At a glance
- Availability: Enabled by default.
- Authentication: OAuth 2.0.
- Connection: A user authorizes the connection in the provider’s consent screen.
- Scopes:
https://www.googleapis.com/auth/drive.readonly,https://www.googleapis.com/auth/drive.file.
Credentials
Set these per environment. See Connect an integration. These variables are required only when you supply your own OAuth app. If a managed app is available, you can connect without setting them. Provider permissions and consent still apply.Setup
- Create a Google Cloud Project: Go to the Google Cloud Console and create a new project
- Enable the Google Drive API: Navigate to APIs & Services > Library and enable the Google Drive API
- Configure OAuth Consent Screen: Go to APIs & Services > OAuth consent screen. Set up your app name, user support email, and developer contact. Add scopes: drive.readonly and drive.file
- Create OAuth 2.0 Client ID: Go to APIs & Services > Credentials. Click ‘Create Credentials’ > ‘OAuth client ID’. Choose ‘Web application’. Add authorized redirect URI: http://localhost:3000/api/auth/drive/callback (adjust port/domain for production)
- Copy Credentials to .env: Copy the Client ID and Client Secret to your .env file as GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET
- Test the Integration: Start your application and navigate to /api/auth/drive to initiate the OAuth flow
Provider notes
- The same Google OAuth credentials work for all Google services (Gmail, Calendar, Sheets, Drive)
- In production, make sure to add your production callback URL to authorized redirect URIs
- The drive.file scope limits file changes to files created or opened by this app
- You may need to verify your app if you plan to distribute it publicly
Tools
Verify the connection
Call a read tool such asdrive__list_files with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.