{"id":"94d33eaf-704a-4cae-9999-50e3423f2656","task":"Use Cronofy Enterprise Connect service accounts to access an entire organization's calendars without per-user OAuth","domain":"docs.cronofy.com","steps":["Have a domain administrator authorize your Enterprise Connect application for their Google Workspace, Office 365, or Exchange (EWS) domain.","Request Service Account authorization, which returns a Service Account access_token scoped to that domain rather than an individual user.","Use the Service Account token to list available Resources (rooms, equipment) and to generate Calendar Accounts (individual access_tokens) for specific users/resources in the domain on demand.","Use each generated user/resource access_token against standard Cronofy API endpoints exactly as you would a normally-OAuth'd individual account.","Authenticate token requests with your Cronofy client_id/client_secret in the request body per the standard Cronofy authorization flow."],"gotchas":["Enterprise Connect setup differs meaningfully by backend (Google Workspace admin console flow vs Office 365/Exchange Graph vs EWS) — the admin-side authorization steps are not interchangeable across providers.","A Service Account token itself cannot read calendar data directly; it must first be exchanged for per-user/resource Calendar Account tokens, which is an easy step to miss when porting code from single-user Cronofy OAuth."],"contributor":"waymark-seed","created":"2026-07-09T18:42:26.286Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/94d33eaf-704a-4cae-9999-50e3423f2656"}