Guides · Setup

Connect Google Slides to Outloop

Last updated:

In short

Connecting Google Slides to Outloop means signing in to Google once from Outloop in your browser, then approving the exact presentations each client workspace is allowed to touch.

Outloop mints and stores the refresh token host-side in the macOS Keychain — there is no token to copy. Agents then build slides, text and shapes in only the presentations you approved for that workspace; a request naming any other presentation is denied before any call reaches Google, and every request is audited with secret_exposed:false.

Summarize this setup guide with AI ChatGPTClaudePerplexity
Setting up Google for the first time? The Google Cloud side — project, APIs, scopes and one OAuth client — is the same for every Google connector and you only do it once. Follow Set up one reusable Google Cloud OAuth app first, then come back here for the Google Slides-specific steps. Already have a saved Google OAuth app? Skip straight to the Outloop steps below.

What this setup gives you

Agents that can do real Slides work inside the client files you approved — and nothing outside them. Outloop holds the Google credential locally, decides which presentation each workspace may reach, and audits every request.

What you need before starting

Which Google account connects what

Three separate identities — keep them apart

Most failed Google Slides setups are one confusion: assuming the Google account that manages the Cloud project is also the account that can open the client's presentations. It does not have to be, and often should not be.

  1. 1

    The Google Cloud project and OAuth app

    This owns the Client ID and Client Secret. It can belong to your agency or to your client — Outloop does not care which, and cannot tell the difference.

    cloud-admin@agency.example — manages the Google Cloud project

  2. 2

    The connected Google account

    This is the account you pick in Google's own chooser during the browser sign-in. It is the account that must actually own or be able to open the client's presentations.

    data-owner@client.example — is chosen at sign-in because it owns the client's presentations

  3. 3

    Outloop workspace access

    This decides which workspace may use the stored credential, which resources it may reach, and which capabilities agents get. It is set in the Access Profile, after the sign-in succeeds.

In that example, cloud-admin@agency.example created the OAuth app once, and every connector after it reuses that app — but the account you actually sign in as is data-owner@client.example, because that is the identity Google Slides will check when an agent asks for a file.

The connected account still has to be allowed in. Four things can block it, and all four are set on the OAuth app, not in Outloop:
  • If the app's audience is External and it is still in Testing, the account must be added as a Test user first.
  • If the audience is Internal, only accounts inside that Google Workspace organisation can sign in at all.
  • The Google Slides API must be enabled in the Google Cloud project the app belongs to.
  • The account must genuinely have access to the client's presentations. A successful sign-in proves identity, not reach.

1. Enable the Google Slides API

In Google Cloud Console, open APIs & Services → Library, search Google Slides API, and click Enable. Outloop calls it at slides.googleapis.com.

2. Create the OAuth client (once, for all Google connectors)

In Google Auth Platform → Clients, create a Web application OAuth client and copy the Client ID and Client Secret. Google may show the secret only once; if you lose it, create a new one. Under Authorized redirect URIs add Outloop's local callback — without it the browser connect below fails with redirect_uri_mismatch:

http://127.0.0.1:44317/oauth2/callback

The full one-time Google Cloud walkthrough — project, APIs, the whole scope set in one paste, and the publishing-status step that stops a working connection expiring after about a week — is in Set up one reusable Google Cloud OAuth app. If you already have a saved Google OAuth app, there is nothing to create here. The scope this connector requests is:

https://www.googleapis.com/auth/presentations
openid
email

The openid and email scopes are how Outloop verifies which Google account you actually connected — that identity check is Google OIDC, and it does not involve any Drive scope.

You only enter the Google OAuth app once

The first Google connector you set up asks for the Client ID and Client Secret from your Google Cloud OAuth client. Tick Save this Google OAuth app so other Google connectors can reuse it and every later Google connector — Gmail, Drive, Docs, Sheets and Analytics GA4 — picks it from the Google OAuth app dropdown with no Client Secret to re-enter. The saved app is then listed under Authentication Profiles. When a saved profile supplies the app, Outloop shows “Using <client-id>. Its Client Secret comes from the saved app — nothing to paste. This connector still signs in separately and gets its own access.”

Reusing the app does not mean sharing one login. Each connector still opens its own browser sign-in and gets its own refresh token, its own scopes and its own connected account — so you can revoke or re-authenticate one connector without touching the others.

Shared agency app or workspace-dedicated?

Which setup should I choose?

There are two reasonable answers for Google Slides, and the right one depends on who owns the Google Cloud infrastructure — not on how many clients you have.

