Skip to content

Google Drive Authentication

1706 edited this page Jul 23, 2026 · 3 revisions

⚠️ Breaking change (as of this update): the token generation method has changed. Any token.pickle created with the old cell (via oauth2client / GoogleCredentials.get_application_default()) is no longer compatible and must be regenerated using the steps below.

This page explains how to generate a token.pickle file that the bot uses to authenticate with the Google Drive API, and that supports automatic token refresh so you don't have to regenerate it every time the access token expires.


Part A — One-time setup in Google Cloud Console

  1. Go to console.cloud.google.com and create a new project (or use an existing one).
  2. Go to APIs & Services → Library, search for Google Drive API, and click Enable.
  3. Go to APIs & Services → OAuth consent screen:
    • Set User type to External (unless you're using a Google Workspace organization account).
    • Fill in the required app info (name, support email, etc. — this is only used internally, values don't matter much).
    • Under Test users, add the Gmail address of the account whose Drive you want the bot to access.
  4. Go to APIs & Services → Credentials → Create Credentials → OAuth client ID:
    • Application type: Desktop app.
    • Give it a name and click Create.
    • Download the resulting JSON file and rename it to client_secrets.json.
  5. Upload client_secrets.json to your Colab session (drag-and-drop it into the file panel, into /content/).

Because the app is still in "Testing" status (not published/verified by Google), you'll see a "Google hasn't verified this app" warning during login. This is expected — click Advanced → Go to (app name) (unsafe) to continue, since you are the test user yourself.


Part B — Run the authentication cell

Copy-paste the code from google_auth.py into a single cell, then run it.

  • DO = "Generate"
  • CLIENT_SECRETS_FILE pointing to the uploaded client_secrets.json path (default /content/client_secrets.json)
  • SAVE_TO set to where you want token.pickle saved (default /content/token.pickle)

The cell will print an authorization URL. Follow these steps:

  1. Open the printed URL in your browser and sign in with the Google account whose Drive you want to use.
  2. Grant the requested permissions.
  3. Your browser will then try to load a http://localhost/?state=...&code=... page and fail to connect. This is expected — do not close the tab.
  4. Copy the value of the code= parameter from that URL in your browser's address bar (everything after code= and before the next &).
  5. Paste that code back into the Colab prompt when asked.

The cell will then save token.pickle and print whether a refresh token was successfully obtained.


Notes

  • client_secrets.json is a secret credential — never commit it to the repository. It is per-user and is only needed locally in your Colab session.
  • The requested scope is drive.readonly, matching what the bot currently does (download only, no uploads via the Drive API). If a future feature requires write access to Drive, the scope will change and all users will need to regenerate token.pickle again.
  • Once generated, token.pickle will be refreshed automatically by the bot when it expires, as long as the refresh token remains valid (i.e. access hasn't been revoked from your Google account and the token hasn't been unused for an extended period).

Clone this wiki locally