> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Share a Google Drive file with a person or the organization

> Creates a Drive permission for one file using the calling member's Google Workspace account. To share with one person pass type=user plus emailAddress; to share with the entire organization pass type=domain plus the org's Google Workspace domain (e.g. openworklabs.com). Sharing files not created through OpenWork needs the Full Drive access feature enabled by an admin.



## OpenAPI

````yaml /openapi.json post /v1/capabilities/google-workspace/drive-file-share/{fileId}
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Use `x-api-key: <den-api-key>` for API-key-authenticated routes that
    accept organization API keys.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set either
    `bearerAuth` or `denApiKey` before trying protected endpoints.
  version: dev
servers: []
security: []
tags:
  - name: System
    description: Service health and operational routes.
  - name: Organizations
    description: Top-level organization creation and context routes.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: SCIM
    description: Organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: Templates
    description: Organization shared template routes.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Workers
    description: Worker lifecycle, billing, and runtime routes.
  - name: Worker Runtime
    description: Worker runtime inspection and upgrade routes.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Admin
    description: Administrative reporting routes.
  - name: Users
    description: Current user and membership routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
paths:
  /v1/capabilities/google-workspace/drive-file-share/{fileId}:
    post:
      tags:
        - Capability Sources
      summary: Share a Google Drive file with a person or the organization
      description: >-
        Creates a Drive permission for one file using the calling member's
        Google Workspace account. To share with one person pass type=user plus
        emailAddress; to share with the entire organization pass type=domain
        plus the org's Google Workspace domain (e.g. openworklabs.com). Sharing
        files not created through OpenWork needs the Full Drive access feature
        enabled by an admin.
      operationId: postV1CapabilitiesGoogleWorkspaceDriveFileShareByFileId
      parameters:
        - in: path
          name: fileId
          schema:
            type: string
            minLength: 1
            maxLength: 512
          required: true
          description: Google Drive file id.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GoogleWorkspaceShareDriveFileBody'
      responses:
        '200':
          description: Google Drive file shared.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GoogleWorkspaceShareDriveFileResponse'
        '400':
          description: The share request was invalid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidRequestError'
        '401':
          description: The caller must be signed in.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '409':
          description: >-
            The calling member has not connected their Google account or is
            missing permission.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GoogleWorkspaceNeedsConnectionError'
        '502':
          description: Google rejected the request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GoogleWorkspaceUpstreamError'
components:
  schemas:
    GoogleWorkspaceShareDriveFileBody:
      type: object
      properties:
        type:
          type: string
          enum:
            - user
            - domain
          description: >-
            Use type=user to share with one person, or type=domain to share with
            the entire organization.
        emailAddress:
          description: >-
            Required when type=user; pass the person's email address, for
            example raghav@openworklabs.com.
          type: string
          maxLength: 320
          format: email
          pattern: >-
            ^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$
        domain:
          description: >-
            Required when type=domain; pass the organization's Google Workspace
            domain, for example openworklabs.com.
          type: string
          minLength: 1
          maxLength: 255
        role:
          default: reader
          description: Drive permission role to grant.
          type: string
          enum:
            - reader
            - commenter
            - writer
        sendNotificationEmail:
          default: true
          description: Whether Google should email the recipient about the new access.
          type: boolean
      required:
        - type
      additionalProperties: false
    GoogleWorkspaceShareDriveFileResponse:
      type: object
      properties:
        ok:
          type: boolean
          const: true
        fileId:
          type: string
        permissionId:
          type: string
        type:
          type: string
        role:
          type: string
      required:
        - ok
        - fileId
        - permissionId
        - type
        - role
    InvalidRequestError:
      type: object
      properties:
        error:
          type: string
          const: invalid_request
        details:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
            required:
              - message
            additionalProperties: {}
      required:
        - error
        - details
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          const: unauthorized
      required:
        - error
    GoogleWorkspaceNeedsConnectionError:
      type: object
      properties:
        error:
          type: string
          const: needs_connection
        message:
          type: string
      required:
        - error
        - message
    GoogleWorkspaceUpstreamError:
      type: object
      properties:
        error:
          type: string
          const: google_api_error
        message:
          type: string
      required:
        - error
        - message

````