Agency-global (shared OAuth app)

One OAuth app your agency owns, reused by every Google connector you add. This is the default and the right choice for most agencies.

  • Client ID and Client Secret entered once, then picked from a dropdown.
  • Every connector still runs its own Google sign-in.
  • Each one gets its own scopes, its own refresh token, its own connected account and its own revocation.
  • Reusing the app grants no data access by itself — workspace grants and Access Profiles stay explicit.

Workspace-dedicated

A separate OAuth client — or a separate Google Cloud project — for one workspace or one client.

  • The client owns the Google Cloud infrastructure and wants to keep owning it.
  • They need stronger administrative separation, or their own consent branding and audience rules.
  • They want separate quotas and their own lifecycle control.
  • The client's decks sit inside their own Google Workspace and their IT team wants the OAuth app to live there too.

A separate Google Cloud project is the strongest operational separation. A separate OAuth client inside the same project is lighter separation — useful, but the project is still shared.

Outloop cannot verify which you chose. It sees a Client ID and a Client Secret. It has no way to infer — and no way to enforce — how you organised your Google Cloud projects. If the separation matters to a client contract, it has to be real on the Google side; Outloop enforces the workspace boundary, not the Cloud-project boundary.
Sharing a stored credential is a third, different thing. Reusing the OAuth app is not the same as granting one stored Google Slides credential to several workspaces. You can do the latter deliberately — but then replacing that credential affects every workspace assigned to it. When Outloop says a credential will be stored in the shared slot and replaces whatever is already there, read that line before you continue, not after. Granting the app to a workspace does not automatically grant it data access either — that is still the Access Profile's job.

3. Add Google Slides in Outloop

In Outloop, open API Keys & Access → Add an API key and choose Google Slides. The panel opens on Connect in your browser, with the Cloud Console detail in the collapsed Setup details — Google Cloud OAuth client, scopes and caveats and Before you connect disclosures.

Under Access to request from Google, choose the level:

The full option is preselected because it is what most agency work needs; read-only is offered but never preselected. Then check the Google OAuth app dropdown — a saved profile supplies the app with no Client Secret to re-enter.

Read the storage line before you continue. Where Outloop says the credential will be stored in the SHARED slot, it also warns that it replaces whatever is already there. If another workspace relies on that slot, change the scope before connecting rather than after.

4. Connect the account in your browser

Click Connect Google Slides in your browser. Google's own sign-in opens and shows an account chooser — pick the account that can open the client presentations, then approve the consent screen. Google hands back to Outloop on a local loopback callback and Outloop mints and stores the refresh token host-side.

Nothing to copy or paste. There is no refresh token on your clipboard, so there is nothing to leak into a screenshot, a chat, or a .env file.

5. Confirm the account and capabilities

Outloop shows Connected as the Google account you just used. Check it — this is the moment to catch a sign-in to the wrong account, before any agent touches client work.

Under Agents will be able to (change any time in the Access profile), these are on by default:

And these are unchecked, marked , and only run if you turn them on:

Why linked charts are an explicit opt-in. Inserting a chart linked from a Google Sheet is not destructive — it is explicit because it reaches a second file. It needs three independent things before it works: the capability enabled here, the Sheets read scope on the connection, and an approved source spreadsheet.

Then click Confirm — this is the approved account.

6. Save the Access Profile and approve the presentations

OAuth is not the finish line — the Access Profile is

When Google Slides hands you back to Outloop, the connector is authenticated but not yet authorized. Agents cannot use it until you make the authorization decision yourself:

  1. OAuth connected
  2. Confirm the account
  3. Open the Access Profile
  4. Choose account-wide or specific presentation IDs
  5. Choose capabilities
  6. Save the Access Profile
  7. Copy the proof prompt

In the Access Profile you set two things. Reach — either account-wide, or a specific list under Approved presentations. And capabilities — what agents may actually do inside that reach, with anything destructive left off unless you turn it on.

“Copy workspace run prompt” does not become available until you save. If it looks inactive, nothing is broken — the Access Profile has not been saved yet. Open the Access Profile, make the two choices below, and click Save Access Profile; the run prompt becomes available once the authorization is recorded. Until then the workspace has no approved reach, so every agent call is refused with CUSTOMER_RESOURCE_PIN_REQUIRED before the credential is ever read.
Account-wide is never chosen for you. Outloop will not pre-select it, and this guide will not recommend it as a shortcut. How much of a client's Google Slides account a workspace can reach is an authorization decision that belongs to you — approve the specific presentation IDs unless you have a deliberate reason to open the whole account.

