Developed by CISA, ScubaGoggles is an assessment tool that verifies a Google Workspace (GWS) organization's configuration conforms to the policies described in the Secure Cloud Business Applications (SCuBA) Secure Configuration Baseline documents.
For the Microsoft 365 (M365) rendition of this tool, see ScubaGear.
Overview
We use a three-step process:
- Export. In this step, we primarily use the Google Admin SDK API to export and serialize all the relevant logs and settings into json. ScubaGoggles also uses various other Google APIs to grab organization metadata, user privileges etc.
- Verify. Compare the exported settings from the previous step with the configuration prescribed in the baselines. We do this using OPA Rego, a declarative query language for defining policy.
- Report. Package the results as HTML and JSON.
Table of Contents
Installation
Prerequisites
Authentication
Usage
- Usage: Parameters
- Usage: Config File
- Configuration UI — web-based form for building config files
- Usage: Examples
- Reviewing Output
- Limitations
Troubleshooting
- Not Authorized to Access This Resource
- macOS: Certificate Verification Error
- WinError 10013 Permission Error
- Unable to view HTML report due to environment limitations
- ScubaGoggles lists failures for the SPF, DKIM, and DMARC policies (GWS.GMAIL.2 through GWS.GMAIL.4) even though you have published the applicable DNS records
Automation
- ScubaConnect - ScubaConnect is cloud-native infrastructure, developed by CISA, that automates the execution of assessment tools ScubaGear and ScubaGoggles.
Misc
Project License
Unless otherwise noted, this project is distributed under the Creative Commons Zero license. With developer approval, contributions may be submitted with an alternate compatible license. If accepted, those contributions will be listed herein with the appropriate license.
Release files for scubagoggles 1.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| scubagoggles-1.0.1.tar.gz | 1.3 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| scubagoggles-1.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size:2.7 MB
Release files / scubagoggles-1.0.1.tar.gz
| Download URL | scubagoggles-1.0.1.tar.gz |
|---|---|
| Size | 1.3 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
74a8dea500543b4b24b85fe6789d0d059021090912182e9f55d06521563ff398
|
|
BLAKE2b-256 checksum How to use checksums |
ff85f5eed467d75fa6f7954aebfb726b0bb36b26833932315d0d763aaec3bc46
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 28, 2026.
Transparency logRelease files / scubagoggles-1.0.1-py3-none-any.whl
| Download URL | scubagoggles-1.0.1-py3-none-any.whl |
|---|---|
| Size | 1.4 MB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0fcbbc73f2c646fb6b01ec8a1a068954684a6022d0a7a32b3b21bba9f408bdc9
|
|
BLAKE2b-256 checksum How to use checksums |
6e239cacc45e30c1253e235f372468505330aaef16c0cc5d1559b0d34e5606c2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 28, 2026.
Transparency log