Set up the Google side so Sasha can sign in to your Google Drive
The steps in Google Cloud Console that give you the client ID and client secret that a Google Drive connection in Settings → Shared Drives needs.
- Where
- Google Cloud Console (console.cloud.google.com) first, then Settings → Shared Drives in Sasha.
- Who
- A Sasha admin, with a Google account that can create a Google Cloud project. For a Google Workspace organisation, use an account in that organisation.
- Needs
- A Google Cloud project with the Google Drive API on, a consent screen, and an OAuth client of type Web application with the redirect address from the Sasha connection card.
What this page is for
A Google Drive connection in Settings → Shared Drives asks for a Client ID and a Client secret. Google gives you these when you register Sasha as an app in Google Cloud Console. This page tells you how. For the Sasha screen itself, see Let Sasha read files that live in OneDrive, SharePoint or Google Drive without uploading them.
You do the steps once for each Sasha. They take about 15 minutes.
Before you start
- In Sasha, open Settings → Shared Drives.
- Click Add Connection, choose Google Drive, type a display name and click Save Connection.
- On the new connection card, find Redirect URI and click Copy. Keep this address. It looks like
https://your-sasha.example.com/api/auth/gdrive/callback.
The address comes from the address your browser uses for Sasha. Open Sasha at its public address before you copy it.
Step 1: create a project
- Go to Google Cloud Console and sign in.
- Open the project list at the top of the page and click New project.
- Type a name, for example "Sasha Drive", and click Create.
- Make sure the new project is selected at the top of the page.
Step 2: turn on the Google Drive API
- Open APIs & Services → Library.
- Search for Google Drive API and open it.
- Click Enable.
Step 3: set up the consent screen
Google calls this area Google Auth Platform or OAuth consent screen, depending on the version of the console.
- Open APIs & Services → OAuth consent screen and click Get started.
- App information: type an app name, for example "Sasha", and choose a support email.
- Audience: choose Internal if you can. See "Internal or External" below.
- Contact information: type an email address for messages from Google.
- Accept the policy and click Create.
- Open Data access and click Add or remove scopes. Select these four and click Update, then Save:
| Scope | Why Sasha asks for it |
|---|---|
openid |
To confirm the account that signed in |
.../auth/userinfo.email |
To show the account's email on the connection card |
.../auth/userinfo.profile |
To show the account's name |
.../auth/drive |
To list, open, upload, move and delete files in the drive |
If you skip step 6, the connection can still work, because Sasha asks for these scopes when you click Connect. Adding them here makes the consent screen show what Sasha uses.
Step 4: create the OAuth client
- Open APIs & Services → Credentials.
- Click Create credentials → OAuth client ID.
- Application type: choose Web application.
- Name: type "Sasha Drive".
- Leave Authorised JavaScript origins empty. Sasha does not use it.
- Under Authorised redirect URIs, click Add URI and paste the Redirect URI from the Sasha card.
- Click Create.
- Google shows the Client ID and the Client secret. Copy both now. Google may not show the secret again.
Google can take a few minutes to apply a new or changed redirect address.
Step 5: connect in Sasha
- Go back to Settings → Shared Drives and find your Google Drive card.
- Paste the Client ID and the Client secret.
- Click Connect.
- Sign in to Google with the account whose files Sasha should read, and click Allow on every screen.
- Google sends you back to Sasha. The card shows Connected and the account.
If Sasha shows "Provider did not return a refresh token. Ensure consent is granted.", sign in again and approve every screen in full.
Internal or External
Sasha asks Google for full access to the drive (.../auth/drive). Google calls this a restricted scope, and the choice of audience then decides how long the connection works.
| Audience | Who can choose it | What happens |
|---|---|---|
| Internal | A Google Workspace organisation | Only accounts in your organisation can sign in. Google does not need to check the app. The connection keeps working. |
| External, status Testing | Anyone, also a personal Gmail account | Only accounts that you add under Audience → Test users can sign in. Google cancels the sign-in after 7 days, and you must click Reconnect each time. |
| External, status In production | Anyone | Google must verify the app before people outside the test list can use it. For a restricted scope, this includes a paid security assessment. |
For a Google Workspace organisation, choose Internal. For a personal Gmail account, use External in Testing, add the account as a test user, and expect to reconnect every week.
Keep it safe
- Paste the client secret only into Sasha. Do not send it by email or chat.
- Sasha stores the client secret and Google's sign-in encrypted on your Sasha server. The secret never goes back to the browser.
- The account that signs in decides what Sasha can see. Use a business account that holds only the files your team should see in Sasha.
- Read-only on the Sasha connection does not limit Google access. Sasha asks Google for full access to the drive whatever you choose. See Let Sasha read files that live in OneDrive, SharePoint or Google Drive without uploading them.
- To stop Sasha's access, remove the connection in Sasha and also remove Sasha's access at Google (see the questions above).
Questions
Do I need a paid Google Cloud account?
No. The Google Drive API and an OAuth client cost nothing. Google may ask you to accept its terms when you create the project.
Internal or External?
Choose Internal if your Google account is in a Google Workspace organisation. Choose External only for a personal Gmail account, and read "Internal or External" below first.
Why does Sasha stop reading the drive after 7 days?
Your consent screen is External with the publishing status Testing. In that state, Google cancels Sasha's sign-in after 7 days. Change to Internal if you can. If you cannot, click Reconnect on the connection card each time.
Google shows "Access blocked" or "This app is blocked". Why?
The consent screen is External, in Testing, and the account that signs in is not on the list of test users. Add that account under test users and try again.
Google shows redirect_uri_mismatch. Why?
The redirect address in the OAuth client does not match the one on the Sasha connection card exactly. Copy it again from the card and paste it into Authorised redirect URIs. Check http and https, the host name and the end of the path.
I lost the client secret. What do I do?
In the OAuth client, add a new secret and copy it. Type it into the connection card in Sasha, then click Reconnect. Delete the old secret at Google when the connection works again.
Which Google account should sign in when I click Connect?
The account whose files you want people to see in Sasha. Sasha sees what that account can open, with full access, so use a business account and not a person's private account.
How do I cancel Sasha's access at Google?
The signed-in account can remove Sasha at myaccount.google.com, under Security, then third-party connections. You can also delete the OAuth client in Google Cloud Console. Remove in Sasha alone does not cancel the access at Google.