Docs

Google Cloud Storage API Authentication

How to authenticate Google Cloud Storage API requests: one Bearer API key plus a connectionId. MindCloud runs the OAuth flow and refreshes tokens for you.

Every Google Cloud Storage API request through MindCloud needs two things: a MindCloud API Key and a connectionId for your Google Cloud Storage account. This page covers both, plus exactly how to send them, so you do not need to visit any other page to get authenticated.

Steps to authenticate

  1. Create a MindCloud account at app.mindcloud.co if you do not already have one.
  2. Generate a MindCloud API Key in API Keys. This is the Bearer token you send on every request. Keep it on your server.
  3. Create a Google Cloud Storage connection in Connections. Google Cloud Storage uses OAuth. When you create the connection, you are redirected to sign in to Google Cloud Storage and approve access — MindCloud stores the resulting tokens and refreshes them automatically, so your integration never has to.
  4. Copy the connection’s connectionId — you will send it on every request alongside your MindCloud API Key.

How requests are authenticated

Authentication has two layers. Your MindCloud API Key authenticates the request to MindCloud, sent as a Bearer token in the Authorization header. The connectionId selects the connected Google Cloud Storage account that should run the action. MindCloud stores and refreshes the Google Cloud Storage credentials behind that connection, so you never send provider tokens with your requests.

Pass connectionId in the query string for GET and DELETE actions, and in the JSON body for POST, PUT, and PATCH actions.

For example, calling List Buckets with an Google Cloud Storage connection looks like this:

curl --request POST \
  --url "https://connect.mindcloud.co/v2/universal/apps/googleCloudStorage/actions/list-buckets/run" \
  --header "Authorization: Bearer $MINDCLOUD_API_KEY" \
  --header "Content-Type: application/json" \
  --data '{
  "connectionId": "$CONNECTION_ID",
  "arguments": {}
}'

The Authorization: Bearer <your MindCloud API Key> header authenticates you to MindCloud; the connectionId tells MindCloud which Google Cloud Storage account to run the action against. Missing or invalid Authorization returns 401, and a missing or mismatched connectionId returns 400.

Connect Google Cloud Storage

You need access to the Google Cloud project that contains the buckets you want to use. The connection form asks for the Google Cloud Project ID, not the project name or project number. If your organization enforces Google Cloud session control and you see a reauthentication error, a Google Workspace admin may need to trust the OAuth app before you reconnect.

  1. Open the Google Cloud Welcome page

    Sign in with the Google account you want to use for this storage connection.

    Google Cloud console → Welcome
  2. Select the correct project

    Use the project picker at the top of the page and select the project that owns the Cloud Storage buckets this connection should access.

  3. Copy the Project ID

    On the Welcome page, copy the Project ID value. Do not use the project name or project number.

  4. Enter the Project ID

    Return to the connection form, paste the copied value into the Project ID field, and continue the OAuth connection flow.

  5. If Google requires reauthentication, open API controls

    Ask a Google Workspace admin to go to admin.google.com, then open Security > Access and data control > API controls.

    Google Admin console → Security → Access and data control → API controls
  6. Find the OAuth app

    Click Manage App Access. Check Accessed apps if the user already connected the app, or go to Configured apps and add an app by OAuth app name or client ID. Paste this OAuth client ID: 75190365279-09qj5dhb7uoc33pgrf8s1rkjrt4grqgl.apps.googleusercontent.com.

  7. Set access to Trusted

    Select the OAuth app or client IDs, open Access to Google data, choose Trusted for the relevant organizational unit, and save the change.

  8. Exempt trusted apps from Google Cloud session control

    In the Google Admin console, open Security > Access and data control > Google Cloud session control, select the relevant organizational unit, and check Exempt trusted apps.

    Google Admin console → Security → Access and data control → Google Cloud session control
  9. Reconnect the account

    After the admin saves the settings, reconnect the Google Cloud Storage account from the connection form and rerun the workflow.

Keep your key safe

Keep your MindCloud API Key on your server; do not ship it in browser code, mobile apps, public repositories, or logs. Anyone with the key can call the Universal API as your MindCloud account, across every connection you have created.