---
title: Google Drive integration (agent-driven file management)
---

# Google Drive integration (agent-driven file management)

## What it is

Omniscio's Google Drive integration is mainly **agent-facing**: alongside the Drive panel's file browser ([DriveProjectView.tsx](/src/renderer/src/features/drive/DriveProjectView.tsx) — grid/list, preview, upload, share), Claude gets seven Drive tool-use calls inside any chat conversation, so you ask in plain English ("create a folder called 2026-campaigns and move the assets from #design-review into it", "share the quarterly report with sarah@…", "what's my Drive quota looking like") and the agent decides which tool to call, Omniscio executes it via Google's API, and the agent continues its turn using the result. Drive shares the same single "Connect Google" OAuth as Calendar, Sheets, and Gmail — one consent, all four integrations.

> **⚠️ CASA Tier 2 scope change (2026-08).** To keep the app on the cheap CASA **Tier 2** assessment, the shared "Connect Google" OAuth now requests `drive.file` (only files the app itself creates) instead of full `auth/drive` — full `drive` is a Tier-3 "restricted" scope that triggers the expensive annual pentest. Under `drive.file`, the six **existing-file** tools below (list / get / move / share / delete / quota) and the read-only Drive MCP no longer work — only creating new files/folders does. The read-only Drive MCP is already **force-disabled** (`DRIVE_MCP_TIER3_DISABLED`, `mcp-config-orchestrator.ts`); the guard test [oauth-scopes-casa-tier2.test.ts](/tests/unit/lint/oauth-scopes-casa-tier2.test.ts) locks the scope. **Full Drive over a user's existing files is moving to a bring-your-own `gog` CLI path** — a user who sets up the `gog` Google Workspace CLI with their own Google credentials gets full Drive with no CASA burden on Omniscio. Fully retiring the built-in Drive AI service + channel adapter and wiring the gog path is a tracked FOLLOW-UP; today the built-in Drive is opt-in (`driveEnabled`, default off) and degrades to create-only when enabled.

## Where to find it

### How to use it

1. **Connect Google.** Settings → **Google** → **Connect Google**. A browser tab opens; approve the scopes for Calendar, Drive, Sheets, and Gmail in one go. Omniscio catches the OAuth redirect on a loopback HTTP server, encrypts the refresh token via `safeStorage`, and stores it.
2. **Toggle Drive on.** Settings → **Google Drive** → enable `driveEnabled`. The OAuth scopes were already requested at connect time; this flag controls whether Omniscio actually issues Drive requests.
3. **Ask the agent for Drive things.** In any Claude session, type natural-language requests — the agent has access to seven Drive tools: list files, get a single file's metadata, create a folder, delete a file, move a file, share a file with someone, and check Drive quota. Results come back as markdown with clickable `webViewLink`s opening Drive in the browser.
4. **The old Drive MCP server for CLI sessions is retired.** It needed the restricted `drive.readonly` scope, so it is force-disabled (see the CASA note above). Omniscio no longer writes anything into `~/.claude.json` for it — it only removes the old entry at startup and on disconnect — and the Google refresh token never leaves Omniscio's encrypted config. Agents reach Docs, Sheets and Drive through the bundled Google Workspace MCP instead, which gets a short-lived access token from Omniscio at call time.

## How it behaves

### How it works

Google OAuth lives in [/src/main/services/google/google-auth-service.ts](/src/main/services/google/google-auth-service.ts) — single flow, loopback HTTP redirect, encrypted refresh token. The Drive AI service is [/src/main/services/drive-ai-service.ts](/src/main/services/drive-ai-service.ts): seven tools (`list_files`, `get_file`, `create_folder`, `delete_file`, `move_file`, `share_file`, `get_storage_quota`) wrapping the `googleapis` npm package, executed inside a token loop that runs _agent message → Claude returns tool_use → Omniscio executes via googleapis → result appended → repeat until `stop_reason='end_turn'`_. A circuit breaker prevents thundering-herd API storms; per-account cost tracking attributes API spend; errors return as tool results so Claude can recover the same turn. IPC handler: [/src/main/ipc/drive-handlers.ts](/src/main/ipc/drive-handlers.ts) (channel `DRIVE_AI_CHAT` plus non-AI list/CRUD endpoints). [/src/main/services/mcp/mcp-registry.ts](/src/main/services/mcp/mcp-registry.ts) now only unregisters the retired read-only Drive MCP's legacy `~/.claude.json` entry (`unregisterDriveMcp`); no refresh token is written into any MCP config. The unified-inbox adapter (used when Drive items are surfaced in the sidebar) is [/src/main/services/channels/drive-adapter.ts](/src/main/services/channels/drive-adapter.ts). Settings flag: `driveEnabled` in [/src/shared/types.ts](/src/shared/types.ts).

## Related

- [INDEX.md](INDEX.md) — full library index
- [google-integrations.md](google-integrations.md) — umbrella doc for Calendar + Drive + Sheets, shared OAuth
- [sheets-integration.md](sheets-integration.md) — sibling Google integration with similar agent-driven UX
- [gmail-integration.md](gmail-integration.md) — Gmail uses the same Google OAuth flow
