CIIFragments Studio is CII-accredited: recover up to 20% of your software development spendLearn more

API integration for Google Drive

We build your Google Drive connector

We link your business file to the Google Drive API to deposit, export and react to a file, with drive.file plus Picker rather than a restricted scope.

  • Senior product team
  • Drive connectors in production
  • from scoping to monitoring
In short

What does the Google Drive API provide and why integrate it into business software?

Google Drive is the reference file storage system for millions of companies working in the Google Workspace ecosystem. Its API lets your application deposit files into a specific Drive, listen for document additions or changes and process them automatically, and export Sheets or Docs to your software. You integrate it so that quotes, contracts or reports generated by your application are automatically saved in the client's Drive folder, without teams switching between tools.

Use cases

What our clients build on the Google Drive API

01

Portal with Picker, not the whole Drive

The user picks the file. drive.file is enough. No six-month security assessment for a document drop.

02

Deal folder in a shared drive

Folder create, PDFs pushed, reaction to a signed contract dropped by sales. My Drive alone misses the real IS.

03

Accounting export from Sheets

files.export as CSV or PDF into the ERP. The table stays a Google Doc, the business flow receives a readable file.

04

"Inbox" folder under files.watch

X-Goog-Changed (content, permissions, parents) steers the re-read. A dropped PDF creates the deal, with no polling.

For you

What this changes in your Workspace files

The engineering serves a measurable result: the document in the file, a signable scope, fewer dead links.

You do not ask for the whole Drive

The user picks the file in the picker. That is often the only path compatible with a production timeline.

Docs and Sheets become usable

Export to PDF or CSV is part of the connector. A download everything without native export misses the core of the Google estate.

Shared drives are the system of record

We target the team drive in scoping. A My Drive demo that fails at the customer is not what we ship.

Quota does not kill the journey

Reads are paced. A naive crawl burns the user quota long before the project limit.

Method

How we deliver your Google Drive connector

01

Scoping

drive.file or a restricted scope (eligibility, audit), Picker, shared drives, Docs export. We refuse "we sync everything" without a security dossier.

02

Development

Persisted startPageToken, renewed watch, 5/50/100/200 unit counter, resumable upload beyond 5 MB, export and shortcut branches.

03

Acceptance

Doc vs PDF, shared drive without supportsAllDrives, expired channel, rejected changes token, 750 GB/day. Replay before cutover.

04

Monitoring

Alert on 403/429, dead channel, units/minute. Revocation procedure when the client leaves. Refresh tokens encrypted off-repo.

What the API allows

What the Google Drive API allows

Files, folders, shared drives
files, drives, permissions, revisions. Shortcuts and folders have no binary. appDataFolder for application state invisible in the UI.
Three upload modes
media and multipart up to 5 MB. resumable beyond that, or as soon as a drop is likely. The session URI expires after one week.
Export of Google files
files.export to a MIME type. alt=media does not download a Doc as a PDF. This is the branch that separates a Workspace connector from a files tutorial.
changes journal and push
getStartPageToken then changes.list. watch on a file or on the journal (pageToken required). Empty body, X-Goog-Changed sometimes present on files.watch.
Glossary

Google Drive API vocabulary

drive.file
Non-sensitive scope: only files the app opened or created. Coupled with Picker, this is the production path. drive and drive.readonly are restricted.
startPageToken
Cursor of the changes journal. We persist newStartPageToken. A rejected token forces a full replay, like a Calendar 410.
X-Goog-Changed
On files.watch: content, properties, parents, children, permissions. On changes.watch, the state is change: you must re-read the journal. Body always empty.
files.export
Only way out of a Doc/Sheet/Slide. alt=media does not apply to Google types. Export MIME scoped per project (PDF, CSV, DOCX).
Units
Read 5, edit 50, list 100, download 200. This is no longer "requests per second". 750 GB upload/day/Workspace user, max file 5 TB.
supportsAllDrives
Required as soon as a shared drive is in play, with driveId / corpora / includeItemsFromAllDrives. Forgetting it is a My Drive demo.
Good to know

The real constraints of the Google Drive API

01

Wide scopes are restricted

drive, drive.readonly, metadata, activity: security assessment if you store or transmit outside Google, and only eligible app categories. Promising "the whole Drive" without that budget stops the project at OAuth consent.

