps ending its Google Cloud sign-in. Each time, their scheduled backups stop until they sign in again. This guide is for the Workspace admin who can stop it.
What is happening
Google Workspace's session control for Google Cloud makes every app with Google Cloud access, VPS Snaps included, ask the person to sign in again after a set number of hours. Since June 2026 Google has also applied a 16-hour default to some Google Cloud organizations, and the Admin console does not show it. VPS Snaps cannot override either one. Only an admin of your organization can. Personal Gmail accounts are never affected.
Fix 1: in the Admin console
This works where your organization's session control is set in the Admin console, which is most of them.
- Go to admin.google.com → Security → Access and data control → API controls → Manage Third-Party App Access, and choose Configure new app.
- Search for VPS Snaps' OAuth client ID, 1077764012355-4um01ompfihmuntr34rig81u4jri7e9h.apps.googleusercontent.com, select it, and set its access to Trusted.
- Go to Security → Access and data control → Google Cloud session control. Tick Exempt Trusted apps, or choose Never require reauthentication, and Save.
Admin console changes can take a while to reach everyone. Once they have, the person using VPS Snaps signs in to Google Cloud once more, and that sign-in then stays.
Fix 2: if session control is not turned on there
If the Admin console shows no Google Cloud session control, yet sign-ins still end about every 16 hours, your organization is on Google's hidden default. It is changed with an Access Context Manager cloud binding that exempts VPS Snaps for a Google group. Run these with gcloud, as an admin who can manage your organization's access bindings.
# Your organization ID
gcloud organizations list
# The group whose members use VPS Snaps (an all-staff group works)
gcloud identity groups describe GROUP_EMAIL --format="value(name)"
# prints groups/GROUP_ID
# Save as vpssnaps-binding.yaml
scopedAccessSettings:
- scope:
clientScope:
restrictedClientApplication:
clientId: 1077764012355-4um01ompfihmuntr34rig81u4jri7e9h.apps.googleusercontent.com
activeSettings:
sessionSettings:
sessionLength: 0s
sessionReauthMethod: LOGIN
sessionLengthEnabled: false
# Then create the binding
gcloud access-context-manager cloud-bindings create \
--organization=ORG_ID \
--group-key=GROUP_ID \
--binding-file=vpssnaps-binding.yamlGoogle's guide to session controls
If that group already has a cloud binding, add this entry to it rather than creating a second one. Google's guide covers updating a binding.
What VPS Snaps can reach
VPS Snaps asks for Compute Engine access, and uses it in the project the person connected. It lists the instances there, takes and deletes machine images on their schedule, and, if they set it up, builds recovery servers and test-restore machines. It never sees anyone's password.