Google Drive Service Account
Use this method when your organization manages Google Workspace access through a service identity. A Workspace administrator approves the delegation and scope, and an OpenCore Admin uploads and maintains the credential and selects or associates it when configuring the connector.
Prerequisites
Use Standard mode, because connectors and document indexing require it. You need a Google Cloud Project controlled by the organization, a Google Workspace administrator who can configure Domain-Wide Delegation, and the Primary Admin Email for the Workspace organization that owns the Drive content.
Create the Service Account
In the Google Cloud Project, create a Service Account and create a JSON Key for it. Keep the key secret and upload it only through the protected OpenCore Admin screen.
Record the Service Account OAuth client ID from Google Cloud. Domain-Wide Delegation uses that OAuth client ID, not the service account email address.
Configure Domain-Wide Delegation
In the Google Workspace Admin console, add the Service Account OAuth client ID to Domain-Wide Delegation and authorize only the scopes currently required by the Google Drive connector:
Do not add broader scopes unless the deployed connector changes its documented requirements. The Service Account impersonates the configured Primary Admin Email when it accesses Google Workspace.
Add the credential to OpenCore
- Sign in to OpenCore as an Admin and open Documents & Knowledge.
- Select Google Drive, choose Service account, and upload the JSON Key.
- Enter the Primary Admin Email for an administrator or owner of the Google Workspace organization that owns the Drive content.
- Create the credential, then keep the key out of source control, Agent instructions, and shared documents.
Only Admins can upload, replace, or otherwise maintain the Service Account credential. The Admin also selects or associates that Google credential when configuring the connector; do not assume it is shared with other roles.
Configure indexing scope
Choose the narrowest approved scope when the Admin configures the connector.
The selected scope and the impersonated account’s Google Drive permissions both limit what the connector can read. Domain-Wide Delegation does not replace content-owner approval for indexing.
Verify the connector
Create a connector with one small, representative approved scope and run an index attempt. Review the attempt result, indexed document set, and any reported skipped files or errors before attaching the document set to an Agent or broadening the scope.
Troubleshooting
Related pages
- Google Drive Overview compares authentication methods and indexing scopes.
- Google Drive OAuth covers browser-based authorization with an OAuth App.
- Connectors & Indexing explains document sets and index attempts.