Sazabi
Sandbox CLIs

Google Drive

Give the Sazabi agent the Google Workspace CLI (gws) in its sandbox for read-only Google Drive access via a service account.

About

This CLI connection makes the Google Workspace CLI (gws) available in the Sazabi agent's sandbox. The agent can use it for read-only Google Drive access. The tool is baked into the sandbox image; connecting it authenticates the already-installed CLI.

Prerequisites

  • A Sazabi project.
  • A Google Workspace service account key as a JSON string (GWS_SERVICE_ACCOUNT_KEY_JSON), downloaded from IAM & Admin > Service Accounts in the Google Cloud console, with Google Drive API access granted.

Set up in the dashboard

Configure the sandbox in the dashboard under Settings > Sandbox CLIs.

Find Google Drive in the catalog

In Settings > Sandbox CLIs, find Google Drive under Browse sandbox CLIs and choose to connect it.

Provide credentials

Enter the required value: GWS_SERVICE_ACCOUNT_KEY_JSON — the full contents of your service account key JSON file. Optionally, set GWS_IMPERSONATE_SUBJECT to a user email address to have the service account impersonate that user (requires domain-wide delegation to be configured on the service account). Save to store it securely; Sazabi injects it into the sandbox when the agent runs.

Set up with the CLI

You can also configure the Google Drive CLI connection with the Sazabi CLI (installed and authenticated — see CLI reference).

sazabi sandbox-clis set --type gws --env GWS_SERVICE_ACCOUNT_KEY_JSON="$(cat service-account.json)"

To validate the credentials without saving, run the same command with test in place of set (the test command also requires the --env flags).

Verify

Ask the agent, in a thread, to run the gws CLI (a read-only or status command) and confirm it returns real output from your account. If the command is not found, the CLI connection may not be enabled; if it runs unauthenticated, recheck the credentials.

Troubleshooting

Command not found — Confirm the Google Drive CLI connection is enabled for the project under Settings > Sandbox CLIs.

Authentication fails — Recheck the credential values; a rotated or revoked token must be re-entered under Settings > Sandbox CLIs or with sazabi sandbox-clis set --type gws.

Further reading