This is the step that separates clients, and the one people skip. Connecting the account is not the same as granting access to a file. On the connector's card, paste the presentation IDs this workspace may touch into Approved presentations, one per line — the ID is the segment between /d/ and /edit in the presentation URL.

Approved presentations:
1AbCdEf...              # client A — presentation the agent may edit
2GhIjKl...              # client B — a second approved presentation

Or, in the Access section, choose Account-wide deliberately. There are only two modes, and the safe pinned one is the default. Then click Save Access Profile — until you do, Copy workspace run prompt stays disabled.

7. Run the first proof

Ask the agent for a safe read against an approved presentation:

{
  "tenant": "<WORKSPACE_ID>",
  "service": "google_slides",
  "verb": "api_bridge.request",
  "method": "GET",
  "path": "/v1/presentations/<PRESENTATION_ID>?fields=presentationId"
}

Use a real presentation ID that the connected account can open — never a guessed one. Success criteria:

decision: allow
HTTP 200
presentationId matches the approved presentation
secret_exposed: false
audit entry exists

Only the last line completes the proof. A grant preflight that passes, or an OAuth callback that succeeded, is not runtime verification — the provider request has to succeed against a real resource first. Because no Slides proof has been published, this run is your verification, not a confirmation of ours.

What happens when nothing is approved

Outloop fails closed here, which is the behaviour you want and the most common first confusion:

A file Drive can see is not a file Slides can open

Google Drive and Google Slides are separate connectors in Outloop, and they can be authenticated as different Google accounts. Finding a deck through the Drive connector therefore proves nothing about whether the Slides connector's identity can open it.

See the Google Drive setup guide for the Drive-side boundary, and the Google Sheets and Google Docs guides, which share this behaviour.

What bites people about the Slides API

Slides is addressed by object, not by position — which makes it easier than Docs in one way and easier to corrupt in another. Worth putting in the agent's instructions up front.

Let Google assign the objectId

Every slide and every element on it has an objectId. A caller may supply one, and Google's documentation carries an explicit warning about doing so: they "must be unique across all objects in the presentation." An agent inventing readable IDs like slide_1 across several runs will eventually collide with itself.

Omit the field and read the ID back. Google generates one and returns it in the reply — for a created slide, at replies[0].createSlide.objectId — which the agent then uses for every follow-up request. Google's own recommendation is to omit it, or use a UUID if you truly need to choose. Building a deck is therefore a sequence: create, read the ID back, then fill it.

A linked chart needs a second file's permission

Inserting a chart linked from a Google Sheet is the one Slides capability that reaches outside the presentation. It is an explicit opt-in in the Access Profile not because it is destructive but because it touches a second file — and that file has its own sharing, which the connected Slides identity must satisfy. Three things must line up: the capability enabled, the Sheets read scope on the connection, and the source spreadsheet reachable by that identity.

Layouts and masters are shared state

Slides inherit from layouts, and layouts from masters. An edit aimed at a master changes every slide built on it — which is powerful for a template and destructive by accident. Point agents at the slide's own page elements unless changing the template really is the task.

Changing the account or the credential later

Changing the account or the credential later

Three controls on the Google Slides connector look similar and do different things. Picking the wrong one is the most common way a working connector gets broken on purpose.

Re-authenticate

Reuses the OAuth app you already selected and refreshes the authorization for the account that is already connected.

When: Use it when the refresh token expired or was revoked and you want the same account back.

Safety: It must not quietly become an account switch. If Outloop finds a different account at the other end, it reports the mismatch and keeps the previous token.

Connect as a different Google account

Keeps the same Client ID and Client Secret and opens Google's account chooser so you can pick another identity.

When: Use it when the wrong account was connected, or when the client moved the data to a different Google account.

Safety: The stored token is replaced only after Outloop positively verifies that the newly connected identity is the one you intended. A mismatch, a missing identity, a failed verification or a cancelled sign-in all leave the previous credential exactly as it was.

Replace the full credential

Swaps the OAuth app itself — a different Google Cloud project, Client ID or Client Secret.

When: Use it when the OAuth app is changing hands, or a client is moving the connector onto their own Cloud project.

Safety: This is not the same as choosing another Google data account. Confirm with "Sign in and replace" only when you actually mean to change the app.

Disconnecting does not delete your saved OAuth app. Removing a Google Slides service credential clears that credential — but the saved Google OAuth app profile is a separate, reusable object and stays. So when you reconnect, Outloop may never ask for the Client ID and Client Secret again. That is the reuse working as designed, not evidence that a stale credential was silently kept. To use a different app, pick another saved profile from the Google OAuth app dropdown, or create a new one and save it alongside the existing one.

