People: Company admins, team admins
Platforms: Browser, Desktop
The Google Workspace integration lets users embed Google Docs, Sheets, and Slides content in Miro boards. This guide covers the integration's technical implementation, security model, and data handling for admins evaluating or configuring the integration.
Key features
- Live embed: Users can embed Google Docs, Sheets, or Slides content into a Miro board as a live iframe.
- Secure: Every board visitor is prompted to log in to the iframe before they can view the embedded content.
- Display options: Users can choose to display embedded content as a live embed or as a bookmark.
- Focus mode: Users can expand a live embed or bookmark into focus mode to view it without distractions.
- Action shortcut: Users can add an action shortcut that opens a dialog for embedding a Google Docs, Sheets, or Slides link.
- Asset picker: Users can add a specific slide as a static image on the board, so collaborators can view and reference that exact content without needing access to the source file.
- Admin controls: Admins can prevent users from using the asset picker to add Google Slides content as static images.
Limitations
- The asset picker is available for Google Slides only. It isn't available for Google Docs or Google Sheets.
Technical implementation
Miro integrates with Google Workspace through the Google REST API. Users authorize access with OAuth 2.0, then link their Google Docs, Sheets, or Slides files to a Miro board.
Security considerations
The integration's asset picker lets users attach part of a Google Slides file to the canvas as a static image. Only authorized users can access the live embed, but anyone with access to the board can view an attached static image. Adding assets from embeds is disabled by default on public boards.
Company admins can disable the asset picker for all boards:
- Go to Company settings > Apps and integrations > Apps > Google Office Integration App (under the Manage apps tab).
- Toggle Prevent users from adding assets from embeds to the canvas.
Data flows
- A user who belongs to a team or organization with this feature enabled pastes a Google Docs, Sheets, or Slides link onto a Miro board.
- Miro reads the link. If the user hasn't authorized the integration yet, Miro starts the OAuth flow and redirects the user to Google's authorization page.
- After the user grants authorization, Miro's integration service uses the user's access token to call the Google REST API and retrieve the content.
What Google data Miro stores
Miro fetches and stores the following data from pasted Google Workspace links:
- Document and file titles
- Images created by the asset picker
Data retention
Embedded data follows Miro's standard data retention policy for all customer data.
Authentication and authorization
Embedding a Google Docs, Sheets, or Slides link on a board requires the user to authorize the integration through Google's OAuth consent screen. Depending on the customer's Google Workspace configuration, this may also require a Google Workspace admin to approve the integration.
Required authorization scopes
The Google Workspace integration requires the following scopes:
https://www.googleapis.com/auth/presentations.readonly https://www.googleapis.com/auth/spreadsheets.readonly https://www.googleapis.com/auth/documents.readonly
What's stored in Miro and how
Miro stores two categories of data for this integration: authorization data and unfurling data.
- Authorization data: Miro stores the access token and refresh token in its database for several days. While the authorization is active, Miro automatically refreshes an expired access token using the refresh token, without requiring the user to reauthorize. All data stored for this integration is encrypted at rest using 256-bit AES.
- Unfurling data: Miro stores two kinds of unfurling data: the images captured by the asset picker (stored as part of the board) and the titles and image references (stored encrypted in an internal service).
Revoking a token
Users can revoke the integration's access at any time from their Google account, following the Google Identity guide.
Set up the Google Workspace integration
Note: Only Miro team admins can install the app. If your Miro organization only allows approved apps, and a regular user pastes a Google Workspace link, that user sees an app install request dialog instead.
To install and start using the integration:
- Copy the Google Docs, Sheets, or Slides file URL.
- Paste the URL onto your Miro board.
-
What happens next depends on who pasted the link:
- A Miro team admin pastes the link: The app is authorized and installed automatically, and the link unfurls without further action.
- A regular user pastes the link, and the organization only allows approved apps: An app install request dialog opens. After the user requests permission, company admins can follow the App request flow article to approve the request.
Connect a Google account
After the integration is installed and authorized:
- Click Connect on the widget created after pasting the URL on the board. You're redirected to a Google page asking you to grant Miro access to your account.
- Confirm authorization on the Google side. The Google content is added to your board as an iframe.
Frequently asked questions
Which users can embed Google content into Miro?
The user and the Miro board must meet both of these criteria:
- The user has authorized the Miro Google Workspace integration.
- The user has access to the Google content they're trying to embed.
Which users can view the embedded Google content?
Anyone with access to the Miro board and permission from the owner of the embedded content — that is, anyone with view, comment, or edit permissions on the board. Viewers don't need to authorize the integration or hold a Google license to view the embedded content on the board.
Do users have to reauthorize to paste links on other boards?
No, as long as the authorization is still valid (Miro treats an authorization as valid for a month after it's granted). Users can paste Google Workspace links on any board, and the content imports normally.
If the board belongs to a different team or organization where this integration isn't enabled, the user can't use it there.
Can I access Google content through Miro that I can't access directly in Google?
No. You can only embed Google content you already have access to — you can't use the integration to see something you couldn't otherwise open in Google. That said, if someone with access has already embedded the content as a static image on a board you share with them, you can view that snapshot even without direct access to the source file. The integration doesn't enforce any additional access policies beyond this; use the Miro board's own sharing settings to restrict who can collaborate. Note that a static image snapshot can't be used to explore the underlying data, open the original file, or change filters.
Where can I find the Miro Data Processing Addendum?
See the Miro Data Processing Addendum.
What's disallowed on public Miro boards?
For security reasons, public boards disable:
- Asset extraction — supported by the Looker, Google Slides, Figma, Power BI, Microsoft Word, Microsoft Excel, and Microsoft PowerPoint integrations.
- Direct asset unfurling (asset instead of live embed) — supported by the Figma integration.
How can I restrict board access to the same people who have access to the source file?
The integration only manages file access from the source system (Google), not from Miro. By default, this isn't enforced — to maintain this level of security, Miro organization admins must disable the asset picker in the app's admin settings.
Disabling the asset picker prevents Google content from being saved as static images on a Miro board, where it could later be seen by people who don't have access to it in Google (for example, if the board is shared publicly or with people who lack source access).