Google Cloud Storage for OutSystems 11, with keyless authentication.
Manage buckets and objects in Google Cloud Storage directly from your OutSystems applications. Built on the official Google Cloud .NET SDK, the connector authenticates with Workload Identity Federation, so no Google key exists anywhere, or with a service account key. It covers the full object and bucket lifecycle, including folders, custom metadata and signed URLs.
Keyless authentication: Workload Identity Federation with any OIDC identity provider (Entra ID, Okta, Auth0, Keycloak and others), server to server. Service account keys are still supported.
Full object lifecycle: upload, download, list, copy, move and delete objects, and delete a whole folder by prefix.
Large buckets: page through results, or browse folder by folder with a delimiter.
Metadata: read a file's size, hashes, versioning and timestamps without downloading it, and store, read and update your own key-value metadata.
Bucket management: create, list, check and delete buckets.
Signed URLs: temporary V4 links for download, upload or delete, optionally locked to one content type.
Clear errors: messages say what to fix, such as a missing bucket, a missing IAM role or a rejected credential.
Object_Upload: uploads binary data with its content type and optional custom metadata. Overwrites an existing object.
Object_Upload
Object_Download: returns an object's content and content type.
Object_Download
Object_List: lists objects, with an optional prefix. Set MaxResults and pass NextPageToken back as PageToken to page through large buckets; set Delimiter to / to get the folders in PrefixList.
Object_List
Object_Exists: checks whether an object exists, without downloading it.
Object_Exists
Object_GetMetadata: returns size, content type, hashes, generation, storage class, timestamps and custom metadata, without downloading the content.
Object_GetMetadata
Object_UpdateMetadata: changes content type, encoding, disposition, cache control and custom metadata without re-uploading. Empty inputs leave a field unchanged; a metadata entry with an empty Value removes that key.
Object_UpdateMetadata
Object_Delete: permanently deletes an object.
Object_Delete
Object_DeleteByPrefix: deletes every object under a prefix (a folder and its subfolders) and returns the count. The prefix can't be empty.
Object_DeleteByPrefix
Object_Copy: copies an object within or between buckets without downloading it.
Object_Copy
Object_Move: copies an object, then deletes the source. Use the same bucket to rename.
Object_Move
Object_GetSignedUrl: creates a signed URL for Download, Upload or Delete, valid from 1 minute to 7 days. For uploads, ContentType makes the URL accept only that content type.
Object_GetSignedUrl
Bucket_List: lists the buckets in the project.
Bucket_List
Bucket_Create: creates a bucket in a location such as US, EU or asia-east1.
Bucket_Create
Bucket_Exists: checks whether a bucket exists and is accessible.
Bucket_Exists
Bucket_Delete: deletes an empty bucket.
Bucket_Delete
A Google Cloud project with billing enabled.
A service account with the roles your operations need: Storage Object Admin (objects) and Storage Admin (buckets).
For Workload Identity Federation: an OIDC identity provider that issues signed JWTs, and, for the federated identity, Workload Identity User on the service account plus Service Account Token Creator if you generate signed URLs.
For a service account key: a downloaded JSON key for the service account. Signed URLs are signed locally and need no extra role.
Create one server action or function that builds a GCS_Authentication record from your Site Properties, and pass it to every call. To change method later, you only change that record. AuthenticationMethod selects the method; leave it empty for a service account key.
GCS_Authentication
AuthenticationMethod
The connector gets a JWT from your identity provider with the OAuth 2.0 client-credentials grant, exchanges it with Google's Security Token Service, and acts as your service account with short-lived tokens. Set:
AuthenticationMethod: WorkloadIdentityFederation
ProjectId: your Google Cloud project ID
WorkloadIdentityProvider: //iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL/providers/PROVIDER
//iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL/providers/PROVIDER
ServiceAccountEmail: the service account the connector acts as
TokenEndpoint, ClientId, ClientSecret: your identity provider's token endpoint (https) and app registration
Scope, Audience: optional values for the token request, if your provider needs them
SubjectToken: optional JWT you already have; when set, TokenEndpoint, ClientId and ClientSecret aren't needed
The OutSystems server must reach your provider's token endpoint, sts.googleapis.com and iamcredentials.googleapis.com. The full Google Cloud setup, with gcloud commands, is in the README on GitHub.
Leave AuthenticationMethod empty and map these values from the service account JSON key:
project_id -> ProjectId
project_id
client_email -> ClientEmail
client_email
private_key -> PrivateKey (the full string, including the -----BEGIN PRIVATE KEY----- header)
private_key
-----BEGIN PRIVATE KEY-----
Security tip: keep PrivateKey and ClientSecret in encrypted Site Properties or an encrypted database table, and never hard-code them.
Prefer keyless: with Workload Identity Federation there is no long-lived Google key to leak or rotate.
Large files: use Object_GetSignedUrl so users transfer directly to and from Google, sparing server memory and bandwidth.
Pre-flight checks: call Object_GetMetadata before a download to read size and content type without transferring the file.
Per-environment config: fill the Authentication record from Site Properties so Dev, QA and Prod each target their own project and bucket.
This connector is open source under the MIT license. Browse the code, report issues, or contribute on GitHub:
github.com/promonteiro89/google-cloud-storage-connector-o11
Google now recommends its latest Cloud Storage client libraries, which validate upload checksums end to end by default. This release adopts them. It’s a drop-in replacement for 1.6.0.
Improved
Updated
Good to know