Supported vs verified

No Google Slides runtime proof has been published. Google Sheets and Google Docs have each passed a real read proof through Outloop; those results say nothing about Slides and are deliberately not reused here. Everything below is supported by the API and permitted by policy — and unverified until you run the safe read above in your own workspace.

Troubleshooting

Google shows an account chooser

Expected. Outloop asks Google for the chooser on purpose, so a sign-in can never silently reuse whichever account your browser happened to be logged into. Pick the account that owns or can open the client's presentations — which is often not the account that manages the Google Cloud project.

“Google hasn’t verified this app”

This appears because the OAuth app is your own and has not been through Google's verification. If it is your app and you trust it, expand Advanced and continue. If you do not know who owns the app, stop — that warning is doing its job, and clicking past an unknown app is not a routine step.

Which audience the app uses decides who can get that far at all. An External app in Testing only admits accounts added as Test users. An Internal app only admits accounts inside its Google Workspace organisation. For customer-facing production use, complete Google's verification rather than living in Testing.

The wrong Google account got connected

Use Connect as a different Google account on the connector. It keeps the same Client ID and Client Secret and reopens Google's chooser. The stored token is only replaced once Outloop verifies the new identity is the intended one — if it does not match, Outloop reports the mismatch and keeps the previous credential. Nothing is lost by trying.

A credential that works but sits on the wrong account is deliberately not marked runtime-verified for that workspace. Working and correct are different things.

BACKEND_AUTH_FAILED during connect

Google rejected the sign-in, so the new credential failed Outloop's safe verification. The important part: the previous credential is unchanged. Do not delete the connector, the OAuth app or the workspace as a first move. Check, in this order — that you signed in as the account that can reach the client's presentations; that the account is admitted by the app's audience (a Test user on an External+Testing app); and that the API is enabled in the right Cloud project. Then try the connect again.

Reconnecting never asked for the Client ID and Secret

Expected. Disconnecting a Google Slides credential does not delete your saved Google OAuth app profile — that is a separate object, kept on purpose so later connectors do not re-enter a Client Secret. Outloop reused it. If you specifically want a different app, pick another saved profile from the Google OAuth app dropdown, or create a new one and save it alongside. This is reuse working, not a stale credential silently retained.

“Copy workspace run prompt” is not available

The Access Profile has not been saved yet. Open the Access Profile, choose the reach and the capabilities, and click Save Access Profile — the run prompt becomes available once the authorization is recorded. OAuth succeeding is not the same as the workspace being authorized, and this is the step that closes the gap.

The connection stops working after about a week

If the OAuth app's audience is External and its publishing status is still Testing, Google expires refresh tokens for that app after roughly seven days. Two honest options: publish the app to In production, or use an Internal audience if everyone signing in is inside your Google Workspace organisation. Publishing may require Google's verification review depending on the scopes the app requests — that is Google's process and its outcome and timing are not ours to promise.

Every call returns CUSTOMER_RESOURCE_PIN_REQUIRED

The workspace has no approved presentation and has not been set to account-wide. Add at least one presentation ID under Approved presentations, or choose account-wide deliberately — then save the Access Profile.

A specific file returns RESOURCE_ID_NOT_ALLOWED

That presentation is not on the approved list for this workspace. Add its ID — and check you are adding it to the right workspace, because this refusal is usually correct.

A specific file returns HTTP 403 from Google

This is a Google answer, not an Outloop refusal — the request reached Google and that account was not allowed to open that file. Check the account under Connected as and share the presentation with it, or connect as an account that already has access. Do not widen the OAuth scope to fix a sharing problem.

The agent created a file and then could not use it

Expected while pinned. Approve the new presentation ID afterwards; Outloop never widens a pin on its own.

A linked chart will not insert

Three things have to line up, and it is usually the second or third: the Insert charts linked from an approved Google Sheet capability enabled in the Access Profile, the Sheets read scope on this connection, and the source spreadsheet approved as well. A linked chart reaches a second file, so a second file's permissions apply.

Rotate or revoke access

Official Google documentation

Outloop is an independent tool and is not affiliated with or endorsed by Google. See the security model, the Google Drive setup guide, or the full guide index.

Summarize this setup guide with AI ChatGPTClaudePerplexity

Run Slides agents on approved client files only.

Outloop is available with guided onboarding for AI agencies, operators, and dev shops.

Frequently Asked Questions

Google Slides API + Outloop — FAQ