CLI tool
GAM-team/GAM avatar
GAM-team/GAM

GAM: command line management for Google Workspace

command line management for Google Workspace

4,326 stars542 forksPythonApache-2.0

At a glance

What is it?
GAM is a Python CLI that puts Google Workspace administration into scripts and terminals instead of the Admin console. It installs in one command on Linux and macOS, ships a Windows EXE installer, and is also available as the gam7 package on PyPI.
Who is it for?
Adopt GAM if you administer Google Workspace and want repeatable, scriptable operations instead of clicking through the Admin console, and if you are comfortable running commands from a terminal. Do not adopt it if you need a graphical interface, or if you cannot give a command line tool OAuth2 credentials with administrative scope over your domain.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What GAM is for and who ends up using it

The README describes GAM in one sentence: a command line tool for Google Workspace admins to manage domain and user settings quickly and easily. That audience is narrow and specific. It is not for end users who want to change their own profile picture, and it is not a general Google API client. It is for the person who holds admin rights over a Workspace domain and has to carry out the same operations repeatedly: creating accounts, adjusting settings, pulling information out of the directory.

The repository topics point at the surface area: google-admin-sdk, google-api, google-apps, google-calendar, google-cloud, google-drive, google-workspace, gsuite, oauth2. So the tool reaches across several Google services rather than one. The value proposition is that a task which takes a sequence of clicks in a browser becomes a single command you can store in a file, review, and run again.

GAM is maintained by Jay (James) Lee and Ross Scroggs, according to the README. The project is not archived, and the last push was on 2026-09-23, with releases v7.48.09, v7.48.10 and v7.48.11 published between 2026-09-16 and 2026-09-19. That release cadence is worth noting if you are deciding whether to depend on it.

How GAM reaches the Google APIs

GAM is a Python program, and the repository layout confirms it: a src/ directory holding the package, a pyproject.toml, and a wiki/ directory. The pyproject.toml declares the package name as gam7 and the console entry point as gam = "gam.__main__:main", so the installed command is gam.

The dependency list is the clearest statement of how it works. GAM depends on google-api-python-client, google-auth, google-auth-httplib2 and google-auth-oauthlib. In other words, it is a client built on Google's own Python libraries and the OAuth2 flow, not a reimplementation of the APIs. When you run a gam command, the work is authenticated with OAuth2 credentials and then sent through the Google API client to whichever Google service the command targets.

That design has a direct consequence for operators. GAM does not hold its own data store or proxy. Your credentials and the API calls are the whole picture, which means the tool inherits the API's permission model, its quotas, and its error messages rather than abstracting them away. The dependency list also pins exact versions (arrow==1.4.0, cryptography==50.0.1, google-api-python-client==2.200.0, and so on), so an install resolves to a known set of libraries rather than floating ranges.

Installing GAM on Linux, macOS and Windows

The README gives a Quick Start with three routes. On Linux and macOS, the documented one-liner is a bash command that downloads GAM, installs it and starts setup. Run it in a terminal and the setup step begins after the download:

bash
bash <(curl -s -S -L https://gam-shortn.appspot.com/gam-install)

On Windows, the README points to the EXE Installer on the GitHub Releases page. You run it and, in the README's words, you'll be prompted to setup GAM. If you would rather manage GAM as a Python package, the README offers pip:

bash
pip install gam7

That last route is the one to watch if you care about your environment. The pyproject.toml sets requires-python = ">=3.10" and lists classifiers for Python 3.10 through 3.14. Installing gam7 on an older interpreter is outside what the project declares support for. There is also an optional extra for hardware keys, declared in pyproject.toml as the yubikey extra, which pulls in yubikey-manager==5.9.2. The README does not document what that extra changes in the setup flow, so treat it as an available extra rather than a documented authentication mode.

Once installed, the command to invoke is gam. The README's setup step is what establishes your credentials; the wiki is where the actual command syntax lives, and the README sends you there rather than listing commands itself.

Where the documentation stops and the wiki begins

The README is short by design. It covers installation, points to the GitHub Wiki for documentation, and routes questions to a Google Groups mailing list. It does not enumerate commands, does not show a worked example of changing a user setting, and does not describe the OAuth2 setup in any detail.

This matters more than it might for a tool of this scope. A command line tool that spans admin settings, calendar, Drive and cloud resources has a large command surface, and the README gives you no map of it. The wiki is the documentation, and the README treats it that way. If you are evaluating GAM, the honest first step is to open the wiki and check whether the specific operation you need is documented with a syntax you can follow.

There is also a support structure to weigh. The project offers a Google Groups mailing list and a public Google Chat room, with instructions to join the chat room on a wiki page. Both are community channels, not a support contract. The README explicitly asks that "how do I?" questions go to the Google Groups list. For an admin tool that touches production accounts, that is a real consideration: you are relying on a mailing list and a wiki, not a vendor.

The limits you should know before you script against it

GAM's power comes from the same place as its risk. It is a direct client to Google's APIs with administrative credentials, so a mistake in a command is a mistake against your live domain. There is no dry-run mode documented in the README, no rollback section, and no staging environment described. The README is silent on all three. If you plan to automate destructive operations, that silence is the thing to resolve before you run anything.

Second, the install story is not uniform. Linux and macOS get a curl-piped-to-bash script, which runs remote code directly in your shell. Windows gets an EXE installer from the releases page. Python users get pip. Three paths mean three different update mechanisms, and the README does not describe how upgrades work on any of them.

Third, GAM is the wrong tool when the job is not administrative. If you need a user-facing integration, a service that runs inside your own application, or a UI for non-technical staff, a CLI that assumes admin credentials is the wrong shape. It is also the wrong tool if your organisation forbids command line tools from holding domain-wide OAuth2 credentials. That is a policy question GAM cannot answer for you.

How GAM differs from Google's own admin surfaces

The obvious alternative is the Google Workspace Admin console itself, plus Google's client libraries used directly. The difference is not features so much as where the logic lives. The Admin console is a browser interface: state lives in your clicks and in whatever notes you keep. GAM moves that state into commands, which can be version-controlled, reviewed and re-run.

The second alternative is writing your own scripts on top of google-api-python-client. That is exactly what GAM already is, and the pyproject.toml shows the same dependencies you would pull in yourself. The trade-off is control versus maintenance. Your own script does only what you wrote, with no command surface to learn, but you own the OAuth2 flow, the argument parsing, the error handling and every API change. GAM owns that for you and you inherit its command syntax and its release cadence instead.

A third comparison is more structural. Because GAM depends on google-api-python-client and google-auth-oauthlib, it is not a competing protocol or a proxy service. It is a front end over the same APIs any other client uses. If GAM's syntax does not fit a task, the underlying API is still there, and you can mix approaches: use gam for the routine operations and your own code for the ones it does not cover.

Licence, maintenance and what an upgrade costs you

GAM is licensed under Apache-2.0, stated in the repository's LICENSE file and in pyproject.toml as "Apache License (2.0)". Apache-2.0 is a permissive licence that allows commercial use and modification, and it includes an explicit patent grant. It also means the project comes with no warranty, which is worth remembering for a tool that holds administrative credentials. This is a description of the licence text, not legal advice; check it against your own policies.

The dependency pins are the practical upgrade cost. Every entry in the dependencies list is pinned to an exact version, including google-api-python-client==2.200.0 and google-auth==2.57.1. That is good for reproducibility and bad for staying current: you do not get a newer Google client library until GAM releases a version that pins it. The build backend is pinned too, hatchling<1.30.0.

The maintenance signal is strong but should be read precisely. The repository is not archived, and the last push was on 2026-09-23. Three releases landed within four days in September 2026. That is a frequent release pattern, and it also means the version you install today may be superseded within days. If you deploy GAM across a team, decide up front whether you track each release or pin to one, because the project's own pinning strategy does not make that choice for you.

Editorial conclusion

Adopt GAM if you administer Google Workspace and want repeatable, scriptable operations instead of clicking through the Admin console, and if you are comfortable running commands from a terminal. Do not adopt it if you need a graphical interface, or if you cannot give a command line tool OAuth2 credentials with administrative scope over your domain. Before rolling it out, verify that your Python is 3.10 or newer if you install the gam7 package, read the GitHub Wiki page for the exact command syntax of the operation you plan to automate, and confirm which Google APIs your project must enable for that operation.

Frequently asked questions

What is GAM?

GAM is a command line tool for Google Workspace admins to manage domain and user settings, according to the README. It is written in Python and installs as the gam command.

What does GAM stand for?

The repository name and the related search phrase "Google Apps Manager (GAM)" indicate the expansion, and the README frames the tool around Google Workspace administration. The README itself does not spell out the acronym.

Is GAM free to use?

GAM is published under Apache-2.0, stated in the repository LICENSE file and in pyproject.toml as "Apache License (2.0)". That is a permissive open source licence, and it comes with no warranty.

What is the latest version of GAM?

The most recent release listed for the project is v7.48.11, published on 2026-09-19. The releases page on GitHub is where the project publishes its versions and the Windows EXE installer.

Official sources

  1. GAM-team/GAM on GitHub
  2. License: Apache-2.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/gam-team-gam.svg)](https://hysenlabs.com/projects/gam-team-gam)