Skip to content
Omnimatch DocsOpen app

Connect Google Drive

On this pageBefore you startConfigure your Google projectEnter settings and choose filesWhere your data goesGet help

Connect selected Google Drive files using a Google Cloud project owned by your organisation. Omnimatch can help with setup; your administrator creates and enters your credentials.

Before you start

Activate a licence with Google Drive enabled and use a stable HTTPS installation address. Google Drive and OneDrive are independent options; only licensed providers appear during agent creation. Neither requires Omnimatch hosted data. Google sign-in, the browser picker and Drive requests require internet access.

Configure your Google project

  1. Create or select your organisation’s Google Cloud project and enable the Google Drive API and Google Picker API.
  2. Configure the OAuth audience and consent screen. For an organisation-owned Workspace application, use the internal audience where available and follow your Workspace administrator’s app access policies.
  3. Create a Web application OAuth client. In Omnimatch, open Admin → System administration → Drives → Google Drive and copy its Redirect URI into the client’s authorised redirect URIs. Add your installation’s origin where Google requests an authorised JavaScript origin.
  4. Create a Picker API key in the same project. Apply API restrictions for Picker and website restrictions covering your app and https://docs.google.com/*. Record the numeric Google Cloud project number.

Follow Google’s Picker setup and OAuth consent guidance.

Enter settings and choose files

In Drives → Google Drive, enter Client ID, Client secret, Picker API key and Google Cloud project number. Choose Save configuration, then open Google Drive in the agent’s Data step, choose Connect account and select files in Google’s picker. Test an answer and its citation before sharing the agent.

The integration requests drive.file access to explicitly authorised files. Although this permission permits edits, Omnimatch’s connected source only searches and reads. You can browse folders in the picker, but cannot grant a folder or automatically include future files. See Google’s Drive scope reference.

The agent uses its source owner’s connected account. Its audience may receive answers from the selected documents; opening an original still requires their Google access. The Picker API key is sent to the browser as required by Google; OAuth client secrets and refresh tokens remain server-side.

Where your data goes

Run Omnimatch on your own servers or in your organisation’s provisioned cloud environment. Your installation connects directly to the document provider using your organisation’s application credentials. These connector requests do not pass through Omnimatch’s servers. The provider still operates its cloud storage service.

Client secrets and account tokens are encrypted in your installation’s database using its own encryption key. No shared Omnimatch document-provider secret is supplied in the image. Your server administrators control the installation and its keys.

Files are searched and read on demand without importing a document corpus into Omnimatch’s index. Retrieved excerpts can enter model requests and saved conversations. Choose an approved model connection and protect local conversation data and backups. A customer-owned external model API key still sends requests to that provider.

Get help

If Google Drive is missing, check its separate licence permission. If Google reports an invalid Picker key, check the enabled APIs, project number and website restrictions. A previous broad Drive grant may need removal in the Google Account before reconnecting with selected-file access.

To replace credentials, open Drives → Google Drive, choose Change beside Client secret, enter the new value and confirm Replace configuration. You can keep the saved secret when updating settings for the same client ID; changing the client ID requires its new secret. All Google Drive accounts must reconnect after a configuration change. Contact Omnimatch for installation help; keep secrets out of support messages.