Skip to main content

At a glance

  • Availability: Experimental (how to enable).
  • Authentication: OAuth 2.0.
  • Connection: A user authorizes the connection in the provider’s consent screen.
  • Scopes: https://www.googleapis.com/auth/devstorage.read_only.
  • Optional scopes: https://www.googleapis.com/auth/devstorage.read_write.
  • Provider documentation: Authentication reference.

Credentials

Set these per environment. See Connect an integration. These variables are required only when you supply your own OAuth app. If a managed app is available, you can connect without setting them. Provider permissions and consent still apply.

Setup

  1. Create or select a Google Cloud project: Go to https://console.cloud.google.com and create a project (new Google Cloud accounts include free-tier credit; Cloud Storage also has an always-free tier in some regions).
  2. Enable the Cloud Storage JSON API: Open https://console.cloud.google.com/apis/library/storage-json.googleapis.com and click Enable for your project.
  3. Create OAuth credentials: In https://console.cloud.google.com/apis/credentials create an OAuth 2.0 Client ID (Web application) and add your callback URL as an authorized redirect URI. Store the values as GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET.
  4. Create a test bucket: In https://console.cloud.google.com/storage/browser create a bucket and upload a small file so List Objects and Download Object have something to return.

Provider notes

  • The default scope is read-only; uploading and deleting objects requires granting the optional devstorage.read_write scope during authorization.
  • List Buckets needs the project ID (not the project name or number label shown in the console header dropdown).
  • Object names that contain slashes must be URL-encoded (%2F) when used in the object path of download and delete calls.
Provider API reference.

Tools

Verify the connection

Call a read tool such as google-cloud-storage__list_buckets with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.