02

The notification is empty

Same family as Calendar. No HMAC. Handler: validate the token, enqueue, 2xx. Re-read via changes.list. No automatic channel renewal.

03

Listing is expensive

files.list = 20 × files.get. A recursive crawl burns 325,000 units/min/user. fields=* in production is an anti-pattern. Truncated backoff per the Google limits guide.

04

quotaUser does not save authenticated Drive

For Drive with a token, quota follows the token, not quotaUser (reserved to anonymous on public files). A delegated service account remains one user. 2026 billing to price into the TCO.

Google Drive or SharePoint

Google Drive API or SharePoint API?

Two corporate disks. The right one follows Workspace or the Microsoft tenant already there.

CriterionGoogle DriveThis pageMicrosoft 365Graph files
Typical estateWorkspace, shared drivesSharePoint / OneDrive on the tenant
Fine perimeterdrive.file + PickerSites.Selected + POST /permissions
Office filesMIME export required (Docs/Sheets)binaries and Office in the drive
Incrementchanges.list + startPageTokendelta query + deltaLink
Push signatureNo HMAC, channel tokenGraph subscription, 202 first
Resumable uploadfrom 5 MB, URI 7 daysfrom ~10 MiB, multiples of 320 KiB
The right caseThe company is already on WorkspaceThe company is already on Microsoft 365

Box and Dropbox come up if the DMS is neither Drive nor SharePoint. Sheets is a deliverable only if the table really is the document.

Our expertise

What we measure on a Google Drive integration

15 d
first Drive flow in production
file
drive.file scope targeted by default
< 1 min
changes re-read after a watch
4
senior developers on the project
Compare

The other file APIs

If the estate is not Workspace, these options belong in the scoping conversation.

We combine Google Drive with

The stack around Drive on our projects.

  • HubSpot
  • Pennylane
  • n8n
  • PostgreSQL
  • Node.js
FAQ

Google Drive integration: your questions

OAuth with the narrowest possible scope (drive.file plus Picker by default), a client that sends fields, an export branch for Google types, resumable upload beyond 5 MB, changes journal plus watch for near real time. supportsAllDrives as soon as a shared drive exists. A unit counter on the client. The hard part is not files.create, it is the restricted scope we did not promise, and a push channel with no HMAC.

The healthy default is drive.file, non-sensitive, limited to the app's files, glued to Picker. drive.appdata is for application state. drive and drive.readonly are restricted: security assessment, eligible app categories (backup, productivity, reporting). Promising a full sync without that dossier is a project stopped at consent. Google also pushes migration toward drive.file. This is a scoping call, written down before the first request, not an acceptance surprise.

A first useful flow, typically a Picker drop attached to the business file, ships in two to three weeks. A DMS connector (changes, watch, export, shared drives, unit counter) is closer to six to eight weeks. A restricted scope adds Google's audit calendar, often longer than the code. We say so at scoping. This is a scoping call, written down before the first request, not an acceptance surprise. A restricted scope adds Google's security assessment calendar, often longer than the code itself.

Follow the tenant. Workspace: Drive v3. Microsoft 365: Graph files (Microsoft 365 page). Both have an increment and a push that needs a re-read. Drive requires files.export for Docs/Sheets; SharePoint speaks units and Sites.Selected. Box and Dropbox if the DMS is already elsewhere. This is a scoping call, written down before the first request, not an acceptance surprise. Box and Dropbox come up if the DMS already lives somewhere else.

Not with files.get alt=media. A Doc, Sheet or Slide comes out through files.export to a MIME type (PDF, DOCX, CSV, and so on). Shortcuts are followed via shortcutDetails.targetId. Folders have no binary content. A connector that "downloads everything" without this branch is wrong on the Workspace estate, even if the demo passes on a PDF. This is a scoping call, written down before the first request, not an acceptance surprise.

A Google Drive integration project?

Let's talk. 30 minutes to scope Picker, scopes, shared drives, and tell you plainly if a restricted scope is tenable.

Discuss my Drive project
Discuss my Drive project