How Do I Replace the Service Account Credential File?

In the JitBackup management console, select the Workspace domain, open Settings > Backup settings > Backup Options, and scroll to Replace the Service Account. The replacement wizard keeps your existing domain, administrator, and backup data.

Before You Start

Sign in to JitBackup as a Domain Administrator or System Administrator with access to the selected domain. Have the new Google service account credential file (.json, no larger than 64 KB) ready. See Setup Service Account to generate a credential file.

Use HTTPS or access JitBackup through localhost so the browser can encrypt the credential upload. You also need a Google Workspace super administrator account to authorize domain-wide delegation.

Risk: Missing permissions, disabled Google APIs, or an invalid key can interrupt backups and restores. Keep the previous service account and its authorization active until running jobs finish and backups and restores succeed with the new account.

Read the risk notice, select I understand the risks of replacing the service account, and click Replace to open the three-step wizard.

Step 1: Select the JSON File

  1. Verify the Domain and Administrator displayed in the wizard.
  2. Choose the new Service account credential file.
  3. Click Next. JitBackup validates the file and displays the new service account email and Client ID in the next step.

Selecting a file does not replace the active credentials.

Step 2: Grant Access

  1. Sign in to the Google Workspace admin console as a super administrator.
  2. Open Security > Access and data control > API controls > Manage Domain Wide Delegation, then click Add new.
  3. Copy the Client ID and the complete OAuth scopes list from the replacement wizard into the corresponding fields. Use the Client ID shown for the newly selected credential.
  4. Click Authorize in the Google Workspace admin console.
  5. Return to JitBackup, select I have authorized this Client ID with all the OAuth scopes above, and click Next.

Step 3: Check Permissions and Replace

JitBackup displays progress and a result for each of these eight checks:

Service Required access
Organizational units Read the organization list and verify the selected Workspace domain
Users Read the user list
Gmail Read/write OAuth authorization and read access
Drive Read/write OAuth authorization, file listing, and root write access
Contacts Read/write OAuth authorization and read access
Calendar Read/write OAuth authorization, event listing, and primary calendar write access
Tasks Read/write OAuth authorization and read access
Shared Drives Read/write OAuth authorization, drive listing, and read/write capabilities for configured Shared Drives

Checks use the administrator displayed in the wizard. Write checks verify OAuth authorization and available resource capabilities; they do not create or modify Workspace data. User licensing and individual item restrictions can still affect later backups and restores. If no Shared Drives are configured for backup, the result states that only authorization and drive listing were checked.

After all eight checks pass, select the confirmation to use the displayed service account for future backups and restores, then click Replace Service Account. Wait for the success message. JitBackup saves the new credential in encrypted form and switches the domain to it.

If a Check Fails

Read the details beside the failed check. Verify the new Client ID, the complete OAuth scopes list, required API enablement, administrator access, and Shared Drive permissions as applicable. For connection errors, check the JitBackup server's network and proxy settings.

Resolve the error, then click Run checks again. Replacement remains unavailable until every check passes. If the wizard reports that the upload expired, select the credential file again; if the check results are too old, rerun the checks before confirming.

You can click Cancel before the final replacement to discard the pending credential. Failed permission checks or a cancelled wizard leave the active service account unchanged.