People: Company admins
The Looker integration lets users embed Looker dashboards and Explores in Miro boards. This guide covers setup, the integration's technical implementation, security model, and data handling for admins evaluating or configuring the integration.
Key features
- Live embed: Users can embed a Looker dashboard or Explore into a Miro board as a live iframe.
- Secure: Every board visitor is prompted to log in to the iframe before they can view the embedded content.
- Display options: Users can choose to display embedded content as a live embed or as a bookmark.
- Focus mode: Users can expand a live embed or bookmark into focus mode to view it without distractions.
- Action shortcut: Users can add an action shortcut that opens a dialog for embedding a Looker link.
- Asset picker: Users can add a specific chart or tile as a static image on the board, so collaborators can view and reference that exact content without needing access to the source file.
- Admin controls: Admins can prevent users from using the asset picker to add Looker content as static images.
Limitations
- Looker Studio isn't supported.
- Looker Looks aren't supported.
- Embedding Looker merge queries or Looker board links isn't supported.
- Images added with the asset picker can't be refreshed.
Known issues
Users who are already authenticated in a browser or the Miro desktop app can run into authentication problems when they switch to a different browser or to the Miro app. This can break the authentication flow and interrupt access to Looker.
Set up the Looker integration
Prerequisites
- A Company admin has approved Looker for your Miro organization.
- You have Looker admin access, to register Miro as an OAuth app in Looker.
Register the OAuth app in Looker
- In the Looker Marketplace, find and select API Explorer extension, then select Install.
- Go to Home > Applications > API Explorer.
- In the API Explorer search box, type
oauth, then select Register OAuth App under Auth. - Select Run It in the top right of the page.
-
In the request form, enter the following values:
-
client_guid:
15609152-a12a-4fa1-b364-337e7896d25d -
body:
{ "redirect_uri": "https://integrations.miro.com/api/contenthub/public/oauth/callback", "display_name": "Miro", "description": "Miro Looker Integration", "enabled": true, "group_id": "" } - Leave fields empty.
For more advanced options — for example, restricting authorization to a specific Looker group with
group_id— see the Looker documentation for registering an OAuth app (external). -
client_guid:
- Select I understand that this API endpoint will change data.
- Select Run. A successful run returns the request body and an HTTP 200 response.
If the returned body includes"enabled": false, run Update OAuth App with the same values to enable the client.
Install and authorize the integration in Miro
NOTE: Only Miro team admins can install the app. If your Miro organization only allows approved apps, and a regular user pastes a Looker link, that user sees an app install request dialog instead.
- Copy the Looker dashboard or Explore URL.
- Paste the URL onto your Miro board.
- What happens next depends on who pasted the link:
- A Miro team admin pastes the link: The app is authorized and installed automatically, and the link unfurls without further action.
-
A regular user pastes the link, and the organization only allows approved apps: An app install request dialog opens. After the user requests permission, company admins can follow the App request flow article to approve the request.
Connect a Looker account
After the integration is installed and authorized:
- Click Connect on the widget created after pasting the URL on the board. You're redirected to a page asking you to grant Miro access to your Looker account.
- Confirm authorization on the Looker side. The Looker content is added to your board as an iframe.
Technical implementation
Miro integrates with Looker through the Looker REST API. Users authorize access with OAuth 2.0, then link their Looker dashboards or Explores to a Miro board.
Security considerations
The integration's asset picker lets users attach a Looker chart or tile to the canvas as a static image. Only authorized users can access the live embed, but anyone with access to the board can view an attached static image. Adding assets from embeds is disabled by default on public boards.
Company admins can disable the asset picker for all boards:
- Go to Company settings > Apps and integrations > Apps > Unfurl Looker (under the Manage apps tab).
- Toggle Prevent users from adding assets from embeds to the canvas.
Data flows
- A user who belongs to a team or organization with this feature enabled pastes a Looker link onto a Miro board.
- Miro reads the link. If the user hasn't authorized the integration yet, Miro starts the OAuth flow and redirects the user to Looker's authorization page.
- After the user grants authorization, Miro's integration service uses the user's access token to call the Looker REST API and retrieve the content.
What Looker data Miro stores
Miro fetches and stores the following data from pasted Looker links:
- Dashboard and Explore titles
- Images created by the asset picker
Data retention
Embedded data follows Miro's standard data retention policy for all customer data.
Authentication and authorization
Embedding a Looker link on a board requires the user to authorize the integration through Looker's OAuth API. This also requires a Looker admin to register Miro as an OAuth app — see Register the OAuth app in Looker above.
Required authorization scopes
The Looker integration requires the following scope:
apiWhat's stored in Miro and how
Miro stores two categories of data for this integration: authorization data and unfurling data.
Authorization data: Miro stores the access token and refresh token in its database for several days. While the authorization is active, Miro automatically refreshes an expired access token using the refresh token, without requiring the user to reauthorize. All data stored for this integration is encrypted at rest using 256-bit AES.
Unfurling data: Miro stores two kinds of unfurling data: the images captured by the asset picker (stored as part of the board) and the titles and image references (stored encrypted in an internal service).
Revoking a token
Looker admins can revoke the integration's access from the Looker admin console:
- Go to Admin > Users.
- Select the user.
- Scroll to API Keys and select Delete next to the token.
Frequently asked questions
How do I turn off the integration?
Delete the Miro OAuth app from Looker. This doesn't remove Looker data already embedded on Miro boards, but it stops users from embedding new content or refreshing existing assets.
Which users can embed Looker content into Miro?
The user and the Miro board must meet both of these criteria:
- The user has authorized the Miro Looker integration.
- The user has access to the Looker content they're trying to embed.
Which users can view the embedded Looker content?
Anyone with access to the Miro board and permission from the owner of the embedded content — that is, anyone with view, comment, or edit permissions on the board. Viewers don't need to authorize the integration or hold a Looker license to view the embedded content on the board.
Do users have to reauthorize to paste links on other boards?
No, as long as the authorization is still valid (Miro treats an authorization as valid for a month after it's granted). Users can paste Looker links on any board, and the content imports normally.
If the board belongs to a different team or organization where this integration isn't enabled, the user can't use it there.
Can I access Looker content through Miro that I can't access directly in Looker?
No. You can only embed Looker content you already have access to — you can't use the integration to see something you couldn't otherwise open in Looker. That said, if someone with access has already embedded the content as a static image on a board you share with them, you can view that snapshot even without direct access to the source file. The integration doesn't enforce any additional access policies beyond this; use the Miro board's own sharing settings to restrict who can collaborate. Note that a static image snapshot can't be used to explore the underlying data, open the original chart, or change filters.
Where can I find the Miro Data Processing Addendum?
See the Miro Data Processing Addendum.
What's disallowed on public Miro boards?
For security reasons, public boards disable:
- Asset extraction — supported by the Looker, Google Slides, Figma, Power BI, Microsoft Word, Microsoft Excel, and Microsoft PowerPoint integrations.
- Direct asset unfurling (asset instead of live embed) — supported by the Figma integration.
How can I restrict board access to the same people who have access to the source file?
The integration only manages file access from the source system (Looker), not from Miro. By default, this isn't enforced — to maintain this level of security, Miro organization admins must disable the asset picker in the app's admin settings (see Security considerations).
Disabling the asset picker prevents Looker content from being saved as static images on a Miro board, where it could later be seen by people who don't have access to it in Looker (for example, if the board is shared publicly or with people who lack source access).