Service account
Recommended for a Google Workspace. Indexes every user’s Drive through domain-wide delegation,
and it is what permission sync needs. Requires a Workspace administrator.
OAuth
Indexes as one Google account: its My Drive, the shared drives it belongs to, and files shared with it.
Works without a Workspace.
What gets indexed
Onyx creates one document per file. The document title is the file name, the link is the file’s Drive link, and the dates are the file’s created and modified times. Each document also records the file’s folder path, so the folder tree shows up as a hierarchy in Onyx, rooted at the shared drive name, My Drive, or Shared with me.What is not indexed
- Files in the trash
- Files over 10 MB. Set
GOOGLE_DRIVE_CONNECTOR_SIZE_THRESHOLD(bytes) on a self-hosted deployment to change the limit. Google-native files report no size, so the limit applies to their exported content. - Google Forms, Sites, Drawings, Jamboard, Colab notebooks, and other Google types with no text export
- Files with an extension Onyx does not accept, such as archives, executables, and video
- Comments, suggestions, and revision history
- Files the credential’s account or the impersonated users cannot open
Before you begin
You need:- An Onyx administrator account.
- A Google Cloud project with the Google Drive API, the Admin SDK API, and the Google Docs API enabled. Each authentication page walks through this.
- For a service account: a Google Workspace administrator, to grant domain-wide delegation.
- For Auto Sync Permissions: a service account credential, and a paid Onyx tier. Business or Enterprise on Onyx Cloud, or the Enterprise Edition when self-hosted.
Configure the connector in Onyx
1
Open the Google Drive connector
In Onyx, go to Admin Panel → Add Connector and select Google Drive.
2
Create or select a credential
Select Create New and follow the service
account
or OAuth page,
or select a credential you created earlier. Then select Continue.An instance can hold several Google Drive credentials, each for its own Workspace or Google account,
so one Onyx deployment can index more than one Workspace.
3
Choose what to index
Name the connector, then pick General or Specific under How should we index your Google Drive?General indexes whole areas of Drive:
Specific indexes only what you list, as comma-separated Drive URLs:
- Shared Drive URLs: whole shared drives.
- Folder URLs: folders, with all their subfolders.
- My Drive Emails: the My Drives of the listed users. Service account only.
4
Review the advanced settings
Under Advanced:
- Specific User Emails, service account only: index as these users instead of every user in the Workspace. Onyx then sees only the files these users can open, and the primary admin is not included unless listed.
- Hide domain link-only files?: skip files shared with the whole domain, or with anyone, by link only. Those files are visible to anyone who has the link, which permission sync cannot mirror.
- The refresh and pruning intervals.
5
Choose the access type
Public shows every indexed file to all Onyx users. Private limits them to selected Onyx user groups.
Auto Sync Permissions applies each searcher’s own Drive access.
See Auto Sync Permissions.See Document Access Controls for what each means.
6
Create and verify
Select Create Connector. Onyx lists one file as the primary admin to check the credential,
and for a service account it also opens the admin’s My Drive. With Auto Sync Permissions,
it also checks that the primary admin can read the Workspace directory. A check that fails names the cause;
see Troubleshooting.Then open Admin Panel → Existing Connectors, select the connector,
and check that the first indexing attempt finishes with about the number of files you expect.
A Workspace with many users takes a while, since Onyx walks each user’s Drive in turn.
How it works
- Refresh. The default refresh interval is 30 minutes. Each refresh lists files by modified time and reads only the ones changed since the last run.
- Resuming. A run saves its position as it goes, per user and per drive, so a run that stops partway resumes where it left off rather than starting over.
- Users. With a service account, Onyx lists the Workspace’s users through the Admin SDK and impersonates
each in turn, four at a time by default. Set
MAX_DRIVE_WORKERSto change that. A user who cannot use Drive, or who was removed from the Workspace, is skipped. - Access to a file. Onyx opens each file as the user it found it through. When that fails, it retries as the primary admin and then as owners of the file in the same domain, and it drops the file if none can open it.
- Rate limits. Google throttles per project and per user. Onyx waits as long as Google asks and retries, up to six times per request. A large first index is slower for it, but it does not fail.
- Deleted files. A file deleted or trashed in Drive, or one the credential can no longer see, stays in Onyx until a pruning run removes it.
Auto Sync Permissions
With Auto Sync Permissions, an Onyx user sees only the Drive files they can open in Google. Onyx reads each file’s sharing settings and the Workspace’s groups, and matches people by email address. Use a service account credential. Nothing stops an OAuth credential, but with OAuth Onyx can only walk the authorizing account’s own folders, so the group sync sees far less.Permission sync is a paid feature: the Business and Enterprise tiers on Onyx Cloud,
and the Enterprise Edition when self-hosted.
Some limits to plan around:
- Email matching. Onyx matches a Google user to an Onyx user by primary email address, case-insensitively. A user who signs in to Onyx with an alias sees nothing. An external collaborator gets access once they sign in to Onyx with the address the file was shared with.
- Nested groups. A group that is a member of another group is treated as a single address, so its members do not inherit the parent group’s files.
- Files owned outside the Workspace. When Google refuses to list a file’s sharing settings, usually for a file owned by another organization, only the user Onyx found it through can see it.
- A folder shared later. Onyx records a file’s folder at index time. A folder shared with new people after that reaches the file at its next re-index, not at the next permission sync.
DEFAULT_PERMISSION_DOC_SYNC_FREQUENCY and GOOGLE_DRIVE_PERMISSION_GROUP_SYNC_FREQUENCY (seconds)
on a self-hosted deployment to change the intervals.