Google Drive / Google Workspace
Shared Drives and My Drive.
Access mode: Read-only (typically)
Required information
| Field | Details |
|---|---|
| Google Workspace domain | Organization domain. |
| Shared Drive ID(s) | If scoping to specific Shared Drives. My Drive requires user impersonation. |
| Service account | GCP service account with domain-wide delegation (for org-wide access) or direct sharing (for specific drives). |
| API scopes | Read-only: https://www.googleapis.com/auth/drive.readonly. |
Network considerations
Fully managed SaaS. HTTPS to googleapis.com. No VPN needed.
Google Workspace admin restrictions: If the org restricts API access, the service account must be allowed in Google Admin Console → Security → API controls.
Credential and auth management
Preferred: Service account with domain-wide delegation. Configured in Google Admin Console. Service account impersonates users to access My Drive content. Requires Super Admin approval.
Alternative: Direct sharing. Share specific Shared Drives with the service account email. No domain-wide delegation needed. More limited but less privileged.
Service account key (JSON): Stored encrypted in Flume’s secrets manager.
No session concept: Each API call independently authenticated.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET https://www.googleapis.com/drive/v3/about?fields=user | Returns authenticated identity |
| Drive listing | GET https://www.googleapis.com/drive/v3/drives | Lists accessible Shared Drives |
| File listing | GET https://www.googleapis.com/drive/v3/files?q='<driveId>'+in+parents | Lists files |
| File read | GET https://www.googleapis.com/drive/v3/files/<fileId>?alt=media | Downloads file